@inkeep/agents-cli
Inkeep CLI tool
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:keytar | AI (phantom-deps): keytar is a declared runtime dependency used via the postinstall script; phantom-dep heuristic is a false positive here. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs ensure-keytar.mjs to set up native keytar module; benign and consistent with keytar's documented install flow. | ai | |
| phantom-deps | phantom-dep:ts-morph | AI (phantom-deps): Code transform lib used indirectly; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:ast-types | AI (phantom-deps): Peer/transitive dep of recast; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/types | AI (phantom-deps): Framework-scoped, loaded by convention per analyzer note; stable false positive. | ai | |
| phantom-deps | phantom-dep:@inkeep/agents-manage-ui | AI (phantom-deps): Same org scope; may be loaded dynamically or via CLI dispatch; stable false positive. | ai | |
| phantom-deps | phantom-dep:inquirer-autocomplete-prompt | AI (phantom-deps): Inquirer plugin loaded by convention/registration; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): Framework-scoped, loaded by convention per analyzer note; stable false positive. | ai | |
| phantom-deps | phantom-dep:recast | AI (phantom-deps): AST transform lib likely used indirectly by build tooling; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ai | AI (phantom-deps): `ai` is explicitly listed in package.json dependencies; phantom-dep is a false positive here. | ai |
Versions (showing 51 of 158)
| Version | Deps | Published |
|---|---|---|
| 0.75.3 | 21 / 8 | |
| 0.75.0 | 21 / 8 | |
| 0.74.4 | 21 / 8 | |
| 0.74.3 | 21 / 8 | |
| 0.74.2 | 21 / 8 | |
| 0.74.1 | 21 / 8 | |
| 0.74.0 | 21 / 8 | |
| 0.73.5 | 21 / 8 | |
| 0.73.4 | 21 / 8 | |
| 0.73.3 | 21 / 8 | |
| 0.73.2 | 21 / 8 | |
| 0.73.1 | 21 / 8 | |
| 0.73.0 | 21 / 8 | |
| 0.72.2 | 21 / 8 | |
| 0.72.1 | 21 / 8 | |
| 0.72.0 | 21 / 8 | |
| 0.71.0 | 21 / 8 | |
| 0.70.8 | 21 / 8 | |
| 0.70.7 | 21 / 8 | |
| 0.70.5 | 21 / 8 | |
| 0.70.4 | 21 / 8 | |
| 0.70.3 | 21 / 8 | |
| 0.70.2 | 21 / 8 | |
| 0.70.1 | 21 / 8 | |
| 0.70.0 | 21 / 8 | |
| 0.69.0 | 21 / 8 | |
| 0.68.4 | 21 / 8 | |
| 0.68.3 | 21 / 8 | |
| 0.68.2 | 21 / 8 | |
| 0.68.1 | 21 / 8 | |
| 0.68.0 | 21 / 8 | |
| 0.67.4 | 21 / 8 | |
| 0.67.3 | 21 / 8 | |
| 0.67.2 | 21 / 8 | |
| 0.67.1 | 21 / 8 | |
| 0.67.0 | 21 / 8 | |
| 0.66.1 | 21 / 8 | |
| 0.66.0 | 21 / 8 | |
| 0.65.2 | 21 / 8 | |
| 0.65.1 | 21 / 8 | |
| 0.65.0 | 21 / 8 | |
| 0.64.10 | 21 / 8 | |
| 0.64.8 | 21 / 8 | |
| 0.64.7 | 21 / 8 | |
| 0.64.6 | 21 / 8 | |
| 0.64.2 | 21 / 8 | |
| 0.64.1 | 21 / 8 | |
| 0.63.3 | 21 / 8 | |
| 0.63.2 | 21 / 8 | |
| 0.63.1 | 21 / 8 | |
| 0.63.0 | 21 / 8 |
v0.75.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.75.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.74.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.73.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.72.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.72.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.72.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.71.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.70.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.69.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.68.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.67.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.66.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.66.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.65.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.65.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.65.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.64.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.64.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.64.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.64.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.64.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.64.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.63.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.