@freehour/supabase-langchain
Integration package for using LangChain with Supabase
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Package has 20 versions in 46 days; rapid iteration is the established pattern for this package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs a bundled local script (copy-supabase-assets.js) to copy migration assets; no network fetch or arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:pdf-parse | AI (phantom-deps): LangChain document loaders use optional/dynamic imports; declared dep is legitimately used at runtime. | ai | |
| phantom-deps | phantom-dep:officeparser | AI (phantom-deps): Same pattern as pdf-parse; optional document loader dependency. | ai | |
| phantom-deps | phantom-dep:srt-parser-2 | AI (phantom-deps): Same pattern; optional document loader dependency for SRT files. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 1.3.9 | 9 / 10 | |
| 1.3.7 | 9 / 10 | |
| 1.2.0 | 9 / 10 | |
| 1.1.0 | 9 / 10 | |
| 1.0.2 | 9 / 10 | |
| 1.0.1 | 10 / 9 |
v1.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
2 findingsScript: bun ./scripts/copy-supabase-assets.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.0
2 findingsScript: bun ./scripts/copy-supabase-assets.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.2
2 findingsScript: bun ./scripts/copy-supabase-assets.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.1
2 findingsScript: bun ./scripts/copy-supabase-assets.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.