deepagents
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/agent-k6GiDPCY.d.ts | AI (source-diff): Generated .d.ts type bundle; readable imports, no obfuscation signature. | ai | |
| source-diff | obfuscated-file:dist/agent-B2XFuA-E.d.cts | AI (source-diff): Generated TypeScript declaration file from tsdown; long lines are build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/agent-D0AY-3B9.d.ts | AI (source-diff): Long-line .d.ts type-declaration bundle from tsdown; benign build output. | ai | |
| source-diff | obfuscated-file:dist/agent-CBuaNmw7.d.cts | AI (source-diff): Long-line .d.cts type-declaration bundle from tsdown; benign build output. | ai | |
| source-diff | obfuscated-file:dist/agent-DsjC63Eg.d.cts | AI (source-diff): Long-line generated .d.cts type bundle from tsdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/agent-DgVtHOV7.d.ts | AI (source-diff): Long-line generated .d.ts type bundle from tsdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/agent-DURA4_mf.d.ts | AI (source-diff): Bundled TypeScript declaration file with long re-export lines; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/agent-2caqZpg2.d.cts | AI (source-diff): Bundled TypeScript declaration file with long re-export lines; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/agent-DNSq5NSK.d.cts | AI (source-diff): TypeScript declaration file with long type-import lines; standard bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/node.d.ts | AI (source-diff): Barrel re-export .d.ts with mangled identifiers from tsdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser.d.ts | AI (source-diff): Barrel re-export .d.ts with mangled identifiers from tsdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/agent-taGqnaXM.d.ts | AI (source-diff): TypeScript declaration file with long type-import lines; standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/node.d.cts | AI (source-diff): Barrel re-export .d.cts with mangled identifiers from tsdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser.d.cts | AI (source-diff): Barrel re-export .d.cts with mangled identifiers from tsdown; not obfuscation. | ai |
Versions (showing 43 of 43)
| Version | Deps | Published |
|---|---|---|
| 1.11.1 | 4 / 19 | |
| 1.11.0 | 4 / 19 | |
| 1.10.8 | 4 / 19 | |
| 1.10.7 | 4 / 19 | |
| 1.10.6 | 4 / 19 | |
| 1.10.5 | 8 / 15 | |
| 1.10.4 | 8 / 15 | |
| 1.10.2 | 8 / 15 | |
| 1.10.1 | 8 / 15 | |
| 1.10.0 | 8 / 15 | |
| 1.9.1 | 8 / 15 | |
| 1.9.0 | 8 / 15 | |
| 1.8.8 | 7 / 15 | |
| 1.8.7 | 7 / 15 | |
| 1.8.6 | 7 / 15 | |
| 1.8.5 | 7 / 15 | |
| 1.8.4 | 8 / 15 | |
| 1.8.3 | 7 / 18 | |
| 1.8.2 | 7 / 18 | |
| 1.8.1 | 7 / 18 | |
| 1.8.0 | 7 / 16 | |
| 1.7.6 | 7 / 15 | |
| 1.7.5 | 7 / 15 | |
| 1.7.4 | 7 / 15 | |
| 1.7.3 | 7 / 15 | |
| 1.7.2 | 7 / 15 | |
| 1.7.1 | 7 / 15 | |
| 1.7.0 | 7 / 15 | |
| 1.6.3 | 7 / 15 | |
| 1.6.2 | 8 / 15 | |
| 1.6.1 | 8 / 15 | |
| 1.6.0 | 8 / 15 | |
| 1.5.1 | 8 / 15 | |
| 1.5.0 | 8 / 15 | |
| 1.4.2 | 8 / 15 | |
| 1.4.1 | 8 / 15 | |
| 1.4.0 | 8 / 15 | |
| 1.3.1 | 7 / 25 | |
| 1.3.0 | 7 / 25 | |
| 1.2.0 | 7 / 25 | |
| 1.1.1 | 7 / 25 | |
| 1.1.0 | 7 / 25 | |
| 1.0.0 | 6 / 9 |
v1.11.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.11.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.