@morphllm/morphmcp
Fast & accurate MCP server with AI-powered file editing and intelligent code search. Prevents context pollution and saves time for a better user experience.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): CLI color utility; indirect usage in build output. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): OpenAI SDK; indirect usage through transitive imports. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Version parsing; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:p-defer | AI (phantom-deps): Promise utility; indirect usage in async code. | ai | |
| phantom-deps | phantom-dep:minimatch | AI (phantom-deps): Pattern matching; indirect usage in build pipeline. | ai | |
| phantom-deps | phantom-dep:string-argv | AI (phantom-deps): CLI argument parsing; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:@vscode/ripgrep | AI (phantom-deps): Code search tool; indirect usage in build pipeline. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Zod used for validation; indirect imports in build/config common for schema tools. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): Diff utility for file comparison; indirect usage in build pipeline. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Glob for file matching; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): HTTP client for API calls; indirect usage through transitive deps. | ai | |
| phantom-deps | phantom-dep:@morphllm/morphsdk | AI (phantom-deps): Same-org scoped dependency; indirect usage in build. | ai | |
| phantom-deps | phantom-dep:zod-to-json-schema | AI (phantom-deps): Schema conversion; indirect usage in build/config. | ai | |
| phantom-deps | phantom-dep:@google/generative-ai | AI (phantom-deps): Google AI SDK; indirect usage through transitive imports. | ai |
Versions (showing 61 of 161)
| Version | Deps | Published |
|---|---|---|
| 0.8.89 | 15 / 12 | |
| 0.8.88 | 15 / 12 | |
| 0.8.87 | 15 / 12 | |
| 0.8.86 | 15 / 12 | |
| 0.8.85 | 15 / 12 | |
| 0.8.84 | 15 / 12 | |
| 0.8.83 | 15 / 12 | |
| 0.8.82 | 15 / 12 | |
| 0.8.81 | 15 / 12 | |
| 0.8.80 | 15 / 12 | |
| 0.8.79 | 15 / 12 | |
| 0.8.78 | 15 / 12 | |
| 0.8.77 | 15 / 12 | |
| 0.8.76 | 15 / 12 | |
| 0.8.75 | 15 / 12 | |
| 0.8.74 | 15 / 12 | |
| 0.8.73 | 15 / 12 | |
| 0.8.72 | 15 / 12 | |
| 0.8.71 | 14 / 12 | |
| 0.8.70 | 14 / 12 | |
| 0.8.68 | 14 / 12 | |
| 0.8.67 | 14 / 12 | |
| 0.8.66 | 14 / 12 | |
| 0.8.65 | 14 / 12 | |
| 0.8.64 | 14 / 12 | |
| 0.8.63 | 14 / 12 | |
| 0.8.62 | 14 / 12 | |
| 0.8.61 | 14 / 12 | |
| 0.8.60 | 14 / 12 | |
| 0.8.59 | 14 / 12 | |
| 0.8.58 | 14 / 12 | |
| 0.8.57 | 14 / 12 | |
| 0.8.56 | 14 / 12 | |
| 0.8.55 | 14 / 12 | |
| 0.8.54 | 14 / 12 | |
| 0.8.53 | 14 / 12 | |
| 0.8.52 | 14 / 12 | |
| 0.8.51 | 14 / 12 | |
| 0.8.47 | 14 / 12 | |
| 0.8.46 | 14 / 12 | |
| 0.8.44 | 14 / 12 | |
| 0.8.38 | 14 / 12 | |
| 0.8.37 | 14 / 12 | |
| 0.8.36 | 14 / 12 | |
| 0.8.35 | 13 / 12 | |
| 0.8.34 | 13 / 12 | |
| 0.8.33 | 13 / 12 | |
| 0.8.32 | 13 / 12 | |
| 0.8.31 | 13 / 12 | |
| 0.8.30 | 13 / 12 | |
| 0.8.29 | 13 / 12 | |
| 0.8.28 | 13 / 12 | |
| 0.8.27 | 13 / 12 | |
| 0.8.26 | 13 / 12 | |
| 0.8.25 | 13 / 12 | |
| 0.8.24 | 13 / 12 | |
| 0.8.23 | 13 / 12 | |
| 0.8.22 | 13 / 12 | |
| 0.8.18 | 13 / 12 | |
| 0.8.6 | 13 / 12 | |
| 0.8.5 | 13 / 12 |
v0.8.89
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.88
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.87
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.86
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.85
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.84
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.83
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.82
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.81
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.80
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.79
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.78
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.77
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.76
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.75
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.74
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.73
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.72
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.71
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.70
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.68
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.67
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.66
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.65
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.64
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.63
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.62
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.61
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.60
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.59
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.58
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.57
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.56
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.55
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.54
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.53
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.52
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.46
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.44
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.8.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.