← Home

@github/copilot

23
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mxie-githubtidy-devcroffzdevm33manuelpuyoljonrohanprimer-cssgraceparkjibrangarciaareliatylerthedevsmocklesimuraikhiga8dustin.greifsrt32githubbotjfuchsandrialexandroujoycezhubteng22dustin.saveryncalteenalaingogaandreiig

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): First-party GitHub Actions publish; gitCommit still recorded in buildMetadata. ai
provenance no-provenance AI (provenance): Provenance absence is not a risk for this established official package. ai
source-diff encoded-string-file:sdk/index.js AI (source-diff): Bundled jsonc parser code, benign build artifact. ai
source-diff encoded-string-file:app.js AI (source-diff): esbuild-bundled output (undici symbols), not obfuscation. ai
phantom-deps phantom-dep:detect-libc AI (phantom-deps): detect-libc is referenced in the loader script for platform detection; phantom-dep heuristic misses indirect usage in this loader pattern. ai
source-diff source-size-dropped AI (source-diff): Package intentionally ships only a loader stub; binaries are in optional platform-specific packages. Size drop is by design. ai
bogus-package bogus-package AI (bogus-package): Official GitHub Copilot CLI with 949k weekly downloads; spam-flagged maintainers are GitHub employees. False positive. ai
semgrep semgrep:env-bulk-read AI (semgrep): Fires on copilot index.js but package is sharp wasm32 prebuilt; finding is from a different package context. ai
npm-metadata bundled-binaries AI (npm-metadata): sharp prebuilt packages routinely bundle platform-specific native binaries; this is the documented distribution mechanism. ai
semgrep semgrep:toplevel-fetch AI (semgrep): Same mismatched context as env-bulk-read; not applicable to sharp wasm32 prebuilt. ai

Versions (showing 23 of 23)

Version Deps Published
1.0.75 1 / 0
1.0.74 1 / 0
1.0.73 1 / 0
1.0.72 1 / 0
1.0.71 1 / 0
1.0.70 1 / 0
1.0.69 1 / 0
1.0.68 1 / 0
1.0.67 1 / 0
1.0.66 1 / 0
1.0.65 1 / 0
1.0.64 1 / 0
1.0.38 0 / 0
1.0.11 0 / 0
1.0.10 0 / 0
1.0.9 0 / 0
1.0.8 0 / 0
1.0.7 0 / 0
1.0.6 0 / 0
1.0.2 0 / 0
1.0.1 0 / 0
1.0.0 0 / 0
0.0.423 0 / 0

v1.0.75

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v1.0.74

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v1.0.73

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v1.0.72

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.71

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.70

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.69

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.68

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.67

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.66

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.