# nocodb/nocodb - passport

nocodb/nocodb: Passed: License file read (commit ba068da), Source link matches (npm:nocodb@0.301.3); Refused: No known advisories for this version; Changed, re-check pending: OpenSSF Scorecard read (last checked 2026-10-11). Not yet checked (not a failure): MCP tool list hashed, Setup recipe reproduced, Publisher manifest read, Publisher domain checked, Reviewed by an independent person, Reviewed by a peer agent of a different owner.

## Stamps (passed, refused or changed)

- \[PASSED\] License file read (license-checked), version: commit ba068da, checked 2026-10-10, issued 2026-10-11T14:31, expires 2026-11-09, by KarmaDue check (license-file-read@1): KarmaDue read the LICENSE file at this commit and it names one recognised license. (<https://karmadue.expo.app/standards#license-checked>)
- \[REFUSED\] No known advisories for this version (advisory-clean), version: npm:nocodb@0.301.3, checked 2026-10-11: Refused: A published advisory affects the current release npm:nocodb@0.301.3 (GHSA-2c5x-4jgf-88mj, GHSA-4w6r-5c2j-qf5f, GHSA-6mhr-74x2-98v9, GHSA-6xcx-7qmg-vjfq, GHSA-8m7c-hf24-5g47, GHSA-8rwr-f68v-cvw6, GHSA-96fh-m4r8-6v9v, GHSA-99vc-2jx2-688p). (2026-10-11) (<https://karmadue.expo.app/standards#advisory-clean>)
- \[PASSED\] Source link matches (provenance-linked), version: npm:nocodb@0.301.3, checked 2026-10-11, issued 2026-10-11T14:31, expires 2026-11-10, by KarmaDue check (provenance-link@1): A signed build record (npm provenance or a SLSA attestation) or the package metadata points back to this exact source repository. (<https://karmadue.expo.app/standards#provenance-linked>)
- \[CHANGED\] OpenSSF Scorecard read (openssf-scorecard-read), version: commit 10cb56d, checked 2026-10-05, issued 2026-10-11T14:31, expires 2026-11-04, by OpenSSF Scorecard (read by KarmaDue): Something this stamp depends on changed since it was issued: OpenSSF Scorecard's latest published result covers commit 10cb56d516d1; the repository HEAD is now ba068da3a8e9. Re-read when OpenSSF rescans (weekly). (<https://karmadue.expo.app/standards#openssf-scorecard-read>)

## Not yet checked (not a failure)

- MCP tool list hashed (schema-disclosed) (<https://karmadue.expo.app/standards#schema-disclosed>)
- Setup recipe reproduced (recipe-reproduced) (<https://karmadue.expo.app/standards#recipe-reproduced>)
- Publisher manifest read (manifest-declared) (<https://karmadue.expo.app/standards#manifest-declared>)
- Publisher domain checked (publisher-domain-verified) (<https://karmadue.expo.app/standards#publisher-domain-verified>)
- Reviewed by an independent person (human-reviewed) (<https://karmadue.expo.app/standards#human-reviewed>)
- Reviewed by a peer agent of a different owner (peer-reviewed) (<https://karmadue.expo.app/standards#peer-reviewed>)

## Identity

- current version: npm:nocodb@0.301.3 (current release, read from the package registry 2026-10-11; stamps bind to this)
- listed as: develop (catalog listing)
- package: npm:nocodb@0.301.3
- type: github\_repo
- commit: {"sha": "ba068da3a8e984ab807841b632df695cdfa4e8a0", "branch": "develop", "method": "license-file-read", "read\_at": "2026-10-10T23:46:56+00:00"}
- license: Sustainable Use License
- locator: https://github.com/nocodb/nocodb
- website: https://nocodb.com
- publisher: {"name": "github:nocodb; npm:dstala,mertmit,o1lab,pranavxc,wingkwong", "basis": "Upstream owner and maintainers read on 2026-10-11 (GitHub owner, npm or PyPI maintainers)."}
- resource id: kd:res:github:nocodb/nocodb
- source repo: https://github.com/nocodb/nocodb

## History

- 2026-10-11 stamp.changed openssf-scorecard-read: OpenSSF Scorecard's latest published result covers commit 10cb56d516d1; the repository HEAD is now ba068da3a8e9. Re-read when OpenSSF rescans (weekly).
- 2026-10-11 stamp.refusal\_withdrawn advisory-clean: listed\_version\_affected
- 2026-10-11 stamp.refused advisory-clean: listed\_version\_affected
- 2026-10-11 stamp.corrected provenance-linked: issued\_at was the evidence time, not the signing time
- 2026-10-11 stamp.corrected license-checked: issued\_at was the evidence time, not the signing time
- 2026-10-11 stamp.corrected openssf-scorecard-read: issued\_at was the evidence time, not the signing time
- 2026-10-11 stamp.issued openssf-scorecard-read
- 2026-10-11 stamp.refused advisory-clean: listed\_version\_affected
- 2026-10-11 stamp.issued provenance-linked
- 2026-10-11 stamp.issued license-checked

## Check it yourself

- Signed statement (kd-subject-passport-v1): v-DcJO4wnxo1Ge1y57sv6t0FVlLF7ryWhWpW62109zaTmOT1HoQk9S0aZEYAgxzaR4nOcQxF22geXMdyqoQsDg
- JSON: GET https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/public-api/v1/passport/kd:res:github:nocodb/nocodb (<https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/public-api/v1/passport/kd:res:github:nocodb/nocodb>)
- Standards for every stamp: https://karmadue.expo.app/standards (<https://karmadue.expo.app/standards>)
- Signing key kd-passport-1: https://karmadue.expo.app/.well-known/jwks.json (<https://karmadue.expo.app/.well-known/jwks.json>)
- A passport lists what was checked, for which version, and when. A stamp is a dated record of one check: not an endorsement and not a safety guarantee.

---

Page: https://karmadue.expo.app/passport/kd:res:github:nocodb/nocodb
Markdown: https://karmadue.expo.app/passport/kd:res:github:nocodb/nocodb.md
Interactive view: https://karmadue.expo.app/resource?id=kd:res:github:nocodb/nocodb
Any HTTP client (no bot checks): https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/docs/passport/kd:res:github:nocodb/nocodb.md

KarmaDue keeps passports for AI agents and the tools they use: signed, dated records of what was checked. MCP: https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/mcp · Guide: https://karmadue.expo.app/llms.txt
