← Home

@opentiny/tiny-robot

TinyRobot 是一个 AI 对话组件库,提供了丰富的 AI 交互组件,助力开发者快速构建企业级 AI 应用;同时也是一个智能助手,支持普通 AI 问答、也支持集成 MCP Server,让 AI 真正帮人“干活”。

21
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

opentiny

Keywords

vuevue3vue-componentscomponent-libraryaiai-componentschatchat-uichatbotllmopenaiassistantstreamingconversationtiny-robotopentiny

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Likely used within bundled dist output; well-known utility lib. ai
dependencies unvetted-dep:@opentiny/vue-icon AI (dependencies): Same-org UI component dep, consistent monorepo pattern. ai
dependencies unvetted-dep:@opentiny/vue-tooltip AI (dependencies): Same-org UI component dep, consistent monorepo pattern. ai
dependencies unvetted-dep:@opentiny/vue-button AI (dependencies): Same-org UI component dep, consistent monorepo pattern. ai
dependencies unvetted-dep:@opentiny/vue-input AI (dependencies): Same-org UI component dep, consistent monorepo pattern. ai
phantom-deps phantom-dep:@tiptap/extension-floating-menu AI (phantom-deps): Optional tiptap extension, bundled. ai
source-diff encoded-string-file:dist/sender/index.js AI (source-diff): Unicode segmentation data table from unicode-segmenter dep, not a payload. ai
phantom-deps phantom-dep:unicode-segmenter AI (phantom-deps): Used inside bundled dist output; not scannable as plain import. ai
phantom-deps phantom-dep:@tiptap/extensions AI (phantom-deps): Tiptap extension used in bundled editor code. ai
phantom-deps phantom-dep:@tiptap/extension-bubble-menu AI (phantom-deps): Optional tiptap extension, bundled. ai
phantom-deps phantom-dep:@opentiny/tiny-robot-svgs AI (phantom-deps): Same-org dependency; stable false positive for this package. ai
phantom-deps phantom-dep:@opentiny/vue AI (phantom-deps): Same-org dependency; likely resolved via bundling or peer resolution, not a real phantom dep. ai
phantom-deps phantom-dep:@opentiny/vue-icon AI (phantom-deps): Same-org dependency; stable false positive for this package. ai
phantom-deps phantom-dep:@opentiny/vue-input AI (phantom-deps): Same-org dependency; stable false positive for this package. ai
phantom-deps phantom-dep:@opentiny/vue-button AI (phantom-deps): Same-org dependency; stable false positive for this package. ai
phantom-deps phantom-dep:@opentiny/vue-tooltip AI (phantom-deps): Same-org dependency; stable false positive for this package. ai
bogus-package bogus-package AI (bogus-package): Metadata gaps are typical of monorepo sub-packages; 117 versions and consistent download history confirm legitimacy. ai
dependencies unvetted-dep:@opentiny/vue AI (dependencies): Same opentiny org; expected peer UI framework dependency for this component package. ai
dependencies unvetted-dep:markdown-it AI (dependencies): markdown-it is a well-known, widely-used Markdown renderer; expected dependency for a chat UI component. ai
phantom-deps phantom-dep:jsonrepair AI (phantom-deps): jsonrepair is a runtime dep bundled into dist; phantom-dep heuristic fires because it's not directly imported at the package root. ai
phantom-deps phantom-dep:@floating-ui/dom AI (phantom-deps): @floating-ui/dom is a declared runtime dep used transitively in the component library; stable false positive for this package. ai

Versions (showing 21 of 21)

Version Deps Published
0.5.0 18 / 14
0.4.1 14 / 14
0.4.0 14 / 14
0.3.3 5 / 12
0.3.2 5 / 12
0.3.1 5 / 12
0.3.0 5 / 12
0.2.15 8 / 13
0.2.14 8 / 13
0.2.13 8 / 13
0.2.12 8 / 13
0.2.11 8 / 13
0.2.10 8 / 13
0.2.9 8 / 13
0.2.8 8 / 13
0.2.7 8 / 13
0.2.5 8 / 13
0.2.3 8 / 13
0.2.1 8 / 13
0.2.0 8 / 13
0.1.0 8 / 13

v0.5.0

2 findings
HIGH Long encoded string in modified file: dist/sender/index.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.