{"uid":"cap_e6JLvJmllTS_nH1BVQ1ox","slug":"dependency-provenance-assessment-4d431928","name":"Dependency Provenance Assessment","description":"Check declared dependency identity, source and digest coverage","url":"https://phion.systems/v1/paid/trust/dependency-provenance-assessment","method":"POST","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema"},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_2IT30tdGdtvIPJph5c3Vt","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Checks declared software dependencies for identity integrity, source authenticity, and cryptographic digest coverage","exampleAgentPrompt":"Can you check the provenance of the dependencies listed in our project manifest — I need to know which ones have verified identity, confirmed source origins, and cryptographic digest coverage?","exampleUseCases":[{"title":"Supply chain audit before release","prompt":"Before we ship this release, run a dependency provenance assessment on all our declared packages and tell me which ones are missing digest coverage or have unverified source origins."},{"title":"CI pipeline integrity gate","prompt":"We want to block builds where any dependency fails provenance checks — can you assess the identity, source, and digest coverage for the dependencies in this lockfile and flag any that don't pass?"},{"title":"Third-party vendor package review","prompt":"We've integrated a vendor-supplied library into our project. Can you assess its dependency provenance to confirm the declared identity matches the source and that all digests are accounted for?"}],"resultDescription":"Returns a structured assessment of declared dependency provenance, including: identity verification status (whether the declared package identity is confirmed), source coverage (whether dependencies trace to verifiable, authentic sources), and digest coverage (whether cryptographic digests are present and valid for all declared dependencies), along with any gaps or failures detected.","failureModes":["Missing or malformed dependency declarations in the input payload result in validation errors","Dependencies referencing private or inaccessible registries may yield incomplete source coverage","Unrecognized package ecosystems may reduce assessment coverage","Stale or unsupported digest algorithms may be flagged as insufficient coverage","Service may return partial results if upstream provenance data sources are unavailable"],"whenToPreferThis":"Choose this endpoint when you need a focused, machine-verifiable attestation of whether software dependencies have proper identity, traceable source origins, and cryptographic digest coverage — particularly in CI/CD pipelines, software release gates, or supply chain audits. Prefer this over general vulnerability scanners when the concern is provenance and attestation integrity rather than known CVEs.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T06:48:16.568Z","isFirstParty":false}