@harness-engineering/orchestrator
Orchestrator daemon for dispatching coding agents to issues
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@harness-engineering/local-models | AI (dependencies): First-party sibling package within same org/monorepo, not a third-party unknown dep. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from manual publish to GitHub Actions CI; SLSA attestation and matching repo URL confirm legitimate handoff. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @google/genai is the official renamed successor to @google/generative-ai; not a suspicious dependency addition. | ai | |
| dependencies | unvetted-dep:@harness-engineering/core | AI (dependencies): First-party scoped dep from the same org; unvetted status reflects review lag, not external risk. | ai | |
| dependencies | unvetted-dep:@harness-engineering/types | AI (dependencies): First-party scoped dep from the same org; unvetted status reflects review lag, not external risk. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): chokidar is declared as a runtime dependency in package.json; phantom-dep fires because it's not directly imported in source, but it's a legitimate declared dep. | ai |
Versions (showing 50 of 50)
| Version | Deps | Published |
|---|---|---|
| 0.18.0 | 18 / 10 | |
| 0.17.0 | 18 / 10 | |
| 0.16.0 | 17 / 10 | |
| 0.15.1 | 17 / 10 | |
| 0.15.0 | 17 / 10 | |
| 0.14.0 | 17 / 10 | |
| 0.13.0 | 17 / 10 | |
| 0.12.0 | 17 / 10 | |
| 0.11.2 | 17 / 10 | |
| 0.11.1 | 17 / 10 | |
| 0.10.0 | 17 / 10 | |
| 0.9.2 | 16 / 10 | |
| 0.9.1 | 16 / 10 | |
| 0.9.0 | 16 / 10 | |
| 0.8.4 | 16 / 10 | |
| 0.8.3 | 16 / 10 | |
| 0.8.2 | 16 / 10 | |
| 0.8.1 | 16 / 10 | |
| 0.8.0 | 16 / 10 | |
| 0.7.0 | 16 / 10 | |
| 0.6.0 | 16 / 10 | |
| 0.5.0 | 16 / 10 | |
| 0.4.6 | 16 / 10 | |
| 0.4.5 | 16 / 10 | |
| 0.4.4 | 16 / 10 | |
| 0.4.3 | 16 / 10 | |
| 0.4.2 | 14 / 6 | |
| 0.4.1 | 14 / 6 | |
| 0.4.0 | 14 / 6 | |
| 0.3.2 | 14 / 6 | |
| 0.3.1 | 14 / 6 | |
| 0.3.0 | 14 / 6 | |
| 0.2.17 | 14 / 6 | |
| 0.2.16 | 14 / 6 | |
| 0.2.15 | 14 / 6 | |
| 0.2.14 | 14 / 6 | |
| 0.2.13 | 14 / 6 | |
| 0.2.12 | 14 / 6 | |
| 0.2.11 | 14 / 6 | |
| 0.2.10 | 14 / 6 | |
| 0.2.9 | 14 / 6 | |
| 0.2.8 | 14 / 6 | |
| 0.2.7 | 9 / 5 | |
| 0.2.6 | 6 / 5 | |
| 0.2.5 | 7 / 5 | |
| 0.2.4 | 7 / 5 | |
| 0.2.3 | 7 / 5 | |
| 0.2.2 | 7 / 5 | |
| 0.2.1 | 7 / 5 | |
| 0.2.0 | 7 / 5 |
v0.18.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.17.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.