← Home

@github/copilot-sdk

38
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

mxie-githubtidy-devcroffzdevm33manuelpuyoljonrohanprimer-cssgraceparkjibrangarciaareliatylerthedevsmocklesimuraikhiga8dustin.greifsrt32githubbotjfuchsandrialexandroujoycezhubteng22dustin.saveryncalteenalaingogaandreiig

Keywords

githubcopilotsdkjsonrpcagent

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Legit first-party GitHub org maintainer addition. ai
provenance missing-githead AI (provenance): CI/CD publish via GitHub Actions with SLSA attestation; gitHead absence is env change, not risk. ai
source-diff source-size-tripled AI (source-diff): SDK growing from 0.3.0 to 1.0.5 naturally triples size; no payload concern. ai
bogus-package bogus-package AI (bogus-package): Package now has real content; prior empty-shell signal no longer applies to this established GitHub org SDK. ai
dependencies unvetted-dep:@github/copilot AI (dependencies): Both packages share the @github org scope; @github/copilot is GitHub's own Copilot CLI package, making this an expected first-party dependency for this SDK. ai
phantom-deps phantom-dep:@github/copilot AI (phantom-deps): Same-org dependency (@github scope); declared as runtime dep but bundled via esbuild. Not a security concern for this package. ai
phantom-deps phantom-dep:zod AI (phantom-deps): zod is a declared runtime dependency likely bundled via esbuild; phantom-dep finding reflects bundling strategy, not a security issue. ai

Versions (showing 38 of 38)

Version Deps Published
1.0.8 4 / 18
1.0.7 4 / 18
1.0.6 3 / 18
1.0.5 3 / 18
1.0.4 3 / 18
1.0.3 3 / 16
1.0.2 3 / 16
1.0.1 3 / 16
1.0.0 3 / 16
0.3.0 3 / 16
0.2.2 3 / 16
0.2.1 3 / 16
0.2.0 3 / 15
0.1.32 3 / 15
0.1.31 3 / 15
0.1.30 3 / 15
0.1.29 3 / 15
0.1.28 3 / 15
0.1.27 3 / 15
0.1.26 3 / 15
0.1.25 3 / 15
0.1.24 3 / 15
0.1.23 3 / 15
0.1.22 3 / 15
0.1.21 3 / 15
0.1.20 3 / 15
0.1.19 3 / 15
0.1.18 3 / 15
0.1.17 3 / 15
0.1.16 3 / 15
0.1.15 3 / 15
0.1.14 3 / 15
0.1.13 3 / 15
0.1.12 3 / 15
0.1.11 3 / 15
0.1.10 3 / 15
0.1.9 3 / 15
0.0.1 0 / 0

v1.0.8

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.5

2 findings
HIGH Low-value / spam package indicators (1 signals, score 3) bogus-package

[Reject — re-review on republish] (prior reject: AI (bogus-package): Package is an empty shell (0 code files, 59 bytes) with no metadata, occupying a high-value GitHub Copilot namespace. This pattern generalizes across all versions unless real conte) Matched 1 signal(s), weighted score 3: • [S_KNOWN_SPAM_PUBLISHER] Maintainer(s) previously flagged as spam: croffz, devm33, mxie-github, andreiig.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.