@sentry/skillet
Create, evaluate, and iterate on agent skills
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:ai | AI (phantom-deps): Used via config, common for AI SDK integration. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Used via config/schema definitions, not direct import. | ai | |
| phantom-deps | phantom-dep:tinyrainbow | AI (phantom-deps): Used via config, minor terminal-color helper dep. | ai | |
| dependencies | unvetted-dep:vitest-evals | AI (dependencies): Legitimate eval-testing dep for this Sentry agent-skills tool. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): vitest is a well-known, established test framework; not a suspicious dependency. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 1.6.0 | 6 / 6 | |
| 1.5.0 | 6 / 6 | |
| 1.4.1 | 6 / 6 | |
| 1.4.0 | 6 / 6 | |
| 1.3.0 | 6 / 6 | |
| 1.2.0 | 6 / 6 | |
| 0.28.0 | 3 / 6 | |
| 0.27.0 | 3 / 6 | |
| 0.26.1 | 3 / 6 | |
| 0.26.0 | 3 / 6 | |
| 0.25.0 | 3 / 6 | |
| 0.24.1 | 3 / 6 | |
| 0.24.0 | 3 / 6 | |
| 0.23.0 | 3 / 6 | |
| 0.22.0 | 3 / 6 | |
| 0.21.0 | 3 / 6 | |
| 0.20.0 | 3 / 6 | |
| 0.19.0 | 3 / 6 | |
| 0.18.0 | 3 / 6 | |
| 0.17.0 | 3 / 6 | |
| 0.16.0 | 2 / 6 | |
| 0.15.0 | 2 / 6 | |
| 0.14.0 | 2 / 6 | |
| 0.13.0 | 2 / 6 | |
| 0.12.0 | 2 / 6 | |
| 0.11.0 | 2 / 6 | |
| 0.10.0 | 2 / 6 | |
| 0.9.0 | 2 / 6 | |
| 0.8.0 | 2 / 6 | |
| 0.7.0 | 2 / 6 | |
| 0.6.0 | 2 / 6 | |
| 0.5.0 | 2 / 6 | |
| 0.4.0 | 2 / 6 | |
| 0.3.0 | 2 / 6 | |
| 0.2.0 | 2 / 6 | |
| 0.1.0 | 2 / 6 |
v1.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.