@framers/agentos
Modular AgentOS orchestration library
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/emergent/SandboxedToolForge.js | AI (source-diff): SandboxedToolForge is a documented sandboxing utility; net+exec combination is intentional and security-hardened. | ai | |
| source-diff | net-exec-file:dist/emergent/SandboxedToolForge.d.ts | AI (source-diff): Type declaration file for SandboxedToolForge; same rationale as the .js file — intentional sandbox design. | ai | |
| dependencies | unvetted-peer-dep:hnswlib-node | AI (dependencies): Peer dependency for optional vector search functionality; consumers control inclusion and vetting. | ai | |
| dependencies | unvetted-peer-dep:ppu-paddle-ocr | AI (dependencies): Peer dependency for optional OCR functionality; consumers control inclusion and vetting. | ai | |
| dependencies | unvetted-peer-dep:@framers/sql-storage-adapter | AI (dependencies): Peer dependency for optional SQL storage; marked optional in peerDependenciesMeta; consumers control inclusion. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package is an AI orchestration library with many optional modules; large source file additions are expected with minor version bumps as new capabilities are added. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Legitimate orchestration library with active maintenance (263 versions, 5.7k weekly downloads). Spam signals are weak metadata heuristics; no malware indicators present. | ai | |
| dependencies | unvetted-dep:natural | AI (dependencies): natural is a well-established NLP library; its use is consistent with this package's NLP/orchestration purpose and poses no security risk. | ai | |
| phantom-deps | phantom-dep:openredaction | AI (phantom-deps): openredaction is declared in dependencies and referenced in config; phantom-dep flag is a minor packaging concern, not a security issue for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 263 versions and 5.7k weekly downloads; lack of provenance is common and not a security disqualifier for this package. | ai |
Versions (showing 100 of 497)
| Version | Deps | Published |
|---|---|---|
| 0.10.0 | 21 / 33 | |
| 0.9.164 | 21 / 33 | |
| 0.9.163 | 20 / 32 | |
| 0.9.162 | 20 / 32 | |
| 0.9.161 | 20 / 32 | |
| 0.9.160 | 20 / 32 | |
| 0.9.159 | 20 / 32 | |
| 0.9.158 | 20 / 32 | |
| 0.9.157 | 20 / 32 | |
| 0.9.156 | 20 / 32 | |
| 0.9.155 | 20 / 32 | |
| 0.9.154 | 20 / 32 | |
| 0.9.153 | 20 / 32 | |
| 0.9.152 | 20 / 32 | |
| 0.9.151 | 20 / 32 | |
| 0.9.150 | 20 / 32 | |
| 0.9.149 | 20 / 32 | |
| 0.9.148 | 20 / 32 | |
| 0.9.147 | 20 / 32 | |
| 0.9.146 | 20 / 32 | |
| 0.9.145 | 20 / 32 | |
| 0.9.144 | 20 / 32 | |
| 0.9.143 | 20 / 32 | |
| 0.9.142 | 20 / 32 | |
| 0.9.141 | 20 / 32 | |
| 0.9.140 | 20 / 32 | |
| 0.9.139 | 20 / 32 | |
| 0.9.138 | 20 / 32 | |
| 0.9.137 | 20 / 32 | |
| 0.9.136 | 20 / 32 | |
| 0.9.135 | 20 / 32 | |
| 0.9.134 | 20 / 32 | |
| 0.9.133 | 20 / 32 | |
| 0.9.132 | 20 / 32 | |
| 0.9.131 | 20 / 32 | |
| 0.9.130 | 20 / 32 | |
| 0.9.129 | 20 / 32 | |
| 0.9.128 | 20 / 32 | |
| 0.9.127 | 20 / 32 | |
| 0.9.126 | 20 / 32 | |
| 0.9.125 | 20 / 32 | |
| 0.9.124 | 20 / 32 | |
| 0.9.123 | 20 / 32 | |
| 0.9.122 | 20 / 32 | |
| 0.9.121 | 20 / 32 | |
| 0.9.120 | 20 / 32 | |
| 0.9.119 | 20 / 32 | |
| 0.9.118 | 20 / 32 | |
| 0.9.117 | 20 / 32 | |
| 0.9.116 | 20 / 32 | |
| 0.9.115 | 20 / 32 | |
| 0.9.114 | 20 / 32 | |
| 0.9.113 | 20 / 32 | |
| 0.9.112 | 20 / 32 | |
| 0.9.111 | 20 / 32 | |
| 0.9.110 | 20 / 32 | |
| 0.9.109 | 20 / 32 | |
| 0.9.108 | 20 / 32 | |
| 0.9.107 | 20 / 32 | |
| 0.9.106 | 20 / 32 | |
| 0.9.105 | 20 / 32 | |
| 0.9.104 | 20 / 32 | |
| 0.9.103 | 20 / 32 | |
| 0.9.102 | 20 / 32 | |
| 0.9.101 | 20 / 32 | |
| 0.9.100 | 20 / 32 | |
| 0.9.99 | 20 / 32 | |
| 0.9.98 | 20 / 32 | |
| 0.9.97 | 20 / 32 | |
| 0.9.96 | 20 / 32 | |
| 0.9.95 | 20 / 32 | |
| 0.9.94 | 20 / 32 | |
| 0.9.93 | 20 / 32 | |
| 0.9.92 | 20 / 32 | |
| 0.9.91 | 20 / 32 | |
| 0.9.90 | 20 / 32 | |
| 0.9.89 | 20 / 32 | |
| 0.9.88 | 20 / 32 | |
| 0.9.87 | 20 / 32 | |
| 0.9.86 | 20 / 32 | |
| 0.9.85 | 20 / 32 | |
| 0.9.84 | 20 / 32 | |
| 0.9.83 | 20 / 32 | |
| 0.9.82 | 20 / 32 | |
| 0.9.81 | 20 / 32 | |
| 0.9.80 | 20 / 32 | |
| 0.9.79 | 20 / 32 | |
| 0.9.78 | 20 / 32 | |
| 0.9.77 | 20 / 32 | |
| 0.9.76 | 20 / 32 | |
| 0.9.75 | 20 / 32 | |
| 0.9.74 | 20 / 32 | |
| 0.9.73 | 20 / 32 | |
| 0.9.72 | 20 / 32 | |
| 0.9.71 | 20 / 32 | |
| 0.9.70 | 20 / 32 | |
| 0.9.69 | 20 / 32 | |
| 0.9.68 | 20 / 32 | |
| 0.9.67 | 20 / 32 | |
| 0.9.66 | 20 / 32 |
v0.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.164
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.163
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.162
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.161
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.160
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.159
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.158
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.157
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.156
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.154
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.153
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.152
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.150
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.149
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.148
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.147
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.146
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.145
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.144
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.143
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.142
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.141
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.140
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.139
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.138
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.137
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.136
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.135
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.134
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.133
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.132
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.131
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.130
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.129
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.128
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.127
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.126
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.125
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.124
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.123
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.122
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.121
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.120
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.119
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.118
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.117
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.116
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.115
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.114
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.113
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.112
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.111
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.110
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.109
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.108
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.107
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.106
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.105
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.104
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.103
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.102
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.101
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.100
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.99
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.98
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.97
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.96
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.95
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.94
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.93
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.92
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.91
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.90
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.89
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.88
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.87
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.86
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.85
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.