@razroo/iso
One command that chains agentmd → isolint → iso-harness: author one prompt, ship it to every coding agent.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped @razroo/iso package; no intent to impersonate 'qs'; edit-distance match is coincidental. | ai | |
| typosquat | typosquat.levenshtein:pino | AI (typosquat): Scoped @razroo/iso package; no intent to impersonate 'pino'; edit-distance match is coincidental. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): require() is called on a resolved absolute path from require.resolve(), not arbitrary user input. | ai | |
| phantom-deps | phantom-dep:@razroo/agentmd | AI (phantom-deps): Same-org monorepo dep; declared but consumed transitively or via CLI orchestration. | ai | |
| phantom-deps | phantom-dep:@razroo/isolint | AI (phantom-deps): Same-org monorepo dep; declared but consumed transitively or via CLI orchestration. | ai | |
| phantom-deps | phantom-dep:@razroo/iso-route | AI (phantom-deps): Same-org monorepo dep; declared but consumed transitively or via CLI orchestration. | ai | |
| phantom-deps | phantom-dep:@razroo/iso-harness | AI (phantom-deps): Same-org monorepo dep; declared but consumed transitively or via CLI orchestration. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 0.3.1 | 4 / 0 | |
| 0.3.0 | 4 / 0 | |
| 0.2.5 | 4 / 0 | |
| 0.2.4 | 4 / 0 | |
| 0.2.3 | 4 / 0 | |
| 0.2.2 | 4 / 0 | |
| 0.2.1 | 4 / 0 | |
| 0.2.0 | 4 / 0 | |
| 0.1.1 | 3 / 0 |
v0.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.