← Home

@paperclipai/adapter-utils

25
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

dottadevinfoley

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): esbuild + bare-* prebuilds are byte-verified vendored copies of known upstream packages; native toolchain for ACP adapter. ai
provenance publisher-changed AI (provenance): Transition from named publisher to GitHub Actions is explained by adoption of SLSA-attested CI/CD publishing. Attestation confirms pipeline integrity; this pattern is stable for this package. ai
npm-metadata no-description AI (npm-metadata): Scoped monorepo utility package; missing description is a cosmetic issue with no security relevance for this established package. ai

Versions (showing 25 of 25)

Version Deps Published
2026.722.0 2 / 2
2026.720.0 2 / 2
2026.707.0 0 / 2
2026.626.0 0 / 2
2026.618.0 0 / 2
2026.609.0 0 / 2
2026.529.0 0 / 2
2026.525.0 0 / 2
2026.517.0 0 / 2
2026.513.0 0 / 2
2026.512.0 0 / 2
2026.428.0 0 / 2
2026.427.0 0 / 2
2026.416.0 0 / 2
2026.403.0 0 / 2
2026.325.0 0 / 2
2026.318.0 0 / 2
0.3.1 0 / 2
0.3.0 0 / 2
0.2.7 0 / 1
0.2.6 0 / 1
0.2.5 0 / 1
0.2.4 0 / 1
0.2.3 0 / 1
0.2.2 0 / 1

v2026.722.0

3 findings
HIGH Bundled binary files (40) npm-metadata

Package contains compiled binaries that could be backdoors: • node_modules/@esbuild/linux-x64/bin/esbuild • node_modules/bare-fs/prebuilds/android-arm/bare-fs.bare • node_modules/bare-fs/prebuilds/android-arm64/bare-fs.bare • node_modules/bare-fs/prebuilds/android-ia32/bare-fs.bare • node_modules/bare-fs/prebuilds/android-x64/bare-fs.bare • node_modules/bare-fs/prebuilds/darwin-arm64/bare-fs.bare • node_modules/bare-fs/prebuilds/darwin-x64/bare-fs.bare • node_modules/bare-fs/prebuilds/ios-arm64-simulator/bare-fs.bare • node_modules/bare-fs/prebuilds/ios-arm64/bare-fs.bare • node_modules/bare-fs/prebuilds/ios-x64-simulator/bare-fs.bare ... and 30 more

HIGH Modified vendored dependency: node_modules/acpx (4 file(s)) vendored-integrity

The directory `node_modules/acpx` byte-matched 25 of 29 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 4 file(s) inside it differ from that package's bytes at the same path: node_modules/acpx/dist/live-checkpoint-ClPCSdrW.js, node_modules/acpx/dist/runtime.d.ts, node_modules/acpx/dist/runtime.js, node_modules/acpx/dist/session-options-jkYbBxGE.d.ts. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.720.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.707.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.