← Home

openclaw

17
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

steipetevincentkoc

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@openclaw/ai AI (dependencies): First-party org-scoped dependency, expected addition. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party/image-processing libs matching stated function. ai
source-diff large-new-source-files AI (source-diff): Bundled dist output changes hash each build; stable pattern for this package. ai
phantom-deps phantom-dep:web-tree-sitter AI (phantom-deps): Tree-sitter WASM binding loaded at runtime; stable phantom-dep for this package. ai
dependencies unvetted-dep:grammy AI (dependencies): grammy is a legitimate Telegram bot framework consistent with openclaw's channel/messaging architecture. ai
dependencies unvetted-dep:@lydell/node-pty AI (dependencies): node-pty fork for terminal emulation; consistent with openclaw's process/CLI runtime features. ai
phantom-deps phantom-dep:@openclaw/proxyline AI (phantom-deps): Same-org scoped dep; consistent with plugin architecture dynamically loading deps at runtime. ai
phantom-deps phantom-dep:@silvia-odwyer/photon-node AI (phantom-deps): Image processing lib; consumed by bundled dist code. ai
phantom-deps phantom-dep:@earendil-works/pi-agent-core AI (phantom-deps): Bundled app; deps consumed by dist bundles not visible to static import scan. ai
phantom-deps phantom-dep:partial-json AI (phantom-deps): Bundled at build time into dist/ files. ai
phantom-deps phantom-dep:@google/genai AI (phantom-deps): Bundled at build time; official Google AI SDK. ai
phantom-deps phantom-dep:hosted-git-info AI (phantom-deps): Bundled at build time; well-known ecosystem package. ai
semgrep semgrep:env-spread AI (semgrep): Standard subprocess launch pattern spreading env for child processes. ai
phantom-deps phantom-dep:@mistralai/mistralai AI (phantom-deps): Bundled at build time; official Mistral AI SDK. ai
phantom-deps phantom-dep:proper-lockfile AI (phantom-deps): Bundled at build time; well-known ecosystem package. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Bundled at build time into dist/ JS files; standard utility dep for this monorepo package. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Bundled at build time; well-known ecosystem package. ai
phantom-deps phantom-dep:ignore AI (phantom-deps): Bundled at build time; well-known ecosystem package. ai
phantom-deps phantom-dep:minimatch AI (phantom-deps): Bundled at build time; well-known ecosystem package. ai
phantom-deps phantom-dep:cross-spawn AI (phantom-deps): Bundled at build time; well-known ecosystem package. ai
phantom-deps phantom-dep:highlight.js AI (phantom-deps): Bundled at build time; well-known ecosystem package. ai
phantom-deps phantom-dep:@grammyjs/transformer-throttler AI (phantom-deps): Bundled at build time; Grammy ecosystem plugin. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): Bundled app; deps consumed in build output, not bare source imports. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Bundled dist output; imports resolved at build time, not visible in shipped JS. ai
phantom-deps phantom-dep:file-type AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:ipaddr.js AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:rastermill AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:tokenjuice AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:typescript AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:@clack/core AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:node-edge-tts AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:playwright-core AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:@grammyjs/runner AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:@homebridge/ciao AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:tree-sitter-bash AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:@openclaw/fs-safe AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:openai AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:linkedom AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:tslog AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:kysely AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:@mozilla/readability AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:@earendil-works/pi-tui AI (phantom-deps): Bundled dist output; imports resolved at build time. ai
phantom-deps phantom-dep:global-agent AI (phantom-deps): global-agent added for proxy support; likely loaded conditionally at runtime, not statically imported. ai
phantom-deps phantom-dep:qrcode AI (phantom-deps): qrcode added as runtime dep for CLI QR display; phantom detection likely misses dynamic/conditional imports in bundled dist. ai
install-scripts install-script:preinstall AI (install-scripts): Package-manager warning script; benign and consistent across versions of this CLI tool. ai
phantom-deps phantom-dep:@mariozechner/pi-agent-core AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:@vincentkoc/qrcode-tui AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:@mariozechner/pi-tui AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:@lydell/node-pty AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:osc-progress AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:sqlite-vec AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:web-push AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
phantom-deps phantom-dep:croner AI (phantom-deps): Bundled plugin architecture; deps loaded dynamically, not statically imported. ai
install-scripts install-script:postinstall AI (install-scripts): Bundled plugin setup script; consistent with documented plugin architecture of this CLI tool. ai

Versions (showing 17 of 17)

Version Deps Published
2026.7.1 56 / 31
2026.6.11 54 / 31
2026.6.10 54 / 31
2026.6.9 54 / 31
2026.6.8 55 / 31
2026.6.6 55 / 31
2026.6.5 55 / 31
2026.5.28 58 / 31
2026.5.27 50 / 23
2026.5.26 50 / 23
2026.5.22 50 / 23
2026.5.20 50 / 23
2026.5.19 50 / 23
2026.5.18 50 / 23
2026.5.12 51 / 24
2026.4.29 35 / 22
2026.4.26 35 / 22

v2026.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2026.6.11

2 findings
HIGH Phantom dependency: web-tree-sitter phantom-deps

Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.