> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Supply Chain Trust

> How Mnemom publishes its npm packages, which carry SLSA provenance, and how to verify the packages you install.

Our npm packages under the `@mnemom/*` scope are published from GitHub Actions through npm's [Trusted Publisher](https://docs.npmjs.com/trusted-publishers) system, so no long-lived npm token is involved. Packages built from our public repositories also carry **SLSA build provenance**: a signed attestation that ties the published tarball to the workflow run, repository and commit that built it.

## What provenance means

For packages with provenance, the tarball on the npm registry is accompanied by a [SLSA provenance attestation](https://slsa.dev/spec/v1.0/provenance) (predicate type `https://slsa.dev/provenance/v1`). The attestation is:

* **Signed** via [sigstore](https://www.sigstore.dev/), using short-lived keys issued only to the specific GitHub Actions workflow run.
* **Bound to the source** — records the exact commit SHA, repository, and workflow path used to build the package.
* **Transparent** — published to the public sigstore transparency log; anyone can audit the full signing history.

## Packages without provenance

npm only issues provenance for packages built from a public source repository. Packages built from our private platform repository are published through Trusted Publisher without a provenance attestation: the CLI (`@mnemom/mnemom`), `@mnemom/sdk`, `@mnemom/policy-engine` and `@mnemom/team-coherence`. Earlier releases of some of these, published while that repository was public, do carry provenance. For these packages, `npm audit signatures` reports a verified registry signature and may report no attestation; that is expected.

## Recording what your agents ran on

Provenance covers the packages you install. To record which SDK, and optionally which dependency lockfile, each agent call ran on, use the [substrate fingerprint](/concepts/substrate-fingerprint): the gateway stores it on every integrity checkpoint. If you later learn that a dependency was compromised, you can find the checkpoints, and so the agent decisions, that ran on it. See the [lockfile-hash opt-in guide](/guides/lockfile-hash-opt-in) to set it up. Mnemom does not analyze fingerprints for compromise; it records them for your audit.

## Verifying a package

### Quick check with npm

```bash theme={null}
# Install, then verify signatures and attestations for your dependency tree:
npm install @mnemom/agent-integrity-protocol
npm audit signatures
```

Expected output:

```
audited 1 package in 0s

1 package has a verified registry signature
1 package has a verified attestation
```

If any `@mnemom/*` package not listed under [packages without provenance](#packages-without-provenance) reports `missing attestations`, or any package reports an invalid signature, treat it as a supply-chain incident and contact [security@mnemom.ai](mailto:security@mnemom.ai) before using the installed code.

### Inspecting provenance directly

```bash theme={null}
npm view @mnemom/agent-integrity-protocol dist.attestations
```

You should see an entry like:

```
{
  url: 'https://registry.npmjs.org/-/npm/v1/attestations/@mnemom%2fagent-integrity-protocol@1.3.0',
  provenance: { predicateType: 'https://slsa.dev/provenance/v1' }
}
```

### SBOMs

Each publish generates a CycloneDX software bill of materials (SBOM). For packages released from our public repositories, the SBOM is attached to the GitHub release, for example on [mnemom/mnemom-types releases](https://github.com/mnemom/mnemom-types/releases). SBOMs are CycloneDX JSON and work with standard scanners such as Grype, Trivy and Dependency-Track.

## Packages covered

All packages under the `@mnemom/*` scope on npm. A non-exhaustive list:

| Package | Repo | Provenance |
| - | - | - |
| `@mnemom/agent-alignment-protocol` | [mnemom/aap](https://github.com/mnemom/aap) | Yes |
| `@mnemom/agent-integrity-protocol` | [mnemom/aip](https://github.com/mnemom/aip) | Yes |
| `@mnemom/aip-otel-exporter` | [mnemom/aip-otel-exporter](https://github.com/mnemom/aip-otel-exporter) | Yes |
| `@mnemom/types` | [mnemom/mnemom-types](https://github.com/mnemom/mnemom-types) | Yes |
| `@mnemom/mnemom` (CLI) | Private | No |
| `@mnemom/sdk` | Private | No (some earlier releases: yes) |
| `@mnemom/policy-engine` | Private | No (some earlier releases: yes) |
| `@mnemom/team-coherence` | Private | No (some earlier releases: yes) |

## Reporting concerns

If you encounter a package that fails verification, or you have questions about the supply-chain posture, email [security@mnemom.ai](mailto:security@mnemom.ai) or see our [security policy](/SECURITY).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.