@forestadmin/agent
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/routes/workflow/workflow-executor-proxy.js | AI (source-diff): tsc-compiled CJS output, not obfuscation; matches source functionality. | ai | |
| source-diff | obfuscated-file:dist/mcp-in-process-dispatcher.js | AI (source-diff): tsc-compiled CJS output, not obfuscation; matches source functionality. | ai | |
| source-diff | obfuscated-file:dist/embedded-workflow-executor.js | AI (source-diff): tsc-compiled CJS output, not obfuscation; matches source functionality. | ai | |
| source-diff | obfuscated-file:dist/services/authorization/internal/generate-actions-from-permissions.js | AI (source-diff): Standard TypeScript CJS compiled output; readable permission mapping logic, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils/forest-http-api.js | AI (source-diff): Standard TypeScript CJS compiled output; readable HTTP API calls, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/agent/services/chart.js | AI (source-diff): Standard TypeScript CJS compiled output; readable class logic, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/services/authorization/internal/action-permission.js | AI (source-diff): Standard TypeScript CJS compiled output; readable class logic, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/routes/modification/action.js | AI (source-diff): Standard TypeScript CJS compiled output; readable class logic, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/services/authorization/internal/rendering-permission.js | AI (source-diff): Standard TypeScript CJS compiled output; readable rendering permission logic, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/services/permissions.js | AI (source-diff): Standard TypeScript CJS compiled output; readable permissions service, no obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer rotation within ForestAdmin org; consistent with CI-based publishing transition. | ai | |
| source-diff | obfuscated-file:dist/fastify-adapter.js | AI (source-diff): Standard TypeScript compiler output (tsc); long lines from bundled helpers, not obfuscation. Stable pattern for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from forestbot to GitHub Actions CI/CD is backed by SLSA provenance attestation; legitimate infra migration. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainer cleanup consistent with CI/CD-driven publishing model; SLSA attestation confirms legitimate pipeline. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @paralleldrive/cuid2 is a well-established CUID2 library, pinned to a specific version with an override — low risk. | ai | |
| provenance | no-provenance | AI (provenance): ForestAdmin publishes via forestbot automation; no provenance is consistent across their release history. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Scoped org package; missing description is cosmetic, not a malware signal for this established package. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published via CI with Sigstore attestation; stable signal for this org. | ai | |
| dependencies | unvetted-dep:forest-ip-utils | AI (dependencies): ForestAdmin-maintained IP utility; consistent with package ecosystem. | ai | |
| dependencies | unvetted-dep:@koa/bodyparser | AI (dependencies): Official @koa scoped bodyparser; no malware indicators. | ai | |
| dependencies | unvetted-dep:koa-jwt | AI (dependencies): Well-known Koa JWT middleware; no malware indicators. | ai | |
| dependencies | unvetted-dep:@forestadmin/mcp-server | AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. | ai | |
| dependencies | unvetted-dep:@forestadmin/agent-toolkit | AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. | ai | |
| dependencies | unvetted-dep:@forestadmin/datasource-toolkit | AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. | ai | |
| dependencies | unvetted-dep:@forestadmin/datasource-customizer | AI (dependencies): First-party ForestAdmin package; stable dependency across all versions. | ai | |
| phantom-deps | phantom-dep:@paralleldrive/cuid2 | AI (phantom-deps): Referenced in config/overrides; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/koa__router | AI (phantom-deps): Type-only declaration; not imported at runtime by convention. | ai |
Versions (showing 100 of 174)
| Version | Deps | Published |
|---|---|---|
| 2.0.1 | 21 / 21 | |
| 2.0.0 | 21 / 21 | |
| 1.90.3 | 22 / 22 | |
| 1.90.2 | 22 / 22 | |
| 1.90.1 | 22 / 22 | |
| 1.90.0 | 22 / 22 | |
| 1.89.1 | 22 / 22 | |
| 1.89.0 | 22 / 22 | |
| 1.88.0 | 22 / 22 | |
| 1.87.1 | 22 / 22 | |
| 1.87.0 | 22 / 22 | |
| 1.86.7 | 21 / 22 | |
| 1.86.6 | 21 / 22 | |
| 1.86.5 | 21 / 22 | |
| 1.86.4 | 21 / 22 | |
| 1.86.3 | 21 / 22 | |
| 1.86.2 | 21 / 22 | |
| 1.86.1 | 21 / 22 | |
| 1.86.0 | 21 / 22 | |
| 1.85.1 | 21 / 22 | |
| 1.85.0 | 21 / 22 | |
| 1.84.1 | 21 / 22 | |
| 1.84.0 | 21 / 22 | |
| 1.83.1 | 21 / 21 | |
| 1.83.0 | 21 / 21 | |
| 1.82.0 | 21 / 21 | |
| 1.81.3 | 21 / 21 | |
| 1.81.2 | 21 / 21 | |
| 1.81.1 | 21 / 21 | |
| 1.81.0 | 21 / 21 | |
| 1.80.0 | 21 / 21 | |
| 1.79.5 | 21 / 21 | |
| 1.79.4 | 21 / 21 | |
| 1.79.3 | 21 / 21 | |
| 1.79.2 | 21 / 21 | |
| 1.79.1 | 21 / 21 | |
| 1.79.0 | 21 / 21 | |
| 1.78.13 | 21 / 21 | |
| 1.78.12 | 21 / 21 | |
| 1.78.11 | 21 / 21 | |
| 1.78.10 | 21 / 21 | |
| 1.78.9 | 21 / 21 | |
| 1.78.8 | 21 / 21 | |
| 1.78.7 | 21 / 21 | |
| 1.78.6 | 21 / 21 | |
| 1.78.5 | 21 / 21 | |
| 1.78.4 | 21 / 21 | |
| 1.78.3 | 21 / 21 | |
| 1.78.2 | 21 / 21 | |
| 1.78.1 | 21 / 21 | |
| 1.78.0 | 21 / 21 | |
| 1.77.1 | 21 / 21 | |
| 1.76.6 | 21 / 21 | |
| 1.76.5 | 21 / 21 | |
| 1.76.4 | 21 / 21 | |
| 1.76.3 | 21 / 21 | |
| 1.76.2 | 21 / 21 | |
| 1.76.1 | 21 / 21 | |
| 1.76.0 | 21 / 21 | |
| 1.75.2 | 21 / 21 | |
| 1.75.1 | 21 / 21 | |
| 1.75.0 | 21 / 21 | |
| 1.74.1 | 21 / 21 | |
| 1.74.0 | 21 / 21 | |
| 1.73.2 | 21 / 21 | |
| 1.73.1 | 21 / 21 | |
| 1.73.0 | 21 / 21 | |
| 1.72.11 | 21 / 21 | |
| 1.72.10 | 21 / 21 | |
| 1.72.9 | 21 / 21 | |
| 1.72.8 | 21 / 21 | |
| 1.72.7 | 21 / 21 | |
| 1.72.6 | 21 / 21 | |
| 1.72.5 | 21 / 21 | |
| 1.72.4 | 21 / 21 | |
| 1.72.3 | 21 / 21 | |
| 1.72.2 | 21 / 21 | |
| 1.72.1 | 21 / 21 | |
| 1.72.0 | 21 / 21 | |
| 1.71.2 | 21 / 21 | |
| 1.71.1 | 21 / 21 | |
| 1.71.0 | 21 / 21 | |
| 1.70.10 | 20 / 21 | |
| 1.70.9 | 20 / 21 | |
| 1.70.8 | 20 / 21 | |
| 1.70.7 | 20 / 21 | |
| 1.70.6 | 20 / 21 | |
| 1.70.5 | 20 / 21 | |
| 1.70.4 | 20 / 21 | |
| 1.70.3 | 20 / 21 | |
| 1.70.2 | 20 / 21 | |
| 1.70.1 | 20 / 21 | |
| 1.70.0 | 20 / 21 | |
| 1.69.0 | 20 / 21 | |
| 1.68.4 | 20 / 21 | |
| 1.68.3 | 20 / 21 | |
| 1.68.2 | 20 / 21 | |
| 1.68.1 | 20 / 21 | |
| 1.68.0 | 21 / 20 | |
| 1.67.0 | 20 / 16 |
v1.90.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.90.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.90.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.90.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.89.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.89.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.88.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.87.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.87.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.86.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.85.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.85.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.84.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.84.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.83.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.83.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.82.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.81.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.