← Home

@openai/agents-realtime

92
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

openai-publishertino-openaidylan-hurd-openaimoustafa-openaitylersmith-openaimdangelo-openaivictor-openaijbeckwith-oaiatty-openaitibo-openaidkundel-openaimbolin-openaifouad-openaieasong-openaiaibrahim-openaiapcha-oaiseratch-openai

Keywords

openaiagentsaiagentic

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/bundle/index-QD66ZcYX.mjs AI (source-diff): Vite bundle output; minified build artifact, stable for this package. ai
source-diff obfuscated-file:dist/bundle/agent-BoxPP-dD.mjs AI (source-diff): Vite bundle output from documented build step; minified not obfuscated. ai
source-diff obfuscated-file:dist/bundle/index-D8tUKoCt.mjs AI (source-diff): Vite build output, not obfuscation; stable for this bundled SDK. ai
source-diff obfuscated-file:dist/bundle/agent-C8KXYIQD.mjs AI (source-diff): Vite build output, not obfuscation; stable for this bundled SDK. ai
source-diff obfuscated-file:dist/bundle/agent-tOSHH7v8.mjs AI (source-diff): Vite build output; minified not obfuscated, stable for this package. ai
source-diff obfuscated-file:dist/bundle/index-DQ5Tty94.mjs AI (source-diff): Vite build output; minified not obfuscated, stable for this package. ai
source-diff obfuscated-file:dist/bundle/index-IC-GtnyH.mjs AI (source-diff): Vite bundle with version banner; minified build artifact. ai
source-diff obfuscated-file:dist/bundle/agent-Bk8ZINBX.mjs AI (source-diff): Vite build output; minified not obfuscated, stable for this package. ai
source-diff obfuscated-file:dist/bundle/index-DZn_0D7x.mjs AI (source-diff): Vite bundled dist output; minified not obfuscated. ai
source-diff obfuscated-file:dist/bundle/agent-BfWKb5VW.mjs AI (source-diff): Vite build bundle output, not obfuscation; stable for this build tooling. ai
source-diff obfuscated-file:dist/bundle/index-x9KfzV3j.mjs AI (source-diff): Vite-bundled dist output, not obfuscation; regenerates each release. ai
source-diff obfuscated-file:dist/bundle/agent-C5sYsRJQ.mjs AI (source-diff): Vite-bundled dist output, not obfuscation; regenerates each release. ai
source-diff obfuscated-file:dist/bundle/index-DQNgjb-V.mjs AI (source-diff): Vite-minified bundle output, not obfuscation; stable build artifact for this package. ai
source-diff obfuscated-file:dist/bundle/agent-DHFen5Vv.mjs AI (source-diff): Vite-minified bundle output, not obfuscation; stable build artifact for this package. ai
source-diff obfuscated-file:dist/bundle/index-B8JqVS66.mjs AI (source-diff): Vite-bundled dist output; minified not obfuscated. Stable for this build. ai
source-diff obfuscated-file:dist/bundle/agent-C8M7S25V.mjs AI (source-diff): Vite-bundled dist output; minified not obfuscated. Stable for this build tool. ai
source-diff obfuscated-file:dist/bundle/index-D3rh1Df0.mjs AI (source-diff): Vite build output; minified bundle, not obfuscation. Stable for this package. ai
source-diff obfuscated-file:dist/bundle/agent-Do-OaBbR.mjs AI (source-diff): Vite build output; minified bundle, not obfuscation. Stable for this package. ai
source-diff obfuscated-file:dist/bundle/agent-DHSTqduz.mjs AI (source-diff): Vite bundle output for browser build; minified not obfuscated. ai
source-diff obfuscated-file:dist/bundle/index-i-CbMN24.mjs AI (source-diff): Vite bundle output with inlined zod; minified not obfuscated. ai
source-diff obfuscated-file:dist/bundle/index-C_3P7LoK.mjs AI (source-diff): Vite-bundled browser output; minification is expected for this package's browser export. ai
source-diff obfuscated-file:dist/bundle/agent-DHsISTB7.mjs AI (source-diff): Vite-bundled browser output; minification is expected for this package's browser export. ai
source-diff obfuscated-file:dist/bundle/agent-Dsbss3pG.mjs AI (source-diff): Vite UMD browser bundle; minified build output is expected for this package. ai
source-diff obfuscated-file:dist/bundle/index-CNTTurUB.mjs AI (source-diff): Vite UMD browser bundle; minified build output is expected for this package. ai
source-diff obfuscated-file:dist/bundle/agent-DBddvcIr.mjs AI (source-diff): Vite build bundle output; minified but not obfuscated. Stable for this package. ai
source-diff obfuscated-file:dist/bundle/index-BV_QRx6B.mjs AI (source-diff): Vite build bundle output; minified but not obfuscated. Stable for this package. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is a zod alias from OpenAI's own namespace; benign addition for this package. ai
source-diff obfuscated-file:dist/bundle/agent-Dk4uIVD4.mjs AI (source-diff): Vite-bundled browser build output; minification is expected for this package. ai
source-diff obfuscated-file:dist/bundle/index-DsZokgsm.mjs AI (source-diff): Vite-bundled browser build output; minification is expected for this package. ai
source-diff obfuscated-file:dist/bundle/index-CbPvEdN4.mjs AI (source-diff): Vite bundle output; standard minification for browser dist, not obfuscation. ai
source-diff obfuscated-file:dist/bundle/agent-DtoxT4Y_.mjs AI (source-diff): Vite bundle output; standard minification for browser dist, not obfuscation. ai
dependencies unvetted-dep:@openai/zod AI (dependencies): @openai/zod is an npm alias for [email protected], a well-known validation library; stable false positive for this package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are OpenAI employees (mbolin-openai, fouad-openai); consistent with internal team rotation. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of fouad alongside addition of fouad-openai is a routine account rename/rotation within OpenAI. ai
source-diff obfuscated-file:dist/bundle/index-Bz7G-f8o.mjs AI (source-diff): Vite build bundle for browser export; minified but readable, stable pattern for this package. ai
source-diff obfuscated-file:dist/bundle/agent-DfCGunwO.mjs AI (source-diff): Vite build bundle for browser export; minified but readable, stable pattern for this package. ai
source-diff obfuscated-file:dist/bundle/index-DpEWIpme.mjs AI (source-diff): Vite-produced browser bundle; minified but not obfuscated. Stable for this package. ai
source-diff obfuscated-file:dist/bundle/agent-CEsEfqN5.mjs AI (source-diff): Vite-produced browser bundle; minified but not obfuscated. Stable for this package. ai
source-diff obfuscated-file:dist/bundle/agent-Z1A04vnn.mjs AI (source-diff): Vite-bundled output for browser entry point; minified but not obfuscated. Stable for this package. ai
source-diff obfuscated-file:dist/bundle/index-BRSSFu1S.mjs AI (source-diff): Vite-bundled output for browser entry point; minified but not obfuscated. Stable for this package. ai
source-diff obfuscated-file:dist/bundle/index-BjYZ_Vs_.mjs AI (source-diff): Vite-bundled output for browser entry; minification is expected for this package. ai
source-diff obfuscated-file:dist/bundle/agent-D1GnyxTI.mjs AI (source-diff): Vite-bundled output for browser entry; minification is expected for this package. ai
source-diff obfuscated-file:dist/bundle/agent-CPV0cGDP.mjs AI (source-diff): Vite bundle output; readable minified code with no suspicious payloads. ai
source-diff obfuscated-file:dist/bundle/index-DN65-mSr.mjs AI (source-diff): Vite bundle output for browser entry point; standard minification, not obfuscation. ai
source-diff obfuscated-file:dist/bundle/index-COJAV3H7.mjs AI (source-diff): Vite-bundled ESM output; minification is expected for this package's browser bundle target. ai
phantom-deps phantom-dep:@types/ws AI (phantom-deps): @types/ws is a type-only dep; not directly imported at runtime by design. ai
source-diff obfuscated-file:dist/bundle/agent-BDVhmhWN.mjs AI (source-diff): Vite-bundled ESM output; minification is expected for this package's browser bundle target. ai
phantom-deps phantom-dep:debug AI (phantom-deps): debug is a runtime dep used via convention/indirect import in this SDK; stable false positive. ai

Versions (showing 92 of 92)

Version Deps Published
0.13.5 4 / 3
0.13.4 4 / 3
0.13.3 4 / 3
0.13.2 4 / 3
0.13.1 4 / 3
0.13.0 4 / 3
0.12.1 4 / 3
0.12.0 4 / 3
0.11.8 4 / 3
0.11.7 4 / 3
0.11.6 4 / 3
0.11.5 4 / 3
0.11.4 4 / 3
0.11.3 4 / 3
0.11.2 4 / 3
0.11.1 4 / 3
0.11.0 4 / 3
0.10.1 4 / 3
0.10.0 4 / 3
0.9.1 4 / 3
0.9.0 4 / 3
0.8.5 4 / 3
0.8.4 4 / 3
0.8.3 4 / 3
0.8.2 4 / 3
0.8.1 4 / 3
0.8.0 4 / 3
0.7.2 4 / 3
0.7.1 4 / 3
0.7.0 4 / 3
0.6.0 4 / 3
0.5.4 4 / 3
0.5.3 4 / 3
0.5.2 4 / 3
0.5.1 4 / 3
0.5.0 4 / 3
0.4.15 4 / 3
0.4.14 4 / 3
0.4.13 4 / 3
0.4.12 4 / 3
0.4.11 4 / 3
0.4.10 4 / 3
0.4.9 4 / 3
0.4.8 4 / 3
0.4.7 4 / 3
0.4.6 4 / 3
0.4.5 4 / 3
0.4.4 4 / 3
0.4.3 4 / 3
0.4.2 4 / 3
0.4.1 4 / 3
0.4.0 4 / 3
0.3.9 4 / 3
0.3.8 4 / 3
0.3.7 4 / 3
0.3.6 4 / 3
0.3.5 4 / 3
0.3.4 4 / 3
0.3.3 4 / 3
0.3.2 4 / 3
0.3.1 4 / 3
0.3.0 4 / 3
0.2.1 4 / 3
0.2.0 4 / 3
0.1.11 4 / 3
0.1.10 4 / 3
0.1.8 4 / 3
0.1.7 4 / 3
0.1.6 4 / 3
0.1.5 4 / 3
0.1.4 4 / 3
0.1.3 4 / 3
0.1.2 4 / 3
0.1.1 4 / 3
0.1.0 4 / 3
0.0.17 4 / 3
0.0.16 5 / 2
0.0.15 5 / 2
0.0.14 5 / 2
0.0.13 5 / 2
0.0.12 5 / 2
0.0.11 5 / 2
0.0.10 5 / 2
0.0.9 5 / 2
0.0.8 5 / 2
0.0.7 5 / 2
0.0.6 5 / 2
0.0.5 5 / 2
0.0.4 4 / 2
0.0.3 4 / 2
0.0.2 4 / 2
0.0.1 4 / 2

v0.13.5

3 findings
HIGH New obfuscated file: dist/bundle/agent-BoxPP-dD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bundle/index-QD66ZcYX.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.4

3 findings
HIGH New obfuscated file: dist/bundle/agent-C8KXYIQD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bundle/index-D8tUKoCt.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.3

3 findings
HIGH New obfuscated file: dist/bundle/agent-tOSHH7v8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bundle/index-DQ5Tty94.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.2

3 findings
HIGH New obfuscated file: dist/bundle/agent-Bk8ZINBX.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bundle/index-IC-GtnyH.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.1

3 findings
HIGH New obfuscated file: dist/bundle/agent-BfWKb5VW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bundle/index-DZn_0D7x.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.0

3 findings
HIGH New obfuscated file: dist/bundle/agent-C5sYsRJQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bundle/index-x9KfzV3j.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.1

3 findings
HIGH New obfuscated file: dist/bundle/agent-DHSTqduz.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/bundle/index-i-CbMN24.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.