← Home

@posthog/agent

TypeScript agent framework wrapping Claude Agent SDK with Git-based task execution for PostHog

20
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

watilotwixesfuziontechmariusandraben-posthogtimglrafael_posthogfraserhoppermanoelposthogrobbie-cdustinbyrnefeliperalmeidalucasheriquesfrankposthogtom-posthogadamleithpcat-phsarahxsanderspeterkirkhamposthogioannisjjoshuasnyderhuguespouillot

Keywords

posthogclaudeagentaigittypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance slsa-provenance AI (provenance): PostHog publishes via CI with SLSA attestation consistently; stable signal for this package. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env to pass environment to Claude CLI subprocess is expected behavior for this agent wrapper. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decode in handoff-checkpoint.ts is for deserializing checkpoint file content, not obfuscated payload execution. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): ajv is a declared runtime dependency; phantom-dep heuristic false positive. ai
npm-metadata bundled-binaries AI (npm-metadata): Ripgrep and audio-capture binaries are vendored for Claude CLI subprocess use; consistent with package purpose and SLSA-attested build. ai
phantom-deps phantom-dep:yoga-wasm-web AI (phantom-deps): Platform-specific binary dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@types/jsonwebtoken AI (phantom-deps): @types/jsonwebtoken listed as runtime dep alongside jsonwebtoken; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:tar AI (phantom-deps): tar is a declared runtime dependency; phantom-dep heuristic false positive. ai

Versions (showing 20 of 20)

Version Deps Published
2.3.736 19 / 10
2.3.735 19 / 10
2.3.727 19 / 10
2.3.709 19 / 10
2.3.696 19 / 10
2.3.678 19 / 10
2.3.670 19 / 10
2.3.658 19 / 10
2.3.616 19 / 10
2.3.556 19 / 10
2.3.478 19 / 10
2.3.474 19 / 10
2.3.459 19 / 10
2.3.425 19 / 10
1.17.0 2 / 10
1.16.6 6 / 10
1.16.5 6 / 10
1.16.4 6 / 10
1.16.3 6 / 10
1.16.2 6 / 10

v2.3.736

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.735

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.727

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.709

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.696

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.678

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.670

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.658

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.616

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.556

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.478

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.474

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.16.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.