@vercel/agent-eval
Framework for testing AI coding agents in isolated sandboxes
53
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
matheussmatt.strakavercel-release-botzeit-bot
Keywords
aievaltestingclaudeagentsandbox
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| email-domain | unclaimed-email:magic.io | AI (email-domain): Package is @vercel-scoped with SLSA provenance via CI; email domain risk is mitigated by strong supply chain attestation. | ai | |
| phantom-deps | phantom-dep:ai | AI (phantom-deps): ai is a peer/optional dep for an AI eval framework; not directly imported in library code is expected. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): glob is legitimately declared and referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/anthropic | AI (phantom-deps): @ai-sdk/anthropic is legitimately declared and referenced in config; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:dockerode | AI (dependencies): dockerode is a well-known Docker API client; its use is appropriate for a sandbox/agent-eval framework. Not a security concern. | ai | |
| dependencies | unvetted-dep:@vercel/sandbox | AI (dependencies): @vercel/sandbox is a first-party Vercel package appropriate for this framework's purpose of running agents in isolated sandboxes. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published with SLSA provenance via Vercel's CI/CD pipeline; this is a stable positive signal for this package. | ai |
Versions (showing 53 of 53)
| Version | Deps | Published |
|---|---|---|
| 1.3.1 | 14 / 8 | |
| 1.3.0 | 14 / 8 | |
| 1.2.0 | 14 / 8 | |
| 1.1.1 | 14 / 8 | |
| 1.1.0 | 14 / 8 | |
| 1.0.1 | 14 / 8 | |
| 1.0.0 | 14 / 8 | |
| 0.14.5 | 14 / 8 | |
| 0.14.4 | 14 / 8 | |
| 0.14.3 | 14 / 8 | |
| 0.14.2 | 14 / 8 | |
| 0.14.1 | 14 / 8 | |
| 0.14.0 | 14 / 8 | |
| 0.13.1 | 14 / 8 | |
| 0.13.0 | 14 / 8 | |
| 0.12.1 | 14 / 8 | |
| 0.12.0 | 14 / 8 | |
| 0.11.0 | 14 / 8 | |
| 0.10.1 | 14 / 8 | |
| 0.10.0 | 14 / 8 | |
| 0.9.5 | 14 / 8 | |
| 0.9.4 | 14 / 8 | |
| 0.9.3 | 14 / 8 | |
| 0.9.2 | 14 / 8 | |
| 0.9.1 | 14 / 8 | |
| 0.9.0 | 14 / 8 | |
| 0.8.0 | 14 / 8 | |
| 0.7.1 | 13 / 8 | |
| 0.7.0 | 13 / 8 | |
| 0.6.2 | 13 / 8 | |
| 0.6.1 | 13 / 8 | |
| 0.6.0 | 13 / 8 | |
| 0.5.0 | 13 / 8 | |
| 0.4.1 | 12 / 8 | |
| 0.4.0 | 12 / 8 | |
| 0.3.2 | 12 / 8 | |
| 0.3.1 | 12 / 8 | |
| 0.3.0 | 12 / 8 | |
| 0.2.0 | 12 / 8 | |
| 0.1.0 | 12 / 8 | |
| 0.0.15 | 11 / 8 | |
| 0.0.14 | 11 / 8 | |
| 0.0.13 | 11 / 8 | |
| 0.0.12 | 10 / 8 | |
| 0.0.11 | 10 / 10 | |
| 0.0.9 | 10 / 8 | |
| 0.0.8 | 10 / 8 | |
| 0.0.6 | 10 / 8 | |
| 0.0.5 | 10 / 8 | |
| 0.0.4 | 8 / 6 | |
| 0.0.3 | 8 / 6 | |
| 0.0.2 | 8 / 6 | |
| 0.0.1 | 8 / 6 |
v1.3.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.