@langchain/langgraph
LangGraph
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:langchain | AI (phantom-deps): Langchain is a core dependency re-exported by this wrapper; phantom-dep pattern is expected for orchestration libraries. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Zod is a direct dependency used in type validation; phantom-dep pattern is expected for schema libraries in wrapper packages. | ai | |
| phantom-deps | phantom-dep:@langchain/community | AI (phantom-deps): Same-org scoped dependency used in examples/config; phantom-dep pattern is expected in monorepo-style ecosystems. | ai | |
| phantom-deps | phantom-dep:@langchain/openai | AI (phantom-deps): Same-org scoped dependency used in examples/config; phantom-dep pattern is expected in monorepo-style ecosystems. | ai | |
| dependencies | unvetted-dep:double-ended-queue | AI (dependencies): double-ended-queue is a well-known, stable utility package with no security concerns; safe for use as a dependency in this package. | ai | |
| dependencies | unvetted-dep:@langchain/langgraph-checkpoint-sqlite | AI (dependencies): First-party sibling package from the same LangChain/LangGraph monorepo, published by the same trusted maintainer team. | ai | |
| provenance | publisher-changed | AI (provenance): davidduong is a known LangChain team publisher (714 days, 207 approved). Legitimate maintainer rotation within the langchain-ai org. | ai | |
| provenance | no-provenance | AI (provenance): Established LangChain package; lack of Sigstore provenance is a known gap for this package family, not a security indicator. | ai | |
| source-diff | encoded-string-file:dist/hash.js | AI (source-diff): The long hex string is the well-known XXH3 secret key constant, used by the xxHash hashing algorithm implementation. This is a legitimate cryptographic constant, not a malicious payload. | ai | |
| source-diff | encoded-string-file:dist/hash.cjs | AI (source-diff): The long hex string is the XXH3 hashing algorithm's secret/seed constant — a standard cryptographic constant used in the XXH3 implementation. Not a malicious payload. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @standard-schema/spec is a legitimate, widely-used schema interface package pinned to 1.1.0; consistent with LangGraph's schema validation support direction. | ai | |
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation via Sigstore, which is a stronger integrity signal. Missing gitHead reflects a CI pipeline change, not a malicious publish. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer change is within the langchain-ai org; hntrl is a known LangChain contributor. Legitimate transition, not a takeover. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): benjamincburns removal is part of a legitimate org-level maintainer transition within langchain-ai. | ai | |
| dependencies | unvetted-dep:@langchain/langgraph-sdk | AI (dependencies): First-party LangChain sibling package published by the same org; expected dependency for langgraph ecosystem packages. | ai | |
| dependencies | unvetted-dep:@langchain/langgraph-checkpoint | AI (dependencies): First-party LangChain sibling package published by the same org; expected dependency for langgraph ecosystem packages. | ai |
Versions (showing 77 of 177)
| Version | Deps | Published |
|---|---|---|
| 0.2.26 | 4 / 37 | |
| 0.2.25 | 4 / 37 | |
| 0.2.24 | 4 / 37 | |
| 0.2.23 | 4 / 37 | |
| 0.2.22 | 4 / 37 | |
| 0.2.21 | 4 / 37 | |
| 0.2.20 | 4 / 37 | |
| 0.2.19 | 5 / 38 | |
| 0.2.18 | 4 / 38 | |
| 0.2.17 | 4 / 38 | |
| 0.2.16 | 4 / 38 | |
| 0.2.15 | 4 / 38 | |
| 0.2.14 | 4 / 38 | |
| 0.2.13 | 4 / 38 | |
| 0.2.12 | 4 / 35 | |
| 0.2.11 | 4 / 35 | |
| 0.2.10 | 4 / 35 | |
| 0.2.9 | 4 / 35 | |
| 0.2.8 | 4 / 35 | |
| 0.2.7 | 4 / 35 | |
| 0.2.6 | 4 / 35 | |
| 0.2.5 | 4 / 35 | |
| 0.2.4 | 4 / 35 | |
| 0.2.3 | 4 / 35 | |
| 0.2.2 | 4 / 35 | |
| 0.2.1 | 4 / 35 | |
| 0.2.0 | 4 / 35 | |
| 0.1.9 | 6 / 34 | |
| 0.1.8 | 6 / 34 | |
| 0.1.7 | 6 / 34 | |
| 0.1.6 | 6 / 34 | |
| 0.1.5 | 6 / 34 | |
| 0.1.4 | 6 / 34 | |
| 0.1.3 | 6 / 34 | |
| 0.1.2 | 6 / 33 | |
| 0.1.1 | 6 / 33 | |
| 0.1.0 | 6 / 33 | |
| 0.0.34 | 3 / 34 | |
| 0.0.33 | 3 / 33 | |
| 0.0.32 | 3 / 33 | |
| 0.0.31 | 3 / 33 | |
| 0.0.30 | 3 / 33 | |
| 0.0.29 | 3 / 33 | |
| 0.0.28 | 3 / 33 | |
| 0.0.27 | 3 / 33 | |
| 0.0.26 | 2 / 34 | |
| 0.0.25 | 2 / 34 | |
| 0.0.24 | 2 / 32 | |
| 0.0.23 | 2 / 32 | |
| 0.0.22 | 2 / 32 | |
| 0.0.21 | 2 / 32 | |
| 0.0.20 | 2 / 32 | |
| 0.0.19 | 2 / 32 | |
| 0.0.18 | 2 / 31 | |
| 0.0.17 | 2 / 31 | |
| 0.0.16 | 2 / 31 | |
| 0.0.15 | 2 / 31 | |
| 0.0.14 | 2 / 31 | |
| 0.0.13 | 3 / 30 | |
| 0.0.12 | 1 / 28 | |
| 0.0.11 | 1 / 28 | |
| 0.0.10 | 1 / 28 | |
| 0.0.9 | 1 / 27 | |
| 0.0.8 | 1 / 27 | |
| 0.0.7 | 1 / 27 | |
| 0.0.6 | 1 / 27 | |
| 0.0.5 | 1 / 27 | |
| 0.0.4 | 1 / 27 | |
| 0.0.3 | 1 / 27 | |
| 0.0.2 | 1 / 26 | |
| 0.0.1 | 5 / 23 | |
| 1.0.0-alpha.5 | 3 / 37 | |
| 1.0.0-alpha.4 | 3 / 37 | |
| 1.0.0-alpha.3 | 3 / 37 | |
| 1.0.0-alpha.2 | 3 / 37 | |
| 1.0.0-alpha.1 | 3 / 37 | |
| 1.0.0-alpha.0 | 3 / 38 |
v0.2.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.34
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.33
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.32
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.31
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.30
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.29
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.28
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.27
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.26
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.25
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.24
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.22
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.21
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.20
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.19
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.18
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.17
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.16
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0-alpha.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0-alpha.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0-alpha.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0-alpha.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0-alpha.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0-alpha.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.