@grafana/sigil-pi
Pi agent extension for Grafana Sigil AI telemetry
16
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
gf_joshhuntgrafanabot
Keywords
pi-package
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Grafana monorepo SDK placeholder; 0.0.0 is a known pattern for initial scoped package stubs under @grafana. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Sparse metadata is expected for a new monorepo plugin stub; not indicative of spam or malice given the @grafana scope and grafanabot publisher. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.17.0 | 2 / 13 | |
| 0.16.0 | 2 / 13 | |
| 0.15.0 | 2 / 13 | |
| 0.14.0 | 2 / 13 | |
| 0.13.0 | 2 / 13 | |
| 0.12.0 | 2 / 13 | |
| 0.11.0 | 2 / 13 | |
| 0.10.0 | 2 / 13 | |
| 0.9.0 | 2 / 13 | |
| 0.8.0 | 2 / 13 | |
| 0.7.0 | 2 / 13 | |
| 0.6.0 | 2 / 13 | |
| 0.5.0 | 2 / 12 | |
| 0.4.0 | 2 / 12 | |
| 0.3.1 | 2 / 12 | |
| 0.0.0 | 0 / 0 |
v0.17.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.