← Home

@a1st/aix

CLI for aix - unified AI agent configuration

10
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mluedke

Keywords

agentsaiai-configclaudeclaude-codeclicodexcopilotcursormcpskillswindsurfzed

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@yeskunall/astro-umami AI (phantom-deps): Astro integration referenced in config, not imported directly. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Config-referenced dep in Astro/oclif toolchain; not a direct import by design. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Config-referenced dep; consistent with CLI config parsing pattern. ai
phantom-deps phantom-dep:astro AI (phantom-deps): Astro framework dep referenced in config files, not direct imports. ai
phantom-deps phantom-dep:giget AI (phantom-deps): Config-referenced dep for template scaffolding; stable pattern. ai
phantom-deps phantom-dep:@astrojs/vercel AI (phantom-deps): Astro adapter referenced in config, not imported directly. ai
phantom-deps phantom-dep:@astrojs/starlight AI (phantom-deps): Astro docs theme referenced in config, not imported directly. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped package @a1st/aix is an AI CLI tool; Levenshtein match to ajv is coincidental, not a typosquat. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): oclif plugins are loaded via oclif.plugins config, not direct imports; stable pattern for this package. ai
phantom-deps phantom-dep:@oclif/plugin-update AI (phantom-deps): Same oclif plugin pattern; not directly imported by design. ai
phantom-deps phantom-dep:@oclif/plugin-version AI (phantom-deps): Same oclif plugin pattern; not directly imported by design. ai
phantom-deps phantom-dep:@oclif/plugin-not-found AI (phantom-deps): Same oclif plugin pattern; not directly imported by design. ai
phantom-deps phantom-dep:@oclif/plugin-autocomplete AI (phantom-deps): Same oclif plugin pattern; not directly imported by design. ai
phantom-deps phantom-dep:ink-spinner AI (phantom-deps): ink-spinner is a React/Ink component; may be used indirectly or via dynamic rendering; stable false positive. ai

Versions (showing 10 of 10)

Version Deps Published
0.5.0 24 / 7
0.4.1 24 / 7
0.3.1 24 / 7
0.3.0 24 / 7
0.2.0 24 / 7
0.1.0 17 / 7
0.0.12 17 / 7
0.0.6 17 / 7
0.0.4 17 / 7
0.0.3 17 / 7

v0.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.