@agentuity/runtime
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/ws | AI (phantom-deps): @types packages are type-only and loaded by convention, not direct import. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): 127.0.0.1 is a localhost server binding, not an exfiltration endpoint. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 used for HMAC signature comparison; standard crypto pattern, not obfuscation. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a newly added runtime dep; phantom-dep heuristic likely fires before import wiring is complete. | ai | |
| phantom-deps | phantom-dep:@agentuity/schema | AI (phantom-deps): Same-org schema package; likely used via type imports or re-exports not caught by the heuristic. | ai | |
| phantom-deps | phantom-dep:@types/mailparser | AI (phantom-deps): @types packages are type-only and won't appear as direct imports. | ai |
Versions (showing 32 of 132)
| Version | Deps | Published |
|---|---|---|
| 0.1.42 | 22 / 11 | |
| 0.1.41 | 22 / 11 | |
| 0.1.40 | 22 / 11 | |
| 0.1.39 | 22 / 11 | |
| 0.1.38 | 22 / 11 | |
| 0.1.37 | 22 / 11 | |
| 0.1.36 | 22 / 11 | |
| 0.1.35 | 22 / 11 | |
| 0.1.34 | 22 / 11 | |
| 0.1.33 | 22 / 11 | |
| 0.1.32 | 22 / 11 | |
| 0.1.31 | 22 / 11 | |
| 0.1.30 | 22 / 11 | |
| 0.1.29 | 22 / 11 | |
| 0.1.28 | 22 / 11 | |
| 0.1.27 | 22 / 11 | |
| 0.1.26 | 22 / 11 | |
| 0.1.25 | 22 / 11 | |
| 0.1.8 | 24 / 11 | |
| 0.0.112 | 23 / 11 | |
| 0.0.100 | 24 / 11 | |
| 0.0.99 | 24 / 11 | |
| 0.0.98 | 24 / 11 | |
| 0.0.97 | 24 / 11 | |
| 0.0.69 | 24 / 8 | |
| 0.0.51 | 21 / 7 | |
| 0.0.50 | 20 / 8 | |
| 0.0.49 | 20 / 5 | |
| 0.0.48 | 20 / 5 | |
| 0.0.45 | 19 / 6 | |
| 0.0.44 | 19 / 6 | |
| 0.0.43 | 18 / 5 |
v0.1.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.112
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.100
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.99
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.98
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.97
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.69
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.51
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.50
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.49
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.48
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.45
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.44
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.