@jaypie/mcp
Jaypie MCP
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are all from the same @jaypie/* monorepo or well-known packages (semver). Consistent with documented MCP/LLM feature expansion; SLSA provenance confirms CI/CD integrity. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): @jaypie/mcp is a scoped package in the established @jaypie namespace; Levenshtein comparison to 'yup' is a false positive — no brand impersonation. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a legitimate declared dependency; phantom detection likely reflects CLI/indirect usage patterns, not a real issue. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander is a legitimate declared dependency used for CLI tooling; phantom detection is a false positive for this package type. | ai |
Versions (showing 51 of 188)
| Version | Deps | Published |
|---|---|---|
| 0.8.112 | 7 / 9 | |
| 0.8.111 | 7 / 9 | |
| 0.8.110 | 7 / 9 | |
| 0.8.109 | 7 / 9 | |
| 0.8.108 | 7 / 9 | |
| 0.8.107 | 7 / 9 | |
| 0.8.106 | 7 / 9 | |
| 0.8.105 | 7 / 9 | |
| 0.8.104 | 7 / 9 | |
| 0.8.103 | 7 / 9 | |
| 0.8.102 | 7 / 9 | |
| 0.8.101 | 7 / 9 | |
| 0.8.100 | 7 / 9 | |
| 0.8.99 | 7 / 9 | |
| 0.8.98 | 7 / 9 | |
| 0.8.97 | 7 / 9 | |
| 0.8.96 | 7 / 9 | |
| 0.8.95 | 7 / 9 | |
| 0.8.94 | 7 / 9 | |
| 0.8.93 | 7 / 9 | |
| 0.8.92 | 7 / 9 | |
| 0.8.91 | 7 / 9 | |
| 0.8.90 | 7 / 9 | |
| 0.8.89 | 7 / 9 | |
| 0.8.88 | 7 / 9 | |
| 0.8.87 | 7 / 9 | |
| 0.8.86 | 7 / 9 | |
| 0.8.85 | 7 / 9 | |
| 0.8.84 | 7 / 9 | |
| 0.8.83 | 7 / 9 | |
| 0.8.82 | 7 / 9 | |
| 0.8.81 | 7 / 9 | |
| 0.8.80 | 7 / 9 | |
| 0.8.79 | 7 / 8 | |
| 0.8.78 | 7 / 8 | |
| 0.8.77 | 7 / 8 | |
| 0.8.76 | 7 / 8 | |
| 0.8.75 | 7 / 8 | |
| 0.8.74 | 7 / 8 | |
| 0.8.73 | 7 / 8 | |
| 0.8.72 | 7 / 8 | |
| 0.8.71 | 7 / 8 | |
| 0.8.70 | 7 / 8 | |
| 0.8.69 | 7 / 8 | |
| 0.8.68 | 7 / 8 | |
| 0.8.67 | 7 / 8 | |
| 0.8.66 | 7 / 8 | |
| 0.8.65 | 7 / 8 | |
| 0.8.64 | 7 / 8 | |
| 0.8.63 | 7 / 8 | |
| 0.8.62 | 7 / 8 |
v0.8.112
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.111
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.110
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.109
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.108
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.107
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.106
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.105
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.104
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.103
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.102
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.101
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.100
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.99
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.98
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.97
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.96
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.95
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.94
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.93
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.92
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.91
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.90
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.89
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.88
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.87
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.86
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.85
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.