@paperclipai/adapter-utils
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | bundled-binaries | AI (npm-metadata): esbuild + bare-* prebuilds are byte-verified vendored copies of known upstream packages; native toolchain for ACP adapter. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from named publisher to GitHub Actions is explained by adoption of SLSA-attested CI/CD publishing. Attestation confirms pipeline integrity; this pattern is stable for this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Scoped monorepo utility package; missing description is a cosmetic issue with no security relevance for this established package. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 2026.722.0 | 2 / 2 | |
| 2026.720.0 | 2 / 2 | |
| 2026.707.0 | 0 / 2 | |
| 2026.626.0 | 0 / 2 | |
| 2026.618.0 | 0 / 2 | |
| 2026.609.0 | 0 / 2 | |
| 2026.529.0 | 0 / 2 | |
| 2026.525.0 | 0 / 2 | |
| 2026.517.0 | 0 / 2 | |
| 2026.513.0 | 0 / 2 | |
| 2026.512.0 | 0 / 2 | |
| 2026.428.0 | 0 / 2 | |
| 2026.427.0 | 0 / 2 | |
| 2026.416.0 | 0 / 2 | |
| 2026.403.0 | 0 / 2 | |
| 2026.325.0 | 0 / 2 | |
| 2026.318.0 | 0 / 2 | |
| 0.3.1 | 0 / 2 | |
| 0.3.0 | 0 / 2 | |
| 0.2.7 | 0 / 1 | |
| 0.2.6 | 0 / 1 | |
| 0.2.5 | 0 / 1 | |
| 0.2.4 | 0 / 1 | |
| 0.2.3 | 0 / 1 | |
| 0.2.2 | 0 / 1 |
v2026.722.0
3 findingsPackage contains compiled binaries that could be backdoors: • node_modules/@esbuild/linux-x64/bin/esbuild • node_modules/bare-fs/prebuilds/android-arm/bare-fs.bare • node_modules/bare-fs/prebuilds/android-arm64/bare-fs.bare • node_modules/bare-fs/prebuilds/android-ia32/bare-fs.bare • node_modules/bare-fs/prebuilds/android-x64/bare-fs.bare • node_modules/bare-fs/prebuilds/darwin-arm64/bare-fs.bare • node_modules/bare-fs/prebuilds/darwin-x64/bare-fs.bare • node_modules/bare-fs/prebuilds/ios-arm64-simulator/bare-fs.bare • node_modules/bare-fs/prebuilds/ios-arm64/bare-fs.bare • node_modules/bare-fs/prebuilds/ios-x64-simulator/bare-fs.bare ... and 30 more
The directory `node_modules/acpx` byte-matched 25 of 29 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: node_modules/acpx/dist/live-checkpoint-ClPCSdrW.js, node_modules/acpx/dist/runtime.d.ts, node_modules/acpx/dist/runtime.js, node_modules/acpx/dist/session-options-jkYbBxGE.d.ts. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.720.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.707.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.