All @langchain/core versions

@langchain/core @0.3.80

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
70
Risk Score
MIT
License
No
Install Scripts
12
Dependencies
23
Dev Dependencies
483.7 KB
Package Size
Published

Core LangChain.js abstractions and schemas

Maintainers

hwchase17jacoblee93basprouleric_langchainandrewnguonlynfcamposdavidduongmaddyadamssam_noyeshntrlchristian-bromann

Keywords

llmaigpt3chainpromptprompt engineeringchatgptmachine learningmlopenaiembeddingsvectorstores

Dependencies (12)

PackageConstraintRegistry Status
zod ^3.25.32 auto_approved
uuid ^10.0.0 auto_approved
p-queue ^6.6.2 auto_approved
p-retry 4 auto_approved
mustache ^4.2.0 auto_approved
camelcase 6 auto_approved
langsmith ^0.3.67 auto_approved
decamelize 1.2.0 auto_approved
ansi-styles ^5.0.0 auto_approved
js-tiktoken ^1.0.12 auto_approved
zod-to-json-schema ^3.22.3 auto_approved
@cfworker/json-schema ^4.0.2 auto_approved

Dev Dependencies (23)

PackageConstraintRegistry Status
dpdm ^3.14.0 Not imported
jest ^29.5.0 auto_approved
eslint ^8.33.0 auto_approved
rimraf ^5.0.1 auto_approved
ts-jest ^29.1.0 auto_approved
prettier ^2.8.3 auto_approved
@swc/core ^1.3.90 auto_approved
@swc/jest ^0.2.29 auto_approved
ml-matrix ^6.10.4 pending
release-it ^18.1.2 pending
typescript ~5.8.3 auto_approved
@jest/globals ^29.5.0 auto_approved
@types/mustache ^4 auto_approved
@types/decamelize ^1.2.0 Not imported
@langchain/scripts >=0.1.0 <0.2.0 Not imported
eslint-plugin-jest ^27.6.0 auto_approved
eslint-plugin-import ^2.27.5 auto_approved
web-streams-polyfill ^4.0.0 auto_approved
jest-environment-node ^29.6.4 auto_approved
eslint-config-prettier ^8.6.0 auto_approved
eslint-plugin-prettier ^4.2.1 auto_approved
eslint-config-airbnb-base ^15.0.0 auto_approved
eslint-plugin-no-instanceof ^1.0.1 Not imported

Transitive Dependency Tree

16 transitive deps max depth 2
  ├─ @cfworker/json-schema ^4.0.2 → 4.1.1
  ├─ ansi-styles ^5.0.0 → 5.2.0
  ├─ camelcase 6 → 6.3.0
  ├─ decamelize 1.2.0 → 1.2.0
  ├─ js-tiktoken ^1.0.12 → 1.0.21
  ├─ langsmith ^0.3.67
  ├─ mustache ^4.2.0 → 4.2.0
  ├─ p-queue ^6.6.2 → 6.6.2
  ├─ p-retry 4 → 4.6.2
  ├─ uuid ^10.0.0 → 10.0.0
  ├─ zod ^3.25.32 → 3.25.76
├─ zod-to-json-schema ^3.22.3 → 3.25.2
  ├─ base64-js ^1.5.1 → 1.5.1
  ├─ eventemitter3 ^4.0.4 → 4.0.7
  ├─ p-timeout ^3.2.0
  ├─ retry ^0.13.1 → 0.13.1

Risk Dispositions (2 applicable to this version, 1 other)

Accepted rules are downgraded to INFO on future analyses; rejected rules escalate to CRITICAL.

Rule Source Disposition Author Reason
regressed-provenance provenance reject AI AI (provenance): High-value package that previously had CI/CD provenance; loss of attestation is a strong compromise indicator that should block all future versions until provenance is restored.
publisher-changed provenance reject AI AI (provenance): Publisher changed from GitHub Actions to a human account on a high-value package; combined with provenance regression this generalizes as a disqualifier until the transition is verified.
Show 1 disposition(s) that do not match any finding on this version
Rule Source Disposition Author Reason
osv:GHSA-r399-636x-v7f6 osv reject AI AI (osv): HIGH severity serialization injection vuln (CVSS 8.6) fixed in 1.1.8; all versions < 1.1.8 in the >= 1.0.0 range are affected. Verdict generalizes to every version in the affected range.

SAST Findings (2)

HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

HIGH Publisher changed: GitHub Actions → hntrl (on 2025-12-23) provenance

This version was published by a different npm account than previous versions on 2025-12-23. This could indicate a legitimate maintainer transition or an account compromise.

Review Summary

Risk score: 70. Findings: 2 high (+50), 2 medium (+20).

Published to npm: