skybridge
Skybridge is a framework for building ChatGPT and MCP Apps
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Package publishes via GitHub Actions CI/CD with SLSA provenance; rapid publishes are expected for automated releases. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All added deps are established ecosystem packages appropriate for a ChatGPT/MCP framework; not a supply-chain injection pattern. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Active framework with frequent releases; file count growth is expected and SLSA provenance confirms CI-built artifact. | ai | |
| dependencies | unvetted-dep:superjson | AI (dependencies): superjson is a well-known, widely-used JSON serialization library. Unvetted status is a process artifact; no real risk for this package. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): handlebars is a mature, widely-used templating engine. Version ^4.7.9 is current and not known-vulnerable. Unvetted status is a process artifact. | ai |
Versions (showing 51 of 51)
| Version | Deps | Published |
|---|---|---|
| 1.3.1 | 18 / 20 | |
| 1.3.0 | 18 / 20 | |
| 1.2.7 | 17 / 20 | |
| 1.2.6 | 17 / 20 | |
| 1.2.5 | 17 / 20 | |
| 1.1.1 | 16 / 20 | |
| 1.0.4 | 16 / 20 | |
| 1.0.0 | 15 / 20 | |
| 0.36.3 | 15 / 20 | |
| 0.36.2 | 13 / 19 | |
| 0.36.1 | 13 / 19 | |
| 0.36.0 | 13 / 19 | |
| 0.35.21 | 13 / 19 | |
| 0.35.20 | 13 / 19 | |
| 0.35.19 | 13 / 19 | |
| 0.35.14 | 13 / 18 | |
| 0.35.13 | 13 / 18 | |
| 0.35.12 | 13 / 18 | |
| 0.35.11 | 13 / 18 | |
| 0.35.10 | 13 / 18 | |
| 0.35.5 | 12 / 19 | |
| 0.35.4 | 12 / 19 | |
| 0.35.2 | 12 / 19 | |
| 0.27.1 | 13 / 19 | |
| 0.26.2 | 13 / 19 | |
| 0.26.0 | 13 / 19 | |
| 0.24.0 | 11 / 19 | |
| 0.23.4 | 11 / 19 | |
| 0.23.3 | 11 / 19 | |
| 0.20.0 | 11 / 19 | |
| 0.17.2 | 9 / 16 | |
| 0.16.10 | 8 / 16 | |
| 0.16.9 | 8 / 16 | |
| 0.16.8 | 8 / 16 | |
| 0.16.6 | 8 / 17 | |
| 0.16.3 | 8 / 17 | |
| 0.16.1 | 8 / 17 | |
| 0.15.0 | 7 / 18 | |
| 0.12.0 | 7 / 17 | |
| 0.9.5 | 7 / 14 | |
| 0.9.4 | 7 / 14 | |
| 0.9.0 | 7 / 14 | |
| 0.8.2 | 7 / 14 | |
| 0.5.0 | 6 / 13 | |
| 0.2.6 | 6 / 13 | |
| 0.2.4 | 6 / 13 | |
| 0.2.3 | 6 / 13 | |
| 0.2.1 | 6 / 13 | |
| 0.2.0 | 6 / 13 | |
| 0.1.0 | 6 / 11 | |
| 0.0.1 | 0 / 1 |
v1.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.