← Home

@inkeep/agents-core

Agents Core contains the database schema, types, and validation schemas for Inkeep Agent Framework, along with core components.

100
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

maria_inkeepabraham-inkeepnick-inkeeprobert-inkeepsarah-inkeepandrew-inkeepomar-inkeepmiles-inkeep

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:better-auth AI (phantom-deps): Config-referenced optional dependency; stable pattern for this framework package. ai
phantom-deps phantom-dep:@electric-sql/pglite AI (phantom-deps): Config-referenced optional dependency; stable pattern for this framework package. ai
phantom-deps phantom-dep:@better-auth/sso AI (phantom-deps): Config-referenced optional dependency; stable pattern for this framework package. ai
phantom-deps phantom-dep:ai AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:jose AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:find-up AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:exit-hook AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:ts-pattern AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:dotenv-expand AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@libsql/client AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@nangohq/node AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:pg AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:jmespath AI (phantom-deps): Config-referenced optional dependency; stable pattern for this package. ai
phantom-deps phantom-dep:postgres AI (phantom-deps): Used indirectly via config, not a malicious dep. ai
vendored-integrity unresolved-vendored-tree:dist/node_modules/.pnpm/@[email protected]/node_modules/@vitest/utils AI (vendored-integrity): Vitest transitive test dep, benign build artifact. ai
vendored-integrity unresolved-vendored-tree:dist/node_modules/.pnpm AI (vendored-integrity): Leftover pnpm-linked devDeps (test tooling) bundled in dist, not an implant. ai
vendored-integrity unresolved-vendored-tree:dist/node_modules/.pnpm/[email protected]/node_modules/loupe AI (vendored-integrity): Vitest transitive test dep, benign build artifact. ai
phantom-deps phantom-dep:@opentelemetry/semantic-conventions AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/baggage-span-processor AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/exporter-trace-otlp-proto AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/auto-instrumentations-node AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/sdk-node AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:ajv-formats AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@nangohq/types AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@hono/node-server AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/sdk-metrics AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/sdk-trace-node AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/exporter-jaeger AI (phantom-deps): Declared and used; phantom-dep heuristic false positive for this package. ai
source-diff net-exec-file:dist/node_modules/.pnpm/@[email protected]/node_modules/@vitest/snapshot/dist/index.js AI (source-diff): File is bundled @vitest/snapshot test utility; VLQ/source-map code triggered the rule, not actual network+exec malware. ai

Versions (showing 100 of 271)

Version Deps Published
0.80.5 48 / 9
0.80.4 48 / 9
0.80.3 48 / 9
0.80.2 48 / 9
0.80.0 48 / 9
0.79.1 48 / 9
0.79.0 48 / 9
0.78.5 48 / 9
0.78.4 48 / 9
0.78.3 48 / 9
0.78.2 48 / 9
0.78.1 48 / 9
0.78.0 48 / 9
0.77.1 48 / 9
0.77.0 48 / 9
0.75.4 45 / 9
0.75.3 45 / 9
0.75.0 45 / 9
0.74.4 45 / 9
0.74.3 45 / 9
0.74.2 45 / 9
0.74.1 45 / 9
0.74.0 45 / 9
0.73.5 45 / 9
0.73.4 45 / 9
0.73.3 45 / 9
0.73.2 45 / 9
0.73.1 45 / 9
0.73.0 45 / 9
0.72.2 45 / 9
0.72.1 45 / 9
0.72.0 45 / 9
0.71.0 45 / 9
0.70.8 45 / 9
0.70.7 45 / 9
0.70.5 45 / 9
0.70.4 45 / 9
0.70.3 45 / 9
0.70.2 45 / 9
0.70.1 45 / 9
0.70.0 45 / 9
0.69.0 45 / 9
0.68.4 45 / 9
0.68.3 45 / 9
0.68.2 45 / 9
0.68.1 45 / 9
0.68.0 45 / 9
0.67.4 44 / 9
0.67.3 44 / 9
0.67.2 44 / 9
0.67.1 44 / 9
0.67.0 44 / 9
0.66.1 44 / 9
0.66.0 44 / 9
0.65.2 44 / 9
0.65.1 44 / 9
0.65.0 44 / 9
0.64.10 44 / 9
0.64.8 44 / 9
0.64.7 44 / 9
0.64.6 44 / 9
0.64.2 45 / 9
0.64.1 45 / 9
0.63.3 45 / 9
0.63.2 45 / 9
0.63.1 43 / 9
0.63.0 43 / 9
0.62.2 42 / 9
0.62.1 42 / 9
0.62.0 42 / 9
0.61.0 42 / 9
0.60.0 42 / 9
0.59.4 42 / 9
0.59.3 42 / 9
0.59.2 42 / 9
0.59.1 42 / 9
0.59.0 42 / 9
0.58.21 41 / 9
0.58.20 41 / 9
0.58.19 41 / 9
0.58.18 41 / 9
0.58.17 41 / 9
0.58.16 41 / 9
0.58.15 41 / 9
0.58.14 41 / 9
0.58.13 41 / 9
0.58.12 41 / 9
0.58.10 41 / 9
0.58.9 41 / 9
0.58.8 41 / 9
0.58.7 40 / 9
0.58.6 40 / 9
0.58.5 40 / 9
0.58.4 40 / 9
0.58.3 40 / 9
0.58.2 40 / 9
0.58.1 40 / 9
0.58.0 40 / 9
0.57.0 40 / 9
0.56.2 40 / 9
Showing 100 of 271 Next page →

v0.80.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.80.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.80.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.75.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.74.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.74.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.74.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.74.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.74.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.73.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.73.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.73.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.73.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.73.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.73.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.72.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.72.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.72.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.71.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.70.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.62.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.62.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.61.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.60.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.59.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.59.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.59.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.59.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.59.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.58.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.57.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.56.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.