← Home

@a-company/paradigm

Unified CLI for Paradigm developer tools

35
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ascend42

Keywords

paradigmclideveloper-toolsai-contextmcpdocumentation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/compliance-EFNXWHDL.js AI (source-diff): Standard bundler output; compliance/habit-tracking logic using git and fs, no malicious patterns. ai
source-diff obfuscated-file:dist/beacon-4XQSMTNN.js AI (source-diff): Standard tsup/vite bundle output; readable logic for AI-agent project orientation, no malicious patterns. ai
source-diff obfuscated-file:dist/commands-RSHKXKXN.js AI (source-diff): Standard bundler output; sets up local Express/WS server with SQLite incident tracking, consistent with CLI tooling. ai
source-diff obfuscated-file:dist/dist-O7KGTIYK.js AI (source-diff): Standard bundler output; Zod schema definitions for project config parsing, no malicious patterns. ai
source-diff obfuscated-file:dist/ambient-2JZTNXUL.js AI (source-diff): Standard tsup/Vite minified CLI output; readable logic for journal entry management, no obfuscation indicators. ai
source-diff obfuscated-file:dist/beacon-QVUD3MGP.js AI (source-diff): Standard minified ESM CLI bundle; reads local project files only. ai
source-diff obfuscated-file:dist/ambient-WTLYUAQM.js AI (source-diff): Standard minified CLI bundle output from tsup; readable logic, no malicious patterns. ai
source-diff obfuscated-file:dist/ambient-GJAEXF7B.js AI (source-diff): Minified tsup CLI build output; readable logic, no malicious patterns. ai
source-diff large-new-source-files AI (source-diff): CLI ships bundled UI assets (lore-ui, graph-ui, platform-ui); large file count is expected. ai
source-diff obfuscated-file:dist/ambient-BKX77DDQ.js AI (source-diff): Standard tsup/Vite minified CLI output; content is domain-appropriate journal/agent logic, no malicious patterns. ai
source-diff obfuscated-file:dist/beacon-5QVYV5DF.js AI (source-diff): Minified CLI beacon generator reading local project files; no exfiltration. ai
phantom-deps phantom-dep:@modelcontextprotocol/sdk AI (phantom-deps): Same as above — bundled ESM, stable false positive. ai
phantom-deps phantom-dep:@a-company/registry-client AI (phantom-deps): Same-org internal dep bundled by tsup; stable false positive. ai
phantom-deps phantom-dep:@a-company/university-core AI (phantom-deps): Newly added same-org dep bundled by tsup; stable false positive. ai
phantom-deps phantom-dep:express AI (phantom-deps): Same as above — bundled ESM, stable false positive. ai
source-diff obfuscated-file:dist/agent-MB3H5EZA.js AI (source-diff): Standard tsup-bundled CLI output; readable logic, no exfiltration or remote code execution. ai
source-diff obfuscated-file:platform-ui/dist/assets/AmbientSection-xoxr3DQg.js AI (source-diff): Vite-minified UI bundle; readable React/fetch logic, no malicious patterns. ai
source-diff obfuscated-file:dist/auto-RHJXOZFL.js AI (source-diff): Standard tsup-bundled CLI output; file-system scanning logic only, no exfiltration. ai
source-diff obfuscated-file:dist/beacon-WVN264OT.js AI (source-diff): Standard tsup-bundled CLI output; generates markdown orientation docs, no malicious patterns. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Bundled ESM package; deps inlined by tsup, phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:ora AI (phantom-deps): Same as above — bundled ESM, stable false positive. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Same as above — bundled ESM, stable false positive. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Same as above — bundled ESM, stable false positive. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Same as above — bundled ESM, stable false positive. ai
phantom-deps phantom-dep:simple-git AI (phantom-deps): Same as above — bundled ESM, stable false positive. ai
source-diff obfuscated-file:lore-ui/dist/assets/index-BB3P4Cok.js AI (source-diff): Standard Vite/React production bundle; minification is expected for UI assets in this CLI package. ai
source-diff obfuscated-file:dist/university-ui/assets/index-CoBFthx2.js AI (source-diff): Standard Vite/React production bundle; minification is expected for UI assets in this CLI package. ai
source-diff obfuscated-file:platform-ui/dist/assets/CanvasSection-rKvA_vZj.js AI (source-diff): Vite-minified React UI component with local API fetch calls. ai
source-diff obfuscated-file:dist/beacon-YBLUUTYY.js AI (source-diff): Minified CLI entry point; standard fs/path/chalk usage. ai
source-diff obfuscated-file:dist/auto-A7VUHCUC.js AI (source-diff): Minified CLI entry point; reads local files with fs, no exfiltration. ai
source-diff obfuscated-file:platform-ui/dist/assets/AmbientSection-BYjt75R1.js AI (source-diff): Vite-minified React UI component; standard fetch to relative API paths. ai
source-diff obfuscated-file:dist/ambient-4NSPAQDJ.js AI (source-diff): Minified CLI entry point from tsup build; readable imports of fs/path/yaml, no obfuscation. ai
source-diff net-exec-file:platform-ui/dist/assets/CanvasSection-rKvA_vZj.js AI (source-diff): React UI component; fetch() hits own API, JSON.parse is data handling not code exec. ai
source-diff obfuscated-file:lore-ui/dist/assets/index-DcT8TINz.js AI (source-diff): Standard Vite/React production bundle; minification is expected for UI dist assets in this package. ai

Versions (showing 35 of 35)

Version Deps Published
7.5.0 18 / 8
7.3.0 17 / 8
5.38.0 16 / 8
5.37.11 15 / 8
5.37.8 15 / 8
5.37.7 15 / 8
5.37.6 15 / 8
5.37.4 15 / 8
5.37.3 15 / 8
5.37.2 15 / 8
5.37.1 15 / 8
5.37.0 15 / 8
5.35.1 14 / 6
5.34.0 14 / 6
5.3.3 14 / 6
3.43.0 14 / 6
3.13.0 14 / 6
3.12.0 11 / 6
3.11.0 11 / 6
3.9.0 10 / 6
3.8.0 10 / 6
3.7.0 10 / 6
3.6.0 10 / 6
3.5.0 10 / 6
3.1.6 10 / 6
3.1.5 10 / 6
3.1.4 10 / 6
3.1.2 10 / 6
3.1.0 10 / 6
3.0.3 10 / 6
3.0.2 10 / 6
3.0.1 10 / 6
3.0.0 10 / 6
2.0.13 9 / 6
1.5.0 9 / 6

v5.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.43.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.