← Home

@tangle-network/agent-knowledge

30
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

vutuanlinh2k2drewstonetjemmmictin-tangle-tools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-BHQk7jOT.d.ts AI (source-diff): Bundled TS declaration file with long type lines, not executable obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): First-party sibling package from same org/monorepo. ai
maintainer-change maintainer-removed AI (maintainer-change): CI/CD provenance-attested publish; no takeover behavior evident. ai
source-diff obfuscated-file:dist/index-BLxw1I_F.d.ts AI (source-diff): Bundled TypeScript declaration file, not obfuscated code. ai
publish-pattern rapid-publish AI (publish-pattern): CI/CD automated release cadence with provenance, not indicative of compromise. ai
source-diff obfuscated-file:dist/index-Cj5jRXOz.d.ts AI (source-diff): Bundled TypeScript .d.ts long-line type declarations, not obfuscation. ai
provenance publisher-changed AI (provenance): Transition from manual (drewstone) to GitHub Actions publishing is confirmed by SLSA provenance attestation; expected for this org. ai
provenance missing-githead AI (provenance): Likely caused by removal of prepare script changing publish flow; no other risk indicators present. ai
provenance slsa-provenance AI (provenance): Package publishes via CI/CD with Sigstore attestation; stable supply chain signal for this package. ai

Versions (showing 30 of 30)

Version Deps Published
4.1.0 4 / 8
4.0.1 4 / 10
3.2.1 4 / 9
3.2.0 4 / 9
3.1.0 4 / 9
3.0.1 4 / 9
3.0.0 4 / 9
2.0.1 4 / 9
2.0.0 3 / 9
1.12.1 2 / 8
1.12.0 2 / 8
1.11.2 2 / 8
1.11.1 2 / 8
1.11.0 2 / 8
1.10.0 3 / 7
1.9.0 3 / 7
1.8.0 3 / 7
1.7.0 3 / 7
1.6.0 3 / 6
1.5.2 3 / 6
1.5.1 3 / 6
1.5.0 4 / 5
1.4.0 4 / 5
1.3.0 2 / 5
1.2.0 2 / 4
1.1.1 2 / 4
1.1.0 2 / 4
1.0.0 2 / 4
0.1.1 2 / 4
0.1.0 2 / 4

v4.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.1

2 findings
HIGH New obfuscated file: dist/index-BHQk7jOT.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

2 findings
HIGH New obfuscated file: dist/index-BLxw1I_F.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.12.1

2 findings
HIGH New obfuscated file: dist/index-Cj5jRXOz.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.12.0

2 findings
HIGH New obfuscated file: dist/index-Cj5jRXOz.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.2

2 findings
HIGH New obfuscated file: dist/index-Cj5jRXOz.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.1

2 findings
HIGH New obfuscated file: dist/index-Cj5jRXOz.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.0

2 findings
HIGH New obfuscated file: dist/index-Cj5jRXOz.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.