@hasna/mementos
Universal memory system for AI agents - CLI + MCP server + library API
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Provenance direction unchanged; likely build-env variance, not takeover. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Well-known libs matching stated CLI/dashboard/OCR features. | ai | |
| source-diff | obfuscated-file:dashboard/dist/assets/index-DqyMbv89.js | AI (source-diff): Vite-bundled dashboard JS with React banner, not true obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundled build output for new dashboard/CLI/MCP surfaces. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Expected growth from new dashboard bundle and dependencies. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/anthropic | AI (phantom-deps): Config-referenced AI SDK dep, benign. | ai | |
| phantom-deps | phantom-dep:@hasna/events | AI (phantom-deps): Same-org package, expected phantom pattern. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/openai | AI (phantom-deps): Config-referenced AI SDK dep, benign. | ai | |
| phantom-deps | phantom-dep:ai | AI (phantom-deps): Used via build externals/config, not a direct import concern. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/openai-compatible | AI (phantom-deps): Config-referenced AI SDK dep, benign. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Deps are bundled via bun build; phantom-dep false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): Deps are bundled via bun build; phantom-dep false positive for this bundled package. | ai | |
| phantom-deps | phantom-dep:pdf-parse | AI (phantom-deps): Bundled externally; phantom-dep is a false positive for this build setup. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall only creates local config directories under $HOME; no network access or code execution. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Externalized at build time via bun build --external ink; not directly imported in dist. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Bundled externally; phantom-dep is a false positive for this build setup. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Externalized at build time; not directly imported in dist. | ai | |
| phantom-deps | phantom-dep:tesseract.js | AI (phantom-deps): Bundled externally; phantom-dep is a false positive for this build setup. | ai |
Versions (showing 100 of 109)
| Version | Deps | Published |
|---|---|---|
| 0.14.50 | 15 / 4 | |
| 0.14.47 | 15 / 4 | |
| 0.14.36 | 9 / 4 | |
| 0.14.35 | 9 / 3 | |
| 0.14.33 | 0 / 0 | |
| 0.14.32 | 9 / 3 | |
| 0.14.31 | 0 / 0 | |
| 0.14.30 | 0 / 0 | |
| 0.14.29 | 0 / 0 | |
| 0.14.28 | 0 / 0 | |
| 0.14.27 | 0 / 0 | |
| 0.14.26 | 0 / 0 | |
| 0.14.25 | 0 / 0 | |
| 0.14.24 | 0 / 0 | |
| 0.14.23 | 0 / 0 | |
| 0.14.22 | 0 / 0 | |
| 0.14.21 | 9 / 3 | |
| 0.14.20 | 9 / 3 | |
| 0.14.19 | 9 / 3 | |
| 0.14.18 | 9 / 3 | |
| 0.14.16 | 9 / 3 | |
| 0.14.15 | 9 / 3 | |
| 0.14.14 | 9 / 3 | |
| 0.14.12 | 9 / 3 | |
| 0.14.11 | 9 / 3 | |
| 0.14.10 | 9 / 3 | |
| 0.14.8 | 9 / 3 | |
| 0.14.7 | 9 / 3 | |
| 0.14.4 | 9 / 3 | |
| 0.14.3 | 8 / 3 | |
| 0.14.2 | 8 / 3 | |
| 0.14.0 | 8 / 3 | |
| 0.11.1 | 6 / 3 | |
| 0.11.0 | 6 / 3 | |
| 0.10.19 | 6 / 3 | |
| 0.10.18 | 6 / 3 | |
| 0.10.17 | 6 / 3 | |
| 0.10.16 | 6 / 3 | |
| 0.10.15 | 6 / 3 | |
| 0.10.14 | 6 / 3 | |
| 0.10.13 | 6 / 3 | |
| 0.10.12 | 6 / 3 | |
| 0.10.11 | 6 / 3 | |
| 0.10.10 | 6 / 3 | |
| 0.10.9 | 6 / 3 | |
| 0.10.8 | 6 / 3 | |
| 0.10.6 | 6 / 3 | |
| 0.10.5 | 6 / 3 | |
| 0.10.4 | 6 / 3 | |
| 0.10.3 | 6 / 3 | |
| 0.10.2 | 6 / 3 | |
| 0.10.1 | 6 / 3 | |
| 0.10.0 | 6 / 3 | |
| 0.9.0 | 6 / 3 | |
| 0.8.0 | 6 / 3 | |
| 0.7.0 | 6 / 3 | |
| 0.6.0 | 6 / 3 | |
| 0.4.41 | 6 / 3 | |
| 0.4.39 | 6 / 3 | |
| 0.4.38 | 6 / 3 | |
| 0.4.37 | 6 / 3 | |
| 0.4.36 | 6 / 3 | |
| 0.4.35 | 6 / 3 | |
| 0.4.34 | 6 / 3 | |
| 0.4.33 | 6 / 3 | |
| 0.4.32 | 6 / 3 | |
| 0.4.31 | 6 / 3 | |
| 0.4.30 | 6 / 3 | |
| 0.4.29 | 6 / 3 | |
| 0.4.28 | 6 / 3 | |
| 0.4.27 | 6 / 3 | |
| 0.4.26 | 6 / 3 | |
| 0.4.25 | 6 / 3 | |
| 0.4.24 | 6 / 3 | |
| 0.4.23 | 6 / 3 | |
| 0.4.22 | 6 / 3 | |
| 0.4.21 | 6 / 3 | |
| 0.4.20 | 6 / 3 | |
| 0.4.19 | 6 / 3 | |
| 0.4.17 | 6 / 3 | |
| 0.4.16 | 6 / 3 | |
| 0.4.15 | 6 / 3 | |
| 0.4.14 | 6 / 3 | |
| 0.4.13 | 6 / 3 | |
| 0.4.12 | 6 / 3 | |
| 0.4.11 | 6 / 3 | |
| 0.4.10 | 6 / 3 | |
| 0.4.9 | 6 / 3 | |
| 0.4.8 | 6 / 3 | |
| 0.4.7 | 6 / 3 | |
| 0.4.6 | 6 / 3 | |
| 0.4.5 | 6 / 3 | |
| 0.4.4 | 6 / 3 | |
| 0.4.3 | 6 / 3 | |
| 0.4.2 | 6 / 3 | |
| 0.4.1 | 6 / 3 | |
| 0.3.9 | 6 / 3 | |
| 0.3.7 | 6 / 3 | |
| 0.3.6 | 6 / 3 | |
| 0.3.5 | 6 / 3 |
v0.14.50
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.47
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.