openclaw
17
Versions
—
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
steipetevincentkoc
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@openclaw/ai | AI (dependencies): First-party org-scoped dependency, expected addition. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party/image-processing libs matching stated function. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundled dist output changes hash each build; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:web-tree-sitter | AI (phantom-deps): Tree-sitter WASM binding loaded at runtime; stable phantom-dep for this package. | ai | |
| dependencies | unvetted-dep:grammy | AI (dependencies): grammy is a legitimate Telegram bot framework consistent with openclaw's channel/messaging architecture. | ai | |
| dependencies | unvetted-dep:@lydell/node-pty | AI (dependencies): node-pty fork for terminal emulation; consistent with openclaw's process/CLI runtime features. | ai | |
| phantom-deps | phantom-dep:@openclaw/proxyline | AI (phantom-deps): Same-org scoped dep; consistent with plugin architecture dynamically loading deps at runtime. | ai | |
| phantom-deps | phantom-dep:@silvia-odwyer/photon-node | AI (phantom-deps): Image processing lib; consumed by bundled dist code. | ai | |
| phantom-deps | phantom-dep:@earendil-works/pi-agent-core | AI (phantom-deps): Bundled app; deps consumed by dist bundles not visible to static import scan. | ai | |
| phantom-deps | phantom-dep:partial-json | AI (phantom-deps): Bundled at build time into dist/ files. | ai | |
| phantom-deps | phantom-dep:@google/genai | AI (phantom-deps): Bundled at build time; official Google AI SDK. | ai | |
| phantom-deps | phantom-dep:hosted-git-info | AI (phantom-deps): Bundled at build time; well-known ecosystem package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Standard subprocess launch pattern spreading env for child processes. | ai | |
| phantom-deps | phantom-dep:@mistralai/mistralai | AI (phantom-deps): Bundled at build time; official Mistral AI SDK. | ai | |
| phantom-deps | phantom-dep:proper-lockfile | AI (phantom-deps): Bundled at build time; well-known ecosystem package. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): Bundled at build time into dist/ JS files; standard utility dep for this monorepo package. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Bundled at build time; well-known ecosystem package. | ai | |
| phantom-deps | phantom-dep:ignore | AI (phantom-deps): Bundled at build time; well-known ecosystem package. | ai | |
| phantom-deps | phantom-dep:minimatch | AI (phantom-deps): Bundled at build time; well-known ecosystem package. | ai | |
| phantom-deps | phantom-dep:cross-spawn | AI (phantom-deps): Bundled at build time; well-known ecosystem package. | ai | |
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): Bundled at build time; well-known ecosystem package. | ai | |
| phantom-deps | phantom-dep:@grammyjs/transformer-throttler | AI (phantom-deps): Bundled at build time; Grammy ecosystem plugin. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Bundled app; deps consumed in build output, not bare source imports. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Bundled dist output; imports resolved at build time, not visible in shipped JS. | ai | |
| phantom-deps | phantom-dep:file-type | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:ipaddr.js | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:rastermill | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:tokenjuice | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:@clack/core | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:node-edge-tts | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:playwright-core | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:@grammyjs/runner | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:@homebridge/ciao | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:tree-sitter-bash | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:@openclaw/fs-safe | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:linkedom | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:tslog | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:kysely | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:@mozilla/readability | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:@earendil-works/pi-tui | AI (phantom-deps): Bundled dist output; imports resolved at build time. | ai | |
| phantom-deps | phantom-dep:global-agent | AI (phantom-deps): global-agent added for proxy support; likely loaded conditionally at runtime, not statically imported. | ai | |
| phantom-deps | phantom-dep:qrcode | AI (phantom-deps): qrcode added as runtime dep for CLI QR display; phantom detection likely misses dynamic/conditional imports in bundled dist. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Package-manager warning script; benign and consistent across versions of this CLI tool. | ai | |
| phantom-deps | phantom-dep:@mariozechner/pi-agent-core | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:@vincentkoc/qrcode-tui | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:@mariozechner/pi-tui | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:@lydell/node-pty | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:osc-progress | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:sqlite-vec | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:web-push | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| phantom-deps | phantom-dep:croner | AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Bundled plugin setup script; consistent with documented plugin architecture of this CLI tool. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 2026.7.1 | 56 / 31 | |
| 2026.6.11 | 54 / 31 | |
| 2026.6.10 | 54 / 31 | |
| 2026.6.9 | 54 / 31 | |
| 2026.6.8 | 55 / 31 | |
| 2026.6.6 | 55 / 31 | |
| 2026.6.5 | 55 / 31 | |
| 2026.5.28 | 58 / 31 | |
| 2026.5.27 | 50 / 23 | |
| 2026.5.26 | 50 / 23 | |
| 2026.5.22 | 50 / 23 | |
| 2026.5.20 | 50 / 23 | |
| 2026.5.19 | 50 / 23 | |
| 2026.5.18 | 50 / 23 | |
| 2026.5.12 | 51 / 24 | |
| 2026.4.29 | 35 / 22 | |
| 2026.4.26 | 35 / 22 |
v2026.7.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.6.11
2 findings
HIGH
Phantom dependency: web-tree-sitter
phantom-deps
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.