← Home

@livekit/agents

76
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

rdsathedavidzhaofeepslkmatkam_livekitraja-livekitlivekitherzoglukasiopaulwedliulkdanm_livekitocupe_livekitcacheonlysfkatbcherrylkrektdeckardjason.lernermantom.ezquerrothomasyuill-livekitlk-toubatbrianrgauslivekit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@livekit/av AI (dependencies): First-party LiveKit sibling package, not third-party unvetted code. ai
phantom-deps phantom-dep:ofetch AI (phantom-deps): Used via config/build tooling, common false positive. ai
dependencies unvetted-dep:@livekit/local-inference AI (dependencies): First-party @livekit org package; same publisher trust as the parent package. ai
bogus-package bogus-package AI (bogus-package): Well-established package; no-keywords/short-README are false positives for a monorepo sub-package. ai
semgrep semgrep:env-spread AI (semgrep): Only in test files; saves/restores env for test isolation. ai
maintainer-change maintainer-removed AI (maintainer-change): Removals paired with additions on an active org package reflect normal team rotation, not a takeover. ai
provenance publisher-changed AI (provenance): LiveKit org uses GitHub Actions CI/CD with SLSA provenance; publisher=GitHub Actions is expected for this package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers have livekit-org handles; consistent with team growth on an active org package. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): pino-pretty is declared as a runtime dep and used as a pino transport; not directly imported in source is expected. ai
semgrep semgrep:base64-decode AI (semgrep): Decodes audio data from WebSocket server events; not a payload loader. ai
phantom-deps phantom-dep:@opentelemetry/exporter-logs-otlp-proto AI (phantom-deps): OpenTelemetry packages loaded by convention/config; stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/instrumentation-pino AI (phantom-deps): OpenTelemetry packages loaded by convention/config; stable false positive for this package. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): OpenTelemetry packages loaded by convention/config; stable false positive for this package. ai
phantom-deps phantom-dep:@types/pidusage AI (phantom-deps): Type-only package used at compile time; not directly imported at runtime. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Standard Proxy trap using Reflect.get; not obfuscation. ai

Versions (showing 76 of 76)

Version Deps Published
1.5.3 35 / 9
1.5.1 35 / 9
1.5.0 35 / 9
1.4.11 35 / 9
1.4.9 35 / 9
1.4.8 35 / 9
1.4.7 35 / 9
1.4.6 34 / 9
1.4.5 34 / 9
1.4.4 33 / 9
1.4.3 33 / 9
1.4.2 33 / 9
1.4.1 33 / 9
1.4.0 33 / 9
1.3.4 34 / 9
1.3.3 34 / 9
1.3.2 34 / 9
1.3.0 34 / 9
1.2.8 34 / 9
1.2.7 34 / 9
1.2.6 34 / 9
1.2.5 34 / 9
1.2.4 34 / 9
1.2.3 34 / 9
1.2.2 34 / 9
1.2.1 34 / 9
1.2.0 33 / 9
1.1.0 17 / 7
1.0.51 31 / 9
1.0.50 31 / 9
1.0.49 31 / 9
1.0.48 31 / 9
1.0.47 31 / 9
1.0.46 31 / 9
1.0.45 31 / 9
1.0.44 31 / 9
1.0.43 31 / 9
1.0.42 31 / 9
1.0.41 31 / 9
1.0.40 31 / 9
1.0.39 31 / 9
1.0.38 31 / 9
1.0.37 31 / 9
1.0.36 31 / 9
1.0.35 31 / 9
1.0.34 31 / 9
1.0.33 31 / 9
1.0.32 31 / 9
1.0.31 31 / 9
1.0.30 31 / 9
1.0.27 31 / 9
1.0.25 31 / 9
1.0.24 31 / 9
1.0.23 31 / 9
1.0.22 25 / 9
1.0.21 25 / 9
1.0.20 25 / 9
1.0.19 25 / 9
1.0.18 18 / 9
1.0.17 18 / 9
1.0.15 18 / 9
1.0.14 19 / 8
1.0.13 17 / 10
1.0.12 17 / 7
1.0.11 17 / 7
1.0.10 17 / 7
1.0.9 17 / 7
1.0.8 17 / 7
1.0.7 17 / 7
1.0.6 16 / 7
1.0.5 16 / 7
1.0.4 16 / 7
1.0.3 16 / 7
1.0.2 16 / 7
1.0.1 14 / 7
1.0.0 14 / 7

v1.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.50

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.41

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.38

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.36

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.35

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.34

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.33

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.32

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.31

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.30

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: lukasio → GitHub Actions (on 2025-12-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (lukasio) on 2025-12-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.27

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: lukasio → GitHub Actions (on 2025-12-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (lukasio) on 2025-12-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.