← Home

@nocobase/plugin-ai

Create AI employees with diverse skills to collaborate with humans, build systems, and handle business operations.

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

chenosjiannlu

Keywords

AI

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/node_modules/@langchain/xai/dist/index.cjs AI (source-diff): Bundled @langchain/xai dependency; long string is readable fast-json-patch logic, not obfuscated payload. ai
source-diff obfuscated-file:dist/client/47.048a6ef8bf62c945.js AI (source-diff): Standard webpack chunk with NocoBase copyright header; minification is expected for client bundles. ai
source-diff obfuscated-file:dist/node_modules/@langchain/xai/dist/index.d.ts AI (source-diff): TypeScript declaration file for bundled @langchain/xai; long lines from re-exported type lists, not obfuscation. ai
source-diff obfuscated-file:dist/client/47.4bf7fafc899b75be.js AI (source-diff): Standard webpack-minified client bundle with NocoBase copyright header; expected build artifact. ai
source-diff obfuscated-file:dist/node_modules/@langchain/xai/dist/index.d.cts AI (source-diff): Type declaration file for bundled @langchain/xai; long lines from re-exports, not obfuscation. ai
source-diff obfuscated-file:dist/client/755.ccd5d007fd1a3b5f.js AI (source-diff): Standard webpack-minified client chunk with NocoBase copyright header; expected build artifact. ai
source-diff obfuscated-file:dist/client/47.2fb813a37bb70c75.js AI (source-diff): Standard webpack-minified client chunk with NocoBase copyright header; expected build artifact. ai
source-diff obfuscated-file:dist/node_modules/@langchain/xai/dist/index.cjs AI (source-diff): Legitimate bundled @langchain/xai dependency declared in devDependencies; minified CJS dist is expected. ai
source-diff obfuscated-file:dist/client/107.a3563226b783a305.js AI (source-diff): Standard webpack minified client bundle for NocoBase plugin; not obfuscated malware. ai
source-diff obfuscated-file:dist/client/47.b477d35e232fe845.js AI (source-diff): Standard webpack minified client bundle for NocoBase plugin; not obfuscated malware. ai
source-diff obfuscated-file:dist/client/755.fea53a5f9b065b6c.js AI (source-diff): Standard webpack minified client bundle for NocoBase plugin; not obfuscated malware. ai
source-diff obfuscated-file:dist/client/9d99ede69dc880d7.js AI (source-diff): Standard webpack-minified client bundle with NocoBase copyright header; consistent with NocoBase's build pipeline across all plugin packages. ai
source-diff obfuscated-file:dist/node_modules/@langchain/core/index.cjs AI (source-diff): Standard webpack bundle using eval('require') for LangChain subpath externals; not malicious obfuscation. Consistent with LangChain's documented build output. ai
source-diff obfuscated-file:dist/node_modules/@langchain/openai/index.cjs AI (source-diff): Minified LangChain OpenAI integration bundle; same pattern as deepseek bundle, legitimate bundled dependency. ai
source-diff obfuscated-file:dist/node_modules/@langchain/deepseek/index.cjs AI (source-diff): Minified LangChain deepseek integration bundle; content is recognizable chalk/ansi utilities and AI client code, not malicious. ai
source-diff obfuscated-file:dist/client/05bb46e182de283c.js AI (source-diff): Standard webpack-minified frontend bundle with NocoBase copyright header; no malicious patterns. Minified dist output is expected for this plugin. ai
source-diff obfuscated-file:dist/client/c49179ef6fcbc972.js AI (source-diff): Standard webpack-minified frontend bundle with NocoBase copyright header; no malicious patterns. Minified dist output is expected for this plugin. ai
source-diff obfuscated-file:dist/client/35156dfea5f288fa.js AI (source-diff): Standard webpack-minified frontend bundle with NocoBase copyright header; no malicious patterns. Minified dist output is expected for this plugin. ai
source-diff obfuscated-file:dist/client/f36cbdd2680ceeba.js AI (source-diff): Standard webpack-minified frontend bundle with NocoBase copyright header; no malicious patterns. Minified dist output is expected for this plugin. ai
source-diff obfuscated-file:dist/client/66c939b3395bb7c4.js AI (source-diff): This is standard webpack-minified client bundle output for a NocoBase UI plugin. The copyright header and webpack chunk pattern confirm legitimate build artifact, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Major version bump (v1.x to v2.x) with extensive AI/LangChain integrations explains the large number of new files. Consistent with the package's stated purpose. ai
source-diff obfuscated-file:dist/node_modules/zod/index.cjs AI (source-diff): This is the standard minified distribution of the well-known zod library bundled as a dependency. The code is recognizable zod API exports, not malicious obfuscation. ai

Versions (showing 51 of 125)

View all versions
Version Deps Published
2.0.61 0 / 28
2.0.60 0 / 28
2.0.59 0 / 28
2.0.58 0 / 28
2.0.57 0 / 28
2.0.56 0 / 28
2.0.55 0 / 28
2.0.54 0 / 28
2.0.53 0 / 28
2.0.52 0 / 28
2.0.51 0 / 28
2.0.50 0 / 28
2.0.49 0 / 27
2.0.48 0 / 27
2.0.47 0 / 27
2.0.46 0 / 27
2.0.45 0 / 27
2.0.44 0 / 27
2.0.43 0 / 27
2.0.42 0 / 27
2.0.41 0 / 27
2.0.40 0 / 27
2.0.39 0 / 27
2.0.38 0 / 27
2.0.37 0 / 27
2.0.36 0 / 27
2.0.35 0 / 27
2.0.34 0 / 27
2.0.33 0 / 27
2.0.32 0 / 27
2.0.31 0 / 27
2.0.30 0 / 27
2.0.29 0 / 27
2.0.28 0 / 27
2.0.27 0 / 27
2.0.26 0 / 27
2.0.25 0 / 27
2.0.24 0 / 27
2.0.23 0 / 27
2.0.22 0 / 27
2.0.21 0 / 27
2.0.20 0 / 27
2.0.19 0 / 27
2.0.18 0 / 27
2.0.17 0 / 27
2.0.16 0 / 27
2.0.15 0 / 27
2.0.14 0 / 27
2.0.13 0 / 27
2.0.12 0 / 27
2.0.11 0 / 27

v2.0.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.60

3 findings
HIGH New obfuscated file: dist/client/47.048a6ef8bf62c945.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.59

2 findings
HIGH Long encoded string in modified file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.55

6 findings
HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.2fb813a37bb70c75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.ccd5d007fd1a3b5f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.54

6 findings
HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.2fb813a37bb70c75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.ccd5d007fd1a3b5f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.53

6 findings
HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.2fb813a37bb70c75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.ccd5d007fd1a3b5f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.52

6 findings
HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.2fb813a37bb70c75.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.ccd5d007fd1a3b5f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.51

6 findings
HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.4bf7fafc899b75be.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.fea53a5f9b065b6c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.50

6 findings
HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/@langchain/xai/dist/index.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.4bf7fafc899b75be.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.fea53a5f9b065b6c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.49

4 findings
HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.b477d35e232fe845.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.fea53a5f9b065b6c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.48

4 findings
HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.b477d35e232fe845.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.fea53a5f9b065b6c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.47

4 findings
HIGH New obfuscated file: dist/client/107.a3563226b783a305.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/47.b477d35e232fe845.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/755.fea53a5f9b065b6c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.44

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.42

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.41

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.40

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.39

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.38

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.37

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.36

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.35

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.34

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.33

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.32

2 findings
HIGH New obfuscated file: dist/node_modules/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.