@openclaw/discord
OpenClaw Discord channel plugin
45
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
steipetevincentkoc
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Size increase is due to bundling multi-platform native binaries; consistent with the package's purpose. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Binaries are @snazzah/davey napi-rs platform builds for @discordjs/voice; expected for this Discord plugin package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are platform-specific prebuilt .node binaries and wasm runtime; expected for this native-binding bundle. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decoding a Discord snowflake/token component to extract numeric ID — legitimate protocol parsing. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in a Proxy handler inside a test mock — standard JS pattern, not obfuscation. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All instances are in test files using 127.0.0.1 for local proxy testing — not production network calls. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Used in a test helper to inject a temp dir env var; not in production code. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published via CI with SLSA attestation; strong supply chain integrity signal. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): vincentkoc added alongside CI publisher transition; consistent with org-level maintainer handoff. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher with SLSA provenance is a legitimate CI/CD migration pattern. | ai |
Versions (showing 45 of 45)
| Version | Deps | Published |
|---|---|---|
| 2026.7.1 | 6 / 0 | |
| 2026.6.11 | 6 / 0 | |
| 2026.6.10 | 6 / 0 | |
| 2026.6.9 | 6 / 0 | |
| 2026.6.8 | 6 / 0 | |
| 2026.6.6 | 6 / 0 | |
| 2026.6.5 | 6 / 0 | |
| 2026.6.1 | 6 / 0 | |
| 2026.5.28 | 6 / 0 | |
| 2026.5.27 | 7 / 0 | |
| 2026.5.26 | 7 / 0 | |
| 2026.5.22 | 7 / 0 | |
| 2026.5.20 | 7 / 2 | |
| 2026.5.19 | 7 / 2 | |
| 2026.5.18 | 7 / 2 | |
| 2026.5.12 | 7 / 2 | |
| 2026.5.7 | 7 / 2 | |
| 2026.5.6 | 7 / 2 | |
| 2026.5.5 | 7 / 2 | |
| 2026.5.4 | 7 / 2 | |
| 2026.5.3 | 7 / 2 | |
| 2026.5.2 | 7 / 2 | |
| 2026.3.13 | 0 / 0 | |
| 2026.3.12 | 0 / 0 | |
| 2026.3.11 | 0 / 0 | |
| 2026.3.10 | 0 / 0 | |
| 2026.3.7 | 0 / 0 | |
| 2026.3.2 | 0 / 0 | |
| 2026.3.1 | 0 / 0 | |
| 2026.2.25 | 0 / 0 | |
| 2026.2.24 | 0 / 0 | |
| 2026.2.23 | 0 / 1 | |
| 2026.2.22 | 0 / 1 | |
| 2026.2.21 | 0 / 1 | |
| 2026.2.19 | 0 / 1 | |
| 2026.2.17 | 0 / 1 | |
| 2026.2.15 | 0 / 1 | |
| 2026.2.14 | 0 / 1 | |
| 2026.2.13 | 0 / 1 | |
| 2026.2.12 | 0 / 1 | |
| 2026.2.9 | 0 / 1 | |
| 2026.2.6 | 0 / 1 | |
| 2026.2.2 | 0 / 1 | |
| 2026.2.1 | 0 / 1 | |
| 2026.1.29 | 0 / 0 |
v2026.7.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.6.11
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.6.10
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.