← Home

@activepieces/piece-mistral-ai

18
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

abuaboudactivepieces-botabdul_activepiecer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:ai AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:fast-glob AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/google AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/anthropic AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@ai-sdk/replicate AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
bogus-package bogus-package AI (bogus-package): Internal framework piece; minimal metadata expected for plugin packages. ai
phantom-deps phantom-dep:socket.io-client AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:@sinclair/typebox AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:axios AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:nanoid AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:mime-types AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:axios-retry AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai
phantom-deps phantom-dep:deepmerge-ts AI (phantom-deps): Framework piece; dependencies declared and used via config/framework integration. ai

Versions (showing 18 of 18)

Version Deps Published
0.2.3 5 / 0
0.2.2 5 / 0
0.2.1 5 / 0
0.2.0 5 / 0
0.1.4 15 / 0
0.1.3 16 / 0
0.1.2 16 / 0
0.1.1 16 / 0
0.1.0 14 / 0
0.0.9 13 / 0
0.0.8 14 / 0
0.0.7 14 / 0
0.0.6 14 / 0
0.0.5 20 / 0
0.0.4 19 / 0
0.0.3 19 / 0
0.0.2 19 / 0
0.0.1 19 / 0

v0.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.