← Home

@lobu/core

Core types and utilities for Lobu agent platform

60
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

buremba

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher with SLSA attestation is a legitimate CI/CD migration, not a compromise signal. ai
publish-pattern new-deps-added AI (publish-pattern): zod is a widely-trusted validation library; addition is benign for this package's use case. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Fires inside a sanitizeFilename test asserting /etc/passwd path traversal is stripped — not credential access. ai
semgrep semgrep:base64-decode AI (semgrep): Used in encryption key parsing utility; legitimate cryptographic key handling pattern. ai
semgrep semgrep:hex-decode AI (semgrep): Used in encryption key parsing utility; legitimate cryptographic key handling pattern. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped package @lobu/core is a legitimate platform library; Levenshtein match to 'cors' is coincidental. ai

Versions (showing 60 of 60)

Version Deps Published
14.3.0 10 / 3
14.2.0 10 / 3
14.1.0 10 / 3
14.0.0 8 / 3
13.4.0 7 / 3
13.3.0 7 / 3
13.2.0 7 / 3
13.1.0 7 / 3
13.0.0 7 / 3
12.1.0 7 / 3
12.0.0 7 / 3
11.3.0 8 / 3
11.2.0 8 / 3
11.1.0 8 / 3
11.0.0 8 / 3
10.2.0 8 / 3
10.1.0 8 / 3
10.0.0 8 / 3
9.4.1 8 / 3
9.4.0 8 / 3
9.3.0 8 / 3
9.2.0 8 / 3
9.1.1 8 / 3
9.1.0 8 / 3
9.0.0 8 / 3
8.0.0 8 / 3
7.2.0 8 / 3
7.1.0 8 / 3
7.0.0 8 / 3
6.1.1 8 / 3
6.1.0 8 / 3
6.0.1 8 / 3
6.0.0 8 / 3
5.0.0 9 / 3
4.3.0 9 / 3
4.2.0 9 / 3
4.1.0 9 / 3
4.0.1 9 / 3
4.0.0 9 / 3
3.7.0 9 / 3
3.5.0 9 / 3
3.4.3 9 / 3
3.4.2 9 / 3
3.4.1 9 / 3
3.4.0 9 / 3
3.3.0 9 / 3
3.2.0 9 / 3
3.1.1 9 / 3
3.1.0 9 / 3
3.0.19 9 / 3
3.0.16 8 / 3
3.0.13 8 / 3
3.0.12 8 / 3
3.0.10 8 / 3
3.0.9 8 / 3
3.0.8 8 / 3
3.0.7 8 / 3
3.0.6 8 / 3
3.0.5 8 / 3
2.8.0 8 / 3

v14.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v14.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v14.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v14.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v13.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.