@hasna/todos
Universal task management for AI coding agents - CLI + MCP server + interactive TUI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Metadata-only regression, no malicious behavior observed. | ai | |
| dependencies | unvetted-dep:@hasna/logs | AI (dependencies): First-party same-org package, not third-party unvetted code. | ai | |
| phantom-deps | phantom-dep:@hasna/events | AI (phantom-deps): Same-org dep used in bundled build; not scannable as import. | ai | |
| source-diff | obfuscated-file:dashboard/dist/assets/index-aJefI7kh.js | AI (source-diff): Minified Vite/React build output with intact license banners, not obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): First-party monorepo sibling dependency, not a third-party supply-chain vector. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. | ai | |
| source-diff | obfuscated-file:dashboard/dist/assets/index-C3fBxEWP.js | AI (source-diff): Standard Vite-bundled React dashboard output; sample confirms React JSX runtime, not obfuscation. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. | ai | |
| source-diff | obfuscated-file:dashboard/dist/assets/index-DVotjwab.js | AI (source-diff): Standard Vite/React production bundle; React license headers confirm legitimate minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dashboard/dist/assets/index-B-w1tUlm.js | AI (source-diff): Standard Vite/React minified dashboard bundle; React license headers confirm legitimate build output. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall only creates local config directories; no network access or code execution. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a common validation lib; phantom finding likely reflects config-only reference pattern. | ai | |
| phantom-deps | phantom-dep:@hasna/cloud | AI (phantom-deps): Same-org dep; phantom finding indicates it may be an indirect/optional usage pattern. | ai |
Versions (showing 90 of 90)
| Version | Deps | Published |
|---|---|---|
| 0.11.81 | 8 / 4 | |
| 0.11.67 | 7 / 4 | |
| 0.11.54 | 7 / 4 | |
| 0.11.48 | 6 / 4 | |
| 0.11.40 | 6 / 3 | |
| 0.11.39 | 6 / 3 | |
| 0.11.36 | 8 / 3 | |
| 0.11.30 | 7 / 3 | |
| 0.11.29 | 7 / 3 | |
| 0.11.24 | 7 / 3 | |
| 0.11.20 | 7 / 3 | |
| 0.11.18 | 7 / 3 | |
| 0.11.10 | 7 / 3 | |
| 0.11.4 | 7 / 3 | |
| 0.11.3 | 7 / 3 | |
| 0.11.2 | 6 / 3 | |
| 0.11.1 | 6 / 3 | |
| 0.10.22 | 6 / 3 | |
| 0.10.21 | 6 / 3 | |
| 0.10.20 | 6 / 3 | |
| 0.10.19 | 6 / 3 | |
| 0.10.18 | 6 / 3 | |
| 0.10.17 | 6 / 3 | |
| 0.10.16 | 6 / 3 | |
| 0.10.15 | 6 / 3 | |
| 0.10.14 | 6 / 3 | |
| 0.10.13 | 6 / 3 | |
| 0.10.11 | 6 / 3 | |
| 0.10.10 | 6 / 3 | |
| 0.10.9 | 6 / 3 | |
| 0.10.8 | 6 / 3 | |
| 0.10.7 | 6 / 3 | |
| 0.10.5 | 6 / 3 | |
| 0.10.4 | 6 / 3 | |
| 0.10.3 | 6 / 3 | |
| 0.10.2 | 6 / 3 | |
| 0.10.1 | 6 / 3 | |
| 0.9.83 | 6 / 3 | |
| 0.9.82 | 6 / 3 | |
| 0.9.81 | 6 / 3 | |
| 0.9.80 | 6 / 3 | |
| 0.9.79 | 6 / 3 | |
| 0.9.77 | 6 / 3 | |
| 0.9.76 | 6 / 3 | |
| 0.9.75 | 6 / 3 | |
| 0.9.74 | 6 / 3 | |
| 0.9.73 | 6 / 3 | |
| 0.9.69 | 6 / 3 | |
| 0.9.68 | 6 / 3 | |
| 0.9.67 | 6 / 3 | |
| 0.9.66 | 6 / 3 | |
| 0.9.65 | 6 / 3 | |
| 0.9.64 | 6 / 3 | |
| 0.9.63 | 6 / 3 | |
| 0.9.62 | 6 / 3 | |
| 0.9.58 | 6 / 3 | |
| 0.9.56 | 6 / 3 | |
| 0.9.55 | 6 / 3 | |
| 0.9.54 | 6 / 3 | |
| 0.9.53 | 6 / 3 | |
| 0.9.48 | 6 / 3 | |
| 0.9.33 | 6 / 3 | |
| 0.9.7 | 6 / 3 | |
| 0.9.6 | 6 / 3 | |
| 0.9.5 | 6 / 3 | |
| 0.9.4 | 6 / 3 | |
| 0.9.3 | 6 / 3 | |
| 0.9.2 | 6 / 3 | |
| 0.9.1 | 6 / 3 | |
| 0.9.0 | 6 / 3 | |
| 0.8.0 | 7 / 3 | |
| 0.7.0 | 7 / 3 | |
| 0.6.1 | 6 / 3 | |
| 0.6.0 | 6 / 3 | |
| 0.5.1 | 6 / 3 | |
| 0.5.0 | 6 / 3 | |
| 0.4.1 | 6 / 3 | |
| 0.4.0 | 6 / 3 | |
| 0.3.6 | 6 / 3 | |
| 0.3.5 | 6 / 3 | |
| 0.3.4 | 6 / 3 | |
| 0.3.3 | 6 / 3 | |
| 0.3.2 | 6 / 3 | |
| 0.3.1 | 6 / 3 | |
| 0.3.0 | 6 / 3 | |
| 0.2.2 | 6 / 3 | |
| 0.2.1 | 6 / 3 | |
| 0.2.0 | 6 / 3 | |
| 0.1.1 | 6 / 3 | |
| 0.1.0 | 6 / 3 |
v0.11.81
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.67
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.54
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.83
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.82
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.81
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.80
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.79
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.74
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.73
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.69
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.68
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.67
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.66
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.65
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.64
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.63
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.62
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.58
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.56
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.55
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.54
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.53
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.48
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.