@openclaw/mattermost
OpenClaw Mattermost channel plugin
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): ws/zod are established, appropriate deps for a chat plugin; bundled and declared. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundled ws/zod source trees explain file count increase; no injected code. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Bundling zod's full src (incl. tests) inflates size; declared in bundledDependencies. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Publish moved to CI/CD trusted publisher with provenance, not a manual account change. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 2026.7.1 | 2 / 0 | |
| 2026.6.33 | 2 / 0 | |
| 2026.6.11 | 2 / 0 | |
| 2026.2.21 | 0 / 1 |
v2026.7.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (steipete) on 2026-07-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2026.6.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.6.11
2 findingsThis version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.