← Home

@forestadmin/agent

100
Versions
GPL-3.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

vincentmolinieforestforestbot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/routes/workflow/workflow-executor-proxy.js AI (source-diff): tsc-compiled CJS output, not obfuscation; matches source functionality. ai
source-diff obfuscated-file:dist/mcp-in-process-dispatcher.js AI (source-diff): tsc-compiled CJS output, not obfuscation; matches source functionality. ai
source-diff obfuscated-file:dist/embedded-workflow-executor.js AI (source-diff): tsc-compiled CJS output, not obfuscation; matches source functionality. ai
source-diff obfuscated-file:dist/services/authorization/internal/generate-actions-from-permissions.js AI (source-diff): Standard TypeScript CJS compiled output; readable permission mapping logic, no obfuscation. ai
source-diff obfuscated-file:dist/utils/forest-http-api.js AI (source-diff): Standard TypeScript CJS compiled output; readable HTTP API calls, no obfuscation. ai
source-diff obfuscated-file:dist/agent/services/chart.js AI (source-diff): Standard TypeScript CJS compiled output; readable class logic, no obfuscation. ai
source-diff obfuscated-file:dist/services/authorization/internal/action-permission.js AI (source-diff): Standard TypeScript CJS compiled output; readable class logic, no obfuscation. ai
source-diff obfuscated-file:dist/routes/modification/action.js AI (source-diff): Standard TypeScript CJS compiled output; readable class logic, no obfuscation. ai
source-diff obfuscated-file:dist/services/authorization/internal/rendering-permission.js AI (source-diff): Standard TypeScript CJS compiled output; readable rendering permission logic, no obfuscation. ai
source-diff obfuscated-file:dist/services/permissions.js AI (source-diff): Standard TypeScript CJS compiled output; readable permissions service, no obfuscation. ai
maintainer-change maintainer-added AI (maintainer-change): Maintainer rotation within ForestAdmin org; consistent with CI-based publishing transition. ai
source-diff obfuscated-file:dist/fastify-adapter.js AI (source-diff): Standard TypeScript compiler output (tsc); long lines from bundled helpers, not obfuscation. Stable pattern for this package. ai
provenance publisher-changed AI (provenance): Transition from forestbot to GitHub Actions CI/CD is backed by SLSA provenance attestation; legitimate infra migration. ai
maintainer-change maintainer-removed AI (maintainer-change): Maintainer cleanup consistent with CI/CD-driven publishing model; SLSA attestation confirms legitimate pipeline. ai
publish-pattern new-deps-added AI (publish-pattern): @paralleldrive/cuid2 is a well-established CUID2 library, pinned to a specific version with an override — low risk. ai
provenance no-provenance AI (provenance): ForestAdmin publishes via forestbot automation; no provenance is consistent across their release history. ai
npm-metadata no-description AI (npm-metadata): Scoped org package; missing description is cosmetic, not a malware signal for this established package. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI with Sigstore attestation; stable signal for this org. ai
dependencies unvetted-dep:forest-ip-utils AI (dependencies): ForestAdmin-maintained IP utility; consistent with package ecosystem. ai
dependencies unvetted-dep:@koa/bodyparser AI (dependencies): Official @koa scoped bodyparser; no malware indicators. ai
dependencies unvetted-dep:koa-jwt AI (dependencies): Well-known Koa JWT middleware; no malware indicators. ai
dependencies unvetted-dep:@forestadmin/mcp-server AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. ai
dependencies unvetted-dep:@forestadmin/agent-toolkit AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. ai
dependencies unvetted-dep:@forestadmin/datasource-toolkit AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. ai
dependencies unvetted-dep:@forestadmin/datasource-customizer AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. ai
phantom-deps phantom-dep:@paralleldrive/cuid2 AI (phantom-deps): Referenced in config/overrides; stable false positive for this package. ai
phantom-deps phantom-dep:@types/koa__router AI (phantom-deps): Type-only declaration; not imported at runtime by convention. ai

Versions (showing 100 of 174)

Version Deps Published
2.0.1 21 / 21
2.0.0 21 / 21
1.90.3 22 / 22
1.90.2 22 / 22
1.90.1 22 / 22
1.90.0 22 / 22
1.89.1 22 / 22
1.89.0 22 / 22
1.88.0 22 / 22
1.87.1 22 / 22
1.87.0 22 / 22
1.86.7 21 / 22
1.86.6 21 / 22
1.86.5 21 / 22
1.86.4 21 / 22
1.86.3 21 / 22
1.86.2 21 / 22
1.86.1 21 / 22
1.86.0 21 / 22
1.85.1 21 / 22
1.85.0 21 / 22
1.84.1 21 / 22
1.84.0 21 / 22
1.83.1 21 / 21
1.83.0 21 / 21
1.82.0 21 / 21
1.81.3 21 / 21
1.81.2 21 / 21
1.81.1 21 / 21
1.81.0 21 / 21
1.80.0 21 / 21
1.79.5 21 / 21
1.79.4 21 / 21
1.79.3 21 / 21
1.79.2 21 / 21
1.79.1 21 / 21
1.79.0 21 / 21
1.78.13 21 / 21
1.78.12 21 / 21
1.78.11 21 / 21
1.78.10 21 / 21
1.78.9 21 / 21
1.78.8 21 / 21
1.78.7 21 / 21
1.78.6 21 / 21
1.78.5 21 / 21
1.78.4 21 / 21
1.78.3 21 / 21
1.78.2 21 / 21
1.78.1 21 / 21
1.78.0 21 / 21
1.77.1 21 / 21
1.76.6 21 / 21
1.76.5 21 / 21
1.76.4 21 / 21
1.76.3 21 / 21
1.76.2 21 / 21
1.76.1 21 / 21
1.76.0 21 / 21
1.75.2 21 / 21
1.75.1 21 / 21
1.75.0 21 / 21
1.74.1 21 / 21
1.74.0 21 / 21
1.73.2 21 / 21
1.73.1 21 / 21
1.73.0 21 / 21
1.72.11 21 / 21
1.72.10 21 / 21
1.72.9 21 / 21
1.72.8 21 / 21
1.72.7 21 / 21
1.72.6 21 / 21
1.72.5 21 / 21
1.72.4 21 / 21
1.72.3 21 / 21
1.72.2 21 / 21
1.72.1 21 / 21
1.72.0 21 / 21
1.71.2 21 / 21
1.71.1 21 / 21
1.71.0 21 / 21
1.70.10 20 / 21
1.70.9 20 / 21
1.70.8 20 / 21
1.70.7 20 / 21
1.70.6 20 / 21
1.70.5 20 / 21
1.70.4 20 / 21
1.70.3 20 / 21
1.70.2 20 / 21
1.70.1 20 / 21
1.70.0 20 / 21
1.69.0 20 / 21
1.68.4 20 / 21
1.68.3 20 / 21
1.68.2 20 / 21
1.68.1 20 / 21
1.68.0 21 / 20
1.67.0 20 / 16
Showing 100 of 174 Next page →

v1.90.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.90.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.90.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.90.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.89.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.89.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.88.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.87.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.87.0

4 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mcp-in-process-dispatcher.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.7

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.6

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.5

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.4

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.3

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.2

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.1

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.86.0

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.85.1

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.85.0

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.84.1

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.84.0

3 findings
HIGH New obfuscated file: dist/embedded-workflow-executor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.83.1

2 findings
HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.83.0

2 findings
HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.82.0

2 findings
HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.81.3

2 findings
HIGH New obfuscated file: dist/routes/workflow/workflow-executor-proxy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.