@aiready/cli
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:preinstall | AI (install-scripts): Only creates placeholder dist dir/file, no code execution or network activity. | ai | |
| dependencies | unvetted-dep:@aiready/agent-grounding | AI (dependencies): Same-org monorepo dependency, not third-party unvetted. | ai | |
| dependencies | unvetted-dep:@aiready/clawmart | AI (dependencies): Same-publisher first-party sibling package in the @aiready monorepo family. | ai | |
| source-diff | obfuscated-file:coverage/prettify.js | AI (source-diff): Known third-party prettify.js bundled with istanbul coverage reports, not attacker code. | ai | |
| phantom-deps | phantom-dep:@aiready/ai-signal-clarity | AI (phantom-deps): Same-org scoped dep; likely consumed transitively within the @aiready monorepo. | ai | |
| phantom-deps | phantom-dep:@aiready/deps | AI (phantom-deps): Same-org scoped dep; likely consumed transitively within the @aiready monorepo. | ai | |
| phantom-deps | phantom-dep:@aiready/doc-drift | AI (phantom-deps): Same-org scoped dep; likely consumed transitively within the @aiready monorepo. | ai | |
| phantom-deps | phantom-dep:@aiready/agent-grounding | AI (phantom-deps): Same-org scoped dep; likely consumed transitively within the @aiready monorepo. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env into spawn options is standard CLI practice; not a secret-exfiltration risk here. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @aiready namespace; edit-distance match to 'joi' is coincidental, not impersonation. | ai |
Versions (showing 51 of 159)
| Version | Deps | Published |
|---|---|---|
| 0.15.39 | 14 / 2 | |
| 0.15.37 | 14 / 2 | |
| 0.15.32 | 14 / 2 | |
| 0.15.31 | 14 / 2 | |
| 0.15.30 | 14 / 2 | |
| 0.15.29 | 14 / 2 | |
| 0.15.28 | 14 / 2 | |
| 0.15.27 | 14 / 2 | |
| 0.15.26 | 14 / 2 | |
| 0.15.25 | 14 / 2 | |
| 0.15.24 | 14 / 2 | |
| 0.15.22 | 14 / 2 | |
| 0.15.21 | 14 / 2 | |
| 0.15.20 | 14 / 2 | |
| 0.15.19 | 14 / 2 | |
| 0.15.18 | 14 / 2 | |
| 0.15.17 | 14 / 2 | |
| 0.15.16 | 14 / 2 | |
| 0.15.14 | 14 / 2 | |
| 0.15.11 | 14 / 2 | |
| 0.15.10 | 14 / 2 | |
| 0.15.9 | 14 / 2 | |
| 0.15.8 | 14 / 2 | |
| 0.15.7 | 14 / 2 | |
| 0.15.6 | 14 / 2 | |
| 0.15.5 | 14 / 2 | |
| 0.15.4 | 14 / 2 | |
| 0.15.3 | 14 / 2 | |
| 0.15.2 | 14 / 2 | |
| 0.15.1 | 14 / 2 | |
| 0.15.0 | 14 / 2 | |
| 0.14.25 | 13 / 2 | |
| 0.14.24 | 13 / 2 | |
| 0.14.23 | 13 / 2 | |
| 0.14.22 | 13 / 2 | |
| 0.14.21 | 13 / 2 | |
| 0.14.17 | 13 / 2 | |
| 0.14.16 | 13 / 2 | |
| 0.14.15 | 13 / 2 | |
| 0.14.14 | 13 / 2 | |
| 0.14.13 | 13 / 2 | |
| 0.14.12 | 13 / 2 | |
| 0.14.11 | 13 / 2 | |
| 0.14.10 | 13 / 2 | |
| 0.14.9 | 13 / 2 | |
| 0.14.8 | 13 / 2 | |
| 0.14.7 | 13 / 2 | |
| 0.14.6 | 13 / 2 | |
| 0.14.5 | 13 / 2 | |
| 0.14.4 | 13 / 2 | |
| 0.14.3 | 13 / 2 |
v0.14.14
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.13
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.12
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.11
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.10
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.9
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.8
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.