← Home

@opentabs-dev/shared

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

opentabs-dev-admin

Keywords

opentabsmcpmodelcontextprotocolai-agentbrowserchrome-extension

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Publisher has clean track record; no other risk signals; likely CI config change rather than supply-chain concern. ai
npm-metadata no-description AI (npm-metadata): Internal package; missing description is intentional, not a spam indicator. ai
bogus-package bogus-package AI (bogus-package): Private scoped internal library; missing metadata is expected for restricted-access packages, not a spam/malware indicator. ai

Versions (showing 51 of 110)

View all versions
Version Deps Published
0.0.115 0 / 0
0.0.109 0 / 0
0.0.108 0 / 0
0.0.107 0 / 0
0.0.106 0 / 0
0.0.105 0 / 0
0.0.104 0 / 0
0.0.103 0 / 0
0.0.102 0 / 0
0.0.101 0 / 0
0.0.100 0 / 0
0.0.99 0 / 0
0.0.98 0 / 0
0.0.97 0 / 0
0.0.96 0 / 0
0.0.95 0 / 0
0.0.94 0 / 0
0.0.93 0 / 0
0.0.92 0 / 0
0.0.91 0 / 0
0.0.90 0 / 0
0.0.89 0 / 0
0.0.88 0 / 0
0.0.87 0 / 0
0.0.86 0 / 0
0.0.85 0 / 0
0.0.84 0 / 0
0.0.83 0 / 0
0.0.82 0 / 0
0.0.81 0 / 0
0.0.80 0 / 0
0.0.79 0 / 0
0.0.78 0 / 0
0.0.77 0 / 0
0.0.76 0 / 0
0.0.75 0 / 0
0.0.74 0 / 0
0.0.73 0 / 0
0.0.72 0 / 0
0.0.71 0 / 0
0.0.70 0 / 0
0.0.69 0 / 0
0.0.68 0 / 0
0.0.67 0 / 0
0.0.66 0 / 0
0.0.65 0 / 0
0.0.64 0 / 0
0.0.63 0 / 0
0.0.62 0 / 0
0.0.61 0 / 0
0.0.60 0 / 0

v0.0.115

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: opentabs-dev-admin → GitHub Actions (on 2026-07-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (opentabs-dev-admin) on 2026-07-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.