khoj-ai/khoj - passport
khoj-ai/khoj: Passed: Source link matches (PyPI:khoj@1.42.10); Refused: No known advisories for this version (last checked 2026-10-11). Not yet checked (not a failure): License file read, MCP tool list hashed, Setup recipe reproduced, Publisher manifest read, Publisher domain checked, OpenSSF Scorecard read, Reviewed by an independent person, Reviewed by a peer agent of a different owner.
Stamps (passed, refused or changed)
- [REFUSED] No known advisories for this version (advisory-clean), version: PyPI:khoj@1.42.10, checked 2026-10-11: Refused: A published advisory affects the current release PyPI:khoj@1.42.10 (GHSA-6whj-7qmg-86qj, PYSEC-2026-1491). (2026-10-11)
- [PASSED] Source link matches (provenance-linked), version: PyPI:khoj@1.42.10, checked 2026-10-11, issued 2026-10-11T14:33, expires 2026-11-10, by KarmaDue check (build-provenance@1): Signed build record for PyPI:khoj@1.42.10 names https://github.com/khoj-ai/khoj at commit a6fe2d2. Sigstore signature verified by deps.dev (Google Open Source Insights), not by KarmaDue.
Not yet checked (not a failure)
- License file read (license-checked)
- MCP tool list hashed (schema-disclosed)
- Setup recipe reproduced (recipe-reproduced)
- Publisher manifest read (manifest-declared)
- Publisher domain checked (publisher-domain-verified)
- OpenSSF Scorecard read (openssf-scorecard-read)
- Reviewed by an independent person (human-reviewed)
- Reviewed by a peer agent of a different owner (peer-reviewed)
Identity
- current version: PyPI:khoj@1.42.10 (current release, read from the package registry 2026-10-11; stamps bind to this)
- listed as: master (catalog listing)
- package: PyPI:khoj@1.42.10
- type: github_repo
- license: AGPL-3.0
- locator: https://github.com/khoj-ai/khoj
- website: https://khoj.dev
- publisher: {"name": "github:khoj-ai; pypi:debanjum singh solanky, saba imran", "basis": "Upstream owner and maintainers read on 2026-10-11 (GitHub owner, npm or PyPI maintainers)."}
- resource id: kd:res:github:khoj-ai/khoj
- source repo: https://github.com/khoj-ai/khoj
History
- 2026-10-11 stamp.refusal_withdrawn advisory-clean: listed_version_affected
- 2026-10-11 stamp.refused advisory-clean: listed_version_affected
- 2026-10-11 stamp.issued provenance-linked
- 2026-10-11 stamp.corrected provenance-linked: issued_at was the evidence time, not the signing time
- 2026-10-11 stamp.refused advisory-clean: listed_version_affected
- 2026-10-11 stamp.issued provenance-linked
Check it yourself
- Signed statement (kd-subject-passport-v1): kOfqNzrILalCAXiN4FBnlCL6UMR9rxZMHU1ju4ucQER-Ed4d5De-plE4FUKIf-RAeZvhOXwuwetFIoDmx7HiDQ
- JSON: GET https://ogogoizwsfaduzehkshb.supabase.co/functions/v1/public-api/v1/passport/kd:res:github:khoj-ai/khoj
- Standards for every stamp: https://karmadue.expo.app/standards
- Signing key kd-passport-1: https://karmadue.expo.app/.well-known/jwks.json
- A passport lists what was checked, for which version, and when. A stamp is a dated record of one check: not an endorsement and not a safety guarantee.