@openai/agents-realtime
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/bundle/index-QD66ZcYX.mjs | AI (source-diff): Vite bundle output; minified build artifact, stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-BoxPP-dD.mjs | AI (source-diff): Vite bundle output from documented build step; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-D8tUKoCt.mjs | AI (source-diff): Vite build output, not obfuscation; stable for this bundled SDK. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-C8KXYIQD.mjs | AI (source-diff): Vite build output, not obfuscation; stable for this bundled SDK. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-tOSHH7v8.mjs | AI (source-diff): Vite build output; minified not obfuscated, stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-DQ5Tty94.mjs | AI (source-diff): Vite build output; minified not obfuscated, stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-IC-GtnyH.mjs | AI (source-diff): Vite bundle with version banner; minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-Bk8ZINBX.mjs | AI (source-diff): Vite build output; minified not obfuscated, stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-DZn_0D7x.mjs | AI (source-diff): Vite bundled dist output; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-BfWKb5VW.mjs | AI (source-diff): Vite build bundle output, not obfuscation; stable for this build tooling. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-x9KfzV3j.mjs | AI (source-diff): Vite-bundled dist output, not obfuscation; regenerates each release. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-C5sYsRJQ.mjs | AI (source-diff): Vite-bundled dist output, not obfuscation; regenerates each release. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-DQNgjb-V.mjs | AI (source-diff): Vite-minified bundle output, not obfuscation; stable build artifact for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-DHFen5Vv.mjs | AI (source-diff): Vite-minified bundle output, not obfuscation; stable build artifact for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-B8JqVS66.mjs | AI (source-diff): Vite-bundled dist output; minified not obfuscated. Stable for this build. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-C8M7S25V.mjs | AI (source-diff): Vite-bundled dist output; minified not obfuscated. Stable for this build tool. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-D3rh1Df0.mjs | AI (source-diff): Vite build output; minified bundle, not obfuscation. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-Do-OaBbR.mjs | AI (source-diff): Vite build output; minified bundle, not obfuscation. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-DHSTqduz.mjs | AI (source-diff): Vite bundle output for browser build; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-i-CbMN24.mjs | AI (source-diff): Vite bundle output with inlined zod; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-C_3P7LoK.mjs | AI (source-diff): Vite-bundled browser output; minification is expected for this package's browser export. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-DHsISTB7.mjs | AI (source-diff): Vite-bundled browser output; minification is expected for this package's browser export. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-Dsbss3pG.mjs | AI (source-diff): Vite UMD browser bundle; minified build output is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-CNTTurUB.mjs | AI (source-diff): Vite UMD browser bundle; minified build output is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-DBddvcIr.mjs | AI (source-diff): Vite build bundle output; minified but not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-BV_QRx6B.mjs | AI (source-diff): Vite build bundle output; minified but not obfuscated. Stable for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a zod alias from OpenAI's own namespace; benign addition for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-Dk4uIVD4.mjs | AI (source-diff): Vite-bundled browser build output; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-DsZokgsm.mjs | AI (source-diff): Vite-bundled browser build output; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-CbPvEdN4.mjs | AI (source-diff): Vite bundle output; standard minification for browser dist, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-DtoxT4Y_.mjs | AI (source-diff): Vite bundle output; standard minification for browser dist, not obfuscation. | ai | |
| dependencies | unvetted-dep:@openai/zod | AI (dependencies): @openai/zod is an npm alias for [email protected], a well-known validation library; stable false positive for this package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are OpenAI employees (mbolin-openai, fouad-openai); consistent with internal team rotation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of fouad alongside addition of fouad-openai is a routine account rename/rotation within OpenAI. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-Bz7G-f8o.mjs | AI (source-diff): Vite build bundle for browser export; minified but readable, stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-DfCGunwO.mjs | AI (source-diff): Vite build bundle for browser export; minified but readable, stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-DpEWIpme.mjs | AI (source-diff): Vite-produced browser bundle; minified but not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-CEsEfqN5.mjs | AI (source-diff): Vite-produced browser bundle; minified but not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-Z1A04vnn.mjs | AI (source-diff): Vite-bundled output for browser entry point; minified but not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-BRSSFu1S.mjs | AI (source-diff): Vite-bundled output for browser entry point; minified but not obfuscated. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-BjYZ_Vs_.mjs | AI (source-diff): Vite-bundled output for browser entry; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-D1GnyxTI.mjs | AI (source-diff): Vite-bundled output for browser entry; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-CPV0cGDP.mjs | AI (source-diff): Vite bundle output; readable minified code with no suspicious payloads. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-DN65-mSr.mjs | AI (source-diff): Vite bundle output for browser entry point; standard minification, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundle/index-COJAV3H7.mjs | AI (source-diff): Vite-bundled ESM output; minification is expected for this package's browser bundle target. | ai | |
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): @types/ws is a type-only dep; not directly imported at runtime by design. | ai | |
| source-diff | obfuscated-file:dist/bundle/agent-BDVhmhWN.mjs | AI (source-diff): Vite-bundled ESM output; minification is expected for this package's browser bundle target. | ai | |
| phantom-deps | phantom-dep:debug | AI (phantom-deps): debug is a runtime dep used via convention/indirect import in this SDK; stable false positive. | ai |
Versions (showing 51 of 92)
| Version | Deps | Published |
|---|---|---|
| 0.13.5 | 4 / 3 | |
| 0.13.4 | 4 / 3 | |
| 0.13.3 | 4 / 3 | |
| 0.13.2 | 4 / 3 | |
| 0.13.1 | 4 / 3 | |
| 0.13.0 | 4 / 3 | |
| 0.12.1 | 4 / 3 | |
| 0.12.0 | 4 / 3 | |
| 0.11.8 | 4 / 3 | |
| 0.11.7 | 4 / 3 | |
| 0.11.6 | 4 / 3 | |
| 0.11.5 | 4 / 3 | |
| 0.11.4 | 4 / 3 | |
| 0.11.3 | 4 / 3 | |
| 0.11.2 | 4 / 3 | |
| 0.11.1 | 4 / 3 | |
| 0.11.0 | 4 / 3 | |
| 0.10.1 | 4 / 3 | |
| 0.10.0 | 4 / 3 | |
| 0.9.1 | 4 / 3 | |
| 0.9.0 | 4 / 3 | |
| 0.8.5 | 4 / 3 | |
| 0.8.4 | 4 / 3 | |
| 0.8.3 | 4 / 3 | |
| 0.8.2 | 4 / 3 | |
| 0.8.1 | 4 / 3 | |
| 0.8.0 | 4 / 3 | |
| 0.7.2 | 4 / 3 | |
| 0.7.1 | 4 / 3 | |
| 0.7.0 | 4 / 3 | |
| 0.6.0 | 4 / 3 | |
| 0.5.4 | 4 / 3 | |
| 0.5.3 | 4 / 3 | |
| 0.5.2 | 4 / 3 | |
| 0.5.1 | 4 / 3 | |
| 0.5.0 | 4 / 3 | |
| 0.4.15 | 4 / 3 | |
| 0.4.14 | 4 / 3 | |
| 0.4.13 | 4 / 3 | |
| 0.4.12 | 4 / 3 | |
| 0.4.11 | 4 / 3 | |
| 0.4.10 | 4 / 3 | |
| 0.4.9 | 4 / 3 | |
| 0.4.8 | 4 / 3 | |
| 0.4.7 | 4 / 3 | |
| 0.4.6 | 4 / 3 | |
| 0.4.5 | 4 / 3 | |
| 0.4.4 | 4 / 3 | |
| 0.4.3 | 4 / 3 | |
| 0.4.2 | 4 / 3 | |
| 0.4.1 | 4 / 3 |
v0.13.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.13.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.12.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.