@sanity/ailf
AI Literacy Framework - Evaluation tool for Sanity documentation
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from individual (gabe.wyatt) to org account (sanity-io) within @sanity scope; legitimate org consolidation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Org-level maintainer consolidation under sanity-io org account; not a takeover signal. | ai | |
| source-diff | obfuscated-file:dist/_vendor/ailf-shared/generated/help-content.js | AI (source-diff): Auto-generated help content with long lines from embedded markdown; not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/agent-harness/assertions-runtime.js | AI (source-diff): Documented promptfoo assertion helper for test harness; execSync runs developer-authored task definitions, not remote code. | ai | |
| source-diff | net-exec-file:dist/agent-harness/assertions-runtime.d.ts | AI (source-diff): Type declaration file for the same assertion helper; no executable payload. | ai | |
| provenance | missing-githead | AI (provenance): Sanity-org package with clean diff and strong publisher history; gitHead absence is a CI config change, not a supply-chain indicator. | ai | |
| dependencies | unvetted-dep:@portabletext/markdown | AI (dependencies): @portabletext/markdown is the official Portable Text markdown library from the Sanity ecosystem; appropriate for this package. | ai | |
| dependencies | unvetted-dep:promptfoo | AI (dependencies): promptfoo is a well-known AI evaluation framework; its use is appropriate and expected for this AI Literacy Framework evaluation tool. | ai | |
| dependencies | unvetted-dep:dotenv-cli | AI (dependencies): dotenv-cli is a standard utility for loading .env files in CLI contexts; used in package.json scripts for promptfoo commands. | ai | |
| dependencies | unvetted-dep:@sanity/client | AI (dependencies): @sanity/client is the official Sanity.io client; expected dependency for a Sanity-scoped evaluation tool. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env spread is used to pass parent environment to a child subprocess (execFileSync), a standard CLI pattern. No exfiltration; stable for this package. | ai | |
| phantom-deps | phantom-dep:dotenv-cli | AI (phantom-deps): dotenv-cli is used as a CLI wrapper in npm scripts (dotenv -e ... -- promptfoo), not imported directly. Expected usage pattern. | ai | |
| phantom-deps | phantom-dep:promptfoo | AI (phantom-deps): promptfoo is invoked as a CLI command in npm scripts, not imported directly. This is expected usage for a CLI orchestration tool. | ai |
Versions (showing 51 of 143)
| Version | Deps | Published |
|---|---|---|
| 7.31.0 | 18 / 10 | |
| 7.30.4 | 18 / 10 | |
| 7.30.3 | 18 / 10 | |
| 7.30.2 | 18 / 10 | |
| 7.30.1 | 18 / 10 | |
| 7.30.0 | 18 / 10 | |
| 7.29.0 | 18 / 10 | |
| 7.28.0 | 18 / 10 | |
| 7.27.1 | 18 / 10 | |
| 7.27.0 | 18 / 10 | |
| 7.26.0 | 18 / 10 | |
| 7.25.0 | 18 / 10 | |
| 7.24.0 | 18 / 10 | |
| 7.22.1 | 18 / 10 | |
| 7.22.0 | 18 / 10 | |
| 7.21.0 | 18 / 10 | |
| 7.19.0 | 17 / 10 | |
| 7.18.1 | 17 / 10 | |
| 7.18.0 | 17 / 10 | |
| 7.17.1 | 17 / 10 | |
| 7.17.0 | 17 / 10 | |
| 7.16.1 | 17 / 10 | |
| 7.16.0 | 17 / 10 | |
| 7.15.0 | 17 / 10 | |
| 7.14.1 | 16 / 10 | |
| 7.14.0 | 16 / 10 | |
| 7.13.0 | 16 / 10 | |
| 7.12.0 | 14 / 10 | |
| 7.11.0 | 14 / 10 | |
| 7.10.0 | 14 / 10 | |
| 7.9.1 | 14 / 10 | |
| 7.9.0 | 14 / 10 | |
| 7.8.2 | 14 / 10 | |
| 7.8.1 | 14 / 10 | |
| 7.8.0 | 14 / 10 | |
| 7.7.0 | 14 / 10 | |
| 7.6.0 | 14 / 10 | |
| 7.5.0 | 14 / 10 | |
| 7.4.2 | 14 / 10 | |
| 7.4.1 | 14 / 10 | |
| 7.4.0 | 14 / 10 | |
| 7.3.1 | 14 / 10 | |
| 7.3.0 | 14 / 10 | |
| 7.2.3 | 14 / 10 | |
| 7.2.2 | 14 / 10 | |
| 7.2.1 | 14 / 10 | |
| 7.2.0 | 14 / 10 | |
| 7.1.2 | 14 / 10 | |
| 7.1.0 | 14 / 10 | |
| 7.0.1 | 14 / 10 | |
| 7.0.0 | 14 / 10 |
v7.31.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.29.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.28.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.27.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.27.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.