← Home

@vibe-agent-toolkit/rag

39
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jeffrdutton

Keywords

ragvector-searchembeddingsretrieval

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped monorepo package; Levenshtein match to 'pg' is coincidental, not impersonation. ai

Versions (showing 39 of 39)

Version Deps Published
0.1.40 5 / 3
0.1.39 5 / 3
0.1.38 5 / 3
0.1.37 5 / 3
0.1.36 5 / 3
0.1.35 5 / 3
0.1.34 5 / 3
0.1.33 5 / 3
0.1.32 5 / 3
0.1.31 5 / 3
0.1.30 5 / 3
0.1.29 5 / 3
0.1.28 5 / 3
0.1.27 5 / 3
0.1.26 5 / 3
0.1.25 5 / 3
0.1.24 5 / 3
0.1.23 5 / 3
0.1.22 5 / 3
0.1.21 5 / 3
0.1.20 5 / 3
0.1.19 5 / 3
0.1.18 5 / 3
0.1.15 5 / 3
0.1.14 5 / 3
0.1.13 6 / 3
0.1.12 6 / 3
0.1.11 6 / 3
0.1.10 6 / 3
0.1.9 6 / 3
0.1.8 6 / 3
0.1.7 6 / 3
0.1.6 6 / 3
0.1.5 6 / 3
0.1.4 6 / 3
0.1.3 6 / 3
0.1.2 6 / 3
0.1.1 6 / 3
0.1.0 6 / 3

v0.1.40

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.39

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.