@morphllm/morphmcp
Fast & accurate MCP server with AI-powered file editing and intelligent code search. Prevents context pollution and saves time for a better user experience.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): CLI color utility; indirect usage in build output. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): OpenAI SDK; indirect usage through transitive imports. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Version parsing; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:p-defer | AI (phantom-deps): Promise utility; indirect usage in async code. | ai | |
| phantom-deps | phantom-dep:minimatch | AI (phantom-deps): Pattern matching; indirect usage in build pipeline. | ai | |
| phantom-deps | phantom-dep:string-argv | AI (phantom-deps): CLI argument parsing; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:@vscode/ripgrep | AI (phantom-deps): Code search tool; indirect usage in build pipeline. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Zod used for validation; indirect imports in build/config common for schema tools. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): Diff utility for file comparison; indirect usage in build pipeline. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Glob for file matching; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): HTTP client for API calls; indirect usage through transitive deps. | ai | |
| phantom-deps | phantom-dep:@morphllm/morphsdk | AI (phantom-deps): Same-org scoped dependency; indirect usage in build. | ai | |
| phantom-deps | phantom-dep:zod-to-json-schema | AI (phantom-deps): Schema conversion; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:@google/generative-ai | AI (phantom-deps): Google AI SDK; indirect usage through transitive imports. | ai |
Versions (showing 51 of 161)
| Version | Deps | Published |
|---|---|---|
| 0.8.190 | 15 / 12 | |
| 0.8.189 | 15 / 12 | |
| 0.8.188 | 15 / 12 | |
| 0.8.187 | 15 / 12 | |
| 0.8.186 | 15 / 12 | |
| 0.8.185 | 15 / 12 | |
| 0.8.184 | 15 / 12 | |
| 0.8.183 | 15 / 12 | |
| 0.8.182 | 15 / 12 | |
| 0.8.181 | 15 / 12 | |
| 0.8.180 | 15 / 12 | |
| 0.8.179 | 15 / 12 | |
| 0.8.178 | 15 / 12 | |
| 0.8.177 | 15 / 12 | |
| 0.8.176 | 15 / 12 | |
| 0.8.175 | 15 / 12 | |
| 0.8.174 | 15 / 12 | |
| 0.8.173 | 15 / 12 | |
| 0.8.172 | 15 / 12 | |
| 0.8.170 | 15 / 12 | |
| 0.8.169 | 15 / 12 | |
| 0.8.168 | 15 / 12 | |
| 0.8.167 | 15 / 12 | |
| 0.8.166 | 15 / 12 | |
| 0.8.165 | 15 / 12 | |
| 0.8.164 | 15 / 12 | |
| 0.8.163 | 15 / 12 | |
| 0.8.162 | 15 / 12 | |
| 0.8.161 | 15 / 12 | |
| 0.8.160 | 15 / 12 | |
| 0.8.159 | 15 / 12 | |
| 0.8.158 | 15 / 12 | |
| 0.8.157 | 15 / 12 | |
| 0.8.156 | 15 / 12 | |
| 0.8.155 | 15 / 12 | |
| 0.8.154 | 15 / 12 | |
| 0.8.153 | 15 / 12 | |
| 0.8.152 | 15 / 12 | |
| 0.8.151 | 15 / 12 | |
| 0.8.150 | 15 / 12 | |
| 0.8.149 | 15 / 12 | |
| 0.8.148 | 15 / 12 | |
| 0.8.147 | 15 / 12 | |
| 0.8.146 | 15 / 12 | |
| 0.8.145 | 15 / 12 | |
| 0.8.144 | 15 / 12 | |
| 0.8.143 | 15 / 12 | |
| 0.8.142 | 15 / 12 | |
| 0.8.141 | 15 / 12 | |
| 0.8.140 | 15 / 12 | |
| 0.8.139 | 15 / 12 |
v0.8.190
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.189
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.188
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.187
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.186
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.185
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.184
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.183
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.182
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.181
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.180
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.179
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.178
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.177
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.176
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.175
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.174
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.173
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.172
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.170
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.169
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.168
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.167
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.166
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.164
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.162
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.161
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.160
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.159
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.158
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.157
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.156
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.155
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.154
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.153
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.152
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.151
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.150
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.149
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.148
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.147
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.146
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.145
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.144
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.143
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.142
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.141
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.140
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.139
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.