← Home

@adobe/aem-cli

AEM CLI

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

marbectripodgarthdblazdadobe-adminpatrickfultontrieloffkrisnyedcpfsdknatebaldwindevongovettaspro83symanovidpfisterstefan-guggisbergrofekptdobeadobehallsfullcolorcoderdjaeggidylandepassmhaackamol-anandstopp-adobenamaroradotenduh_schmidtasthabh23zdahbituicufmeschbe

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@adobe/helix-html2md AI (dependencies): First-party Adobe/helix package from same monorepo org. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are trusted first-party @adobe/helix-* packages. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): CLI tool; deps referenced in config files rather than direct imports is normal for this package. ai
phantom-deps phantom-dep:shelljs AI (phantom-deps): CLI tool; deps referenced in config files rather than direct imports is normal for this package. ai
semgrep semgrep:env-bulk-read AI (semgrep): CLI config loader filtering process.env for HLX_ prefixed vars; expected pattern for this package. ai
phantom-deps phantom-dep:proxy-agent AI (phantom-deps): CLI tool; deps referenced in config files rather than direct imports is normal for this package. ai
phantom-deps phantom-dep:progress AI (phantom-deps): CLI tool; deps referenced in config files rather than direct imports is normal for this package. ai
phantom-deps phantom-dep:glob AI (phantom-deps): CLI tool; deps referenced in config files rather than direct imports is normal for this package. ai

Versions (showing 51 of 227)

View all versions
Version Deps Published
16.21.0 44 / 16
16.20.13 43 / 16
16.20.12 43 / 16
16.20.11 43 / 16
16.20.10 43 / 16
16.20.9 42 / 16
16.20.8 42 / 16
16.20.7 42 / 16
16.20.6 42 / 16
16.20.5 42 / 16
16.20.4 42 / 16
16.20.3 42 / 16
16.20.2 42 / 16
16.20.1 42 / 16
16.20.0 42 / 16
16.19.14 42 / 16
16.19.13 42 / 16
16.19.12 42 / 16
16.19.11 42 / 16
16.19.10 42 / 16
16.19.9 42 / 16
16.19.8 42 / 16
16.19.7 42 / 16
16.19.6 42 / 16
16.19.5 42 / 16
16.19.4 42 / 16
16.19.3 42 / 16
16.19.2 42 / 16
16.19.1 42 / 16
16.18.7 42 / 16
16.18.6 42 / 16
16.18.3 42 / 16
16.18.2 42 / 16
16.18.1 42 / 16
16.18.0 42 / 16
16.17.1 37 / 16
16.17.0 37 / 16
16.16.33 37 / 16
16.16.32 37 / 16
16.16.31 37 / 16
16.16.30 37 / 16
16.16.29 37 / 16
16.16.28 37 / 16
16.16.27 37 / 16
16.16.26 37 / 16
16.16.25 37 / 16
16.16.24 37 / 16
16.16.23 37 / 16
16.16.22 37 / 16
16.16.21 37 / 16
16.16.20 37 / 16

v16.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v16.20.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.