@windyroad/architect
Architecture decision enforcement for AI coding agents
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 0.20.0 | 0 / 0 | |
| 0.5.2 | 0 / 0 | |
| 0.2.0 | 0 / 0 | |
| 0.1.2 | 0 / 0 | |
| 0.1.1 | 0 / 0 |
v0.20.0
1 finding[Reject — re-review on republish] (prior reject: AI (provenance): Provenance regression is a strong supply-chain attack signal for this package; all future versions should be published via CI/CD with attestations to clear this finding.) This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.