← Home

@hasna/todos

Universal task management for AI coding agents - CLI + MCP server + interactive TUI

90
Versions
Apache-2.0
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

andreihasna2

Keywords

todostasksmcpaicoding-agentclaudecodexgeminituiclidashboard

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Metadata-only regression, no malicious behavior observed. ai
dependencies unvetted-dep:@hasna/logs AI (dependencies): First-party same-org package, not third-party unvetted code. ai
phantom-deps phantom-dep:@hasna/events AI (phantom-deps): Same-org dep used in bundled build; not scannable as import. ai
source-diff obfuscated-file:dashboard/dist/assets/index-aJefI7kh.js AI (source-diff): Minified Vite/React build output with intact license banners, not obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): First-party monorepo sibling dependency, not a third-party supply-chain vector. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. ai
source-diff obfuscated-file:dashboard/dist/assets/index-C3fBxEWP.js AI (source-diff): Standard Vite-bundled React dashboard output; sample confirms React JSX runtime, not obfuscation. ai
phantom-deps phantom-dep:ink AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. ai
phantom-deps phantom-dep:react AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Explicitly marked external in bun build command; not imported directly by design. ai
source-diff obfuscated-file:dashboard/dist/assets/index-DVotjwab.js AI (source-diff): Standard Vite/React production bundle; React license headers confirm legitimate minified output, not obfuscation. ai
source-diff obfuscated-file:dashboard/dist/assets/index-B-w1tUlm.js AI (source-diff): Standard Vite/React minified dashboard bundle; React license headers confirm legitimate build output. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall only creates local config directories; no network access or code execution. ai
phantom-deps phantom-dep:zod AI (phantom-deps): zod is a common validation lib; phantom finding likely reflects config-only reference pattern. ai
phantom-deps phantom-dep:@hasna/cloud AI (phantom-deps): Same-org dep; phantom finding indicates it may be an indirect/optional usage pattern. ai

Versions (showing 90 of 90)

Version Deps Published
0.11.81 8 / 4
0.11.67 7 / 4
0.11.54 7 / 4
0.11.48 6 / 4
0.11.40 6 / 3
0.11.39 6 / 3
0.11.36 8 / 3
0.11.30 7 / 3
0.11.29 7 / 3
0.11.24 7 / 3
0.11.20 7 / 3
0.11.18 7 / 3
0.11.10 7 / 3
0.11.4 7 / 3
0.11.3 7 / 3
0.11.2 6 / 3
0.11.1 6 / 3
0.10.22 6 / 3
0.10.21 6 / 3
0.10.20 6 / 3
0.10.19 6 / 3
0.10.18 6 / 3
0.10.17 6 / 3
0.10.16 6 / 3
0.10.15 6 / 3
0.10.14 6 / 3
0.10.13 6 / 3
0.10.11 6 / 3
0.10.10 6 / 3
0.10.9 6 / 3
0.10.8 6 / 3
0.10.7 6 / 3
0.10.5 6 / 3
0.10.4 6 / 3
0.10.3 6 / 3
0.10.2 6 / 3
0.10.1 6 / 3
0.9.83 6 / 3
0.9.82 6 / 3
0.9.81 6 / 3
0.9.80 6 / 3
0.9.79 6 / 3
0.9.77 6 / 3
0.9.76 6 / 3
0.9.75 6 / 3
0.9.74 6 / 3
0.9.73 6 / 3
0.9.69 6 / 3
0.9.68 6 / 3
0.9.67 6 / 3
0.9.66 6 / 3
0.9.65 6 / 3
0.9.64 6 / 3
0.9.63 6 / 3
0.9.62 6 / 3
0.9.58 6 / 3
0.9.56 6 / 3
0.9.55 6 / 3
0.9.54 6 / 3
0.9.53 6 / 3
0.9.48 6 / 3
0.9.33 6 / 3
0.9.7 6 / 3
0.9.6 6 / 3
0.9.5 6 / 3
0.9.4 6 / 3
0.9.3 6 / 3
0.9.2 6 / 3
0.9.1 6 / 3
0.9.0 6 / 3
0.8.0 7 / 3
0.7.0 7 / 3
0.6.1 6 / 3
0.6.0 6 / 3
0.5.1 6 / 3
0.5.0 6 / 3
0.4.1 6 / 3
0.4.0 6 / 3
0.3.6 6 / 3
0.3.5 6 / 3
0.3.4 6 / 3
0.3.3 6 / 3
0.3.2 6 / 3
0.3.1 6 / 3
0.3.0 6 / 3
0.2.2 6 / 3
0.2.1 6 / 3
0.2.0 6 / 3
0.1.1 6 / 3
0.1.0 6 / 3

v0.11.81

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.67

2 findings
HIGH New obfuscated file: dashboard/dist/assets/index-DVotjwab.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.54

2 findings
HIGH New obfuscated file: dashboard/dist/assets/index-aJefI7kh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.83

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.82

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.81

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.80

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.79

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.74

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.73

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.69

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.68

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.67

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.66

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.65

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.64

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.63

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.62

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.58

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.56

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.55

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.54

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.53

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.48

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.7

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: andreihasna2.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.