@kubb/agent
Agent server for Kubb, enabling HTTP-based access to code generation capabilities.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Nitro bundled runtime util, standard base64 helper, no exfil behavior. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in a Proxy trap inside bundled nitro output; benign. | ai | |
| phantom-deps | phantom-dep:nitropack | AI (phantom-deps): Used via config/build scripts, not direct import; false positive. | ai | |
| source-diff | obfuscated-file:.output/server/node_modules/consola/dist/index.mjs | AI (source-diff): Bundled third-party consola lib in build output, not obfuscated package code. | ai | |
| source-diff | obfuscated-file:.output/server/node_modules/consola/dist/chunks/prompt.mjs | AI (source-diff): Bundled third-party consola lib in build output, not obfuscated package code. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-swr | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-zod | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-faker | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-redoc | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-client | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/core | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-vue-query | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-react-query | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-solid-query | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-svelte-query | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:unstorage | AI (phantom-deps): Declared dep used in config/runtime; phantom-dep heuristic miss. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-cypress | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-ts | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-mcp | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-msw | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai | |
| phantom-deps | phantom-dep:@kubb/plugin-oas | AI (phantom-deps): Same-org plugin dep; agent aggregates plugins without direct imports. | ai |
Versions (showing 51 of 53)
| Version | Deps | Published |
|---|---|---|
| 4.37.12 | 23 / 5 | |
| 4.37.11 | 23 / 5 | |
| 4.37.10 | 23 / 5 | |
| 4.37.9 | 23 / 5 | |
| 4.37.8 | 23 / 5 | |
| 4.37.5 | 23 / 5 | |
| 4.37.4 | 23 / 5 | |
| 4.37.3 | 23 / 5 | |
| 4.37.2 | 23 / 5 | |
| 4.37.1 | 23 / 5 | |
| 4.37.0 | 23 / 5 | |
| 4.36.5 | 23 / 5 | |
| 4.36.4 | 23 / 5 | |
| 4.36.3 | 23 / 5 | |
| 4.36.2 | 23 / 5 | |
| 4.36.1 | 23 / 5 | |
| 4.36.0 | 23 / 5 | |
| 4.35.1 | 23 / 5 | |
| 4.35.0 | 23 / 5 | |
| 4.34.0 | 23 / 5 | |
| 4.33.5 | 23 / 5 | |
| 4.33.4 | 23 / 5 | |
| 4.33.3 | 23 / 5 | |
| 4.33.2 | 23 / 5 | |
| 4.33.1 | 23 / 5 | |
| 4.33.0 | 23 / 4 | |
| 4.32.4 | 23 / 4 | |
| 4.32.3 | 23 / 4 | |
| 4.32.2 | 23 / 4 | |
| 4.32.1 | 23 / 4 | |
| 4.32.0 | 23 / 4 | |
| 4.31.6 | 23 / 4 | |
| 4.31.5 | 23 / 4 | |
| 4.31.4 | 23 / 4 | |
| 4.31.3 | 23 / 4 | |
| 4.31.2 | 23 / 4 | |
| 4.31.1 | 23 / 4 | |
| 4.31.0 | 23 / 4 | |
| 4.29.1 | 19 / 4 | |
| 4.29.0 | 19 / 4 | |
| 4.28.1 | 21 / 4 | |
| 4.28.0 | 21 / 4 | |
| 4.27.4 | 21 / 4 | |
| 4.27.2 | 22 / 3 | |
| 4.27.1 | 22 / 3 | |
| 4.27.0 | 21 / 3 | |
| 4.26.1 | 8 / 3 | |
| 4.26.0 | 8 / 3 | |
| 4.25.2 | 8 / 3 | |
| 4.25.1 | 7 / 2 | |
| 4.25.0 | 7 / 2 |
v4.37.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.36.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.36.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.36.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.36.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.36.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.36.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.35.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.35.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.34.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.33.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.33.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.33.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.33.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.33.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.33.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.32.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.32.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.32.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.32.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.32.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.31.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.31.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.31.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.31.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.31.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.31.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.31.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.29.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.29.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.28.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.28.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.27.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.27.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.27.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.27.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.26.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.25.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.25.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.