@moltzap/server-core
Building blocks for agent-to-agent messaging — services, RPC, WebSocket, encryption
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@effect/sql-kysely | AI (dependencies): @effect/sql-kysely is a legitimate Effect ecosystem package; stable dependency for this package. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance attestation is present; missing gitHead is a minor metadata gap, not a supply-chain risk for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Size increase matches documented architectural refactor from Hono to Effect/SQL; SLSA provenance confirms CI build integrity. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 5.6x growth consistent with adding Effect platform, SQL, and pglite layers; not indicative of injected payload given SLSA attestation. | ai | |
| phantom-deps | phantom-dep:@hono/node-server | AI (phantom-deps): Config-referenced dependency; likely false positive for this package. | ai | |
| phantom-deps | phantom-dep:@hono/node-ws | AI (phantom-deps): Config-referenced dependency; likely false positive for this package. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): pino-pretty is a logging formatter typically used as a dev/optional dep; not directly imported is expected. | ai | |
| phantom-deps | phantom-dep:@electric-sql/pglite | AI (phantom-deps): In-process PG adapter likely used in test/dev config; not directly imported is expected. | ai | |
| phantom-deps | phantom-dep:@effect/sql-kysely | AI (phantom-deps): SQL adapter referenced in config files; not directly imported is a common pattern for optional DB adapters. | ai | |
| phantom-deps | phantom-dep:@effect/sql-pg | AI (phantom-deps): SQL adapter referenced in config files; not directly imported is a common pattern for optional DB adapters. | ai |
Versions (showing 51 of 54)
| Version | Deps | Published |
|---|---|---|
| 2026.529.0 | 19 / 9 | |
| 2026.528.0 | 19 / 9 | |
| 2026.526.1 | 19 / 9 | |
| 2026.526.0 | 19 / 9 | |
| 2026.525.0 | 19 / 9 | |
| 2026.524.4 | 19 / 9 | |
| 2026.524.3 | 21 / 9 | |
| 2026.524.2 | 14 / 9 | |
| 2026.524.1 | 14 / 9 | |
| 2026.524.0 | 14 / 9 | |
| 2026.523.0 | 14 / 9 | |
| 2026.520.1 | 14 / 9 | |
| 2026.520.0 | 14 / 9 | |
| 2026.519.3 | 14 / 9 | |
| 2026.519.2 | 14 / 9 | |
| 2026.519.1 | 14 / 9 | |
| 2026.519.0 | 14 / 9 | |
| 2026.518.0 | 14 / 9 | |
| 2026.511.4 | 17 / 9 | |
| 2026.511.3 | 17 / 9 | |
| 2026.511.2 | 17 / 9 | |
| 2026.511.1 | 17 / 9 | |
| 2026.511.0 | 17 / 9 | |
| 2026.510.0 | 17 / 9 | |
| 2026.509.0 | 17 / 9 | |
| 2026.508.5 | 17 / 9 | |
| 2026.508.4 | 17 / 9 | |
| 2026.508.3 | 17 / 9 | |
| 2026.508.2 | 17 / 9 | |
| 2026.508.1 | 17 / 9 | |
| 2026.508.0 | 17 / 9 | |
| 2026.507.2 | 17 / 9 | |
| 2026.507.1 | 17 / 9 | |
| 2026.507.0 | 17 / 9 | |
| 2026.506.5 | 17 / 9 | |
| 2026.506.4 | 17 / 9 | |
| 2026.506.3 | 17 / 9 | |
| 2026.506.2 | 17 / 9 | |
| 2026.506.1 | 17 / 9 | |
| 2026.506.0 | 17 / 9 | |
| 2026.505.3 | 17 / 9 | |
| 2026.503.5 | 17 / 9 | |
| 2026.502.1 | 17 / 9 | |
| 2026.501.7 | 17 / 9 | |
| 2026.501.5 | 17 / 9 | |
| 2026.501.1 | 17 / 9 | |
| 2026.501.0 | 17 / 9 | |
| 2026.430.0 | 17 / 9 | |
| 2026.425.4 | 17 / 9 | |
| 2026.425.3 | 17 / 9 | |
| 2026.425.1 | 16 / 10 |
v2026.529.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.528.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.526.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.526.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.525.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.524.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.524.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.524.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.524.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.524.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.523.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.520.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.520.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.519.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.519.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.519.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.519.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.518.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.511.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.511.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.511.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.511.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.511.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.510.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.509.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.508.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.508.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.508.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.508.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.508.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.508.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.507.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.507.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.507.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.506.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.506.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.506.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.506.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.506.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.506.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.505.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.503.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.502.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.501.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.501.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.501.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.501.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.430.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.425.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.425.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.425.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.