@akanjs/cli
The official command-line interface for the Akan.js ecosystem, providing powerful development tools for creating, managing, and deploying modern web applications with ease.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-bulk-read | AI (semgrep): Used to forward env to child build processes; standard CLI/build-tool pattern for this package. | ai | |
| semgrep | semgrep:silent-process-exec | AI (semgrep): Fires on openBrowser() which uses detached spawn to open a URL in the OS browser — standard pattern, not malicious. | ai | |
| semgrep | semgrep:silent-process-exec-var | AI (semgrep): Same openBrowser() call site; variable-command variant of the same benign pattern. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): IP is 127.0.0.1:4873 — local Verdaccio registry default, not an external exfiltration endpoint. | ai | |
| phantom-deps | phantom-dep:daisyui | AI (phantom-deps): Tailwind plugin; referenced in config files rather than imported directly — expected usage pattern. | ai | |
| phantom-deps | phantom-dep:tailwind-scrollbar | AI (phantom-deps): Tailwind plugin; config-file reference only, not a direct import — expected usage pattern. | ai | |
| dependencies | unvetted-dep:next-pwa | AI (dependencies): next-pwa 5.6.0 is a well-known PWA plugin pinned at a specific version; acceptable for a CLI build tool context. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI tool executing system commands via child_process is core functionality, not malicious. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @akanjs/cli is not a plausible typosquat of joi; different namespace and purpose. | ai | |
| phantom-deps | phantom-dep:lodash | AI (phantom-deps): lodash is declared in package.json dependencies; phantom-dep heuristic is a false positive here. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): CLI devkit tool spreading process.env for build environment configuration is expected behavior. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 2.3.10 | 24 / 0 | |
| 2.2.6 | 24 / 0 | |
| 2.2.0 | 24 / 0 | |
| 2.1.0 | 22 / 0 | |
| 1.0.21 | 40 / 0 | |
| 1.0.20 | 40 / 0 | |
| 1.0.19 | 40 / 0 | |
| 1.0.18 | 40 / 0 | |
| 1.0.17 | 40 / 0 | |
| 1.0.16 | 40 / 0 | |
| 1.0.15 | 40 / 0 | |
| 1.0.14 | 40 / 0 | |
| 1.0.13 | 40 / 0 | |
| 1.0.12 | 40 / 0 | |
| 1.0.11 | 40 / 0 | |
| 1.0.10 | 40 / 0 | |
| 1.0.9 | 40 / 0 | |
| 1.0.8 | 40 / 0 | |
| 1.0.7 | 40 / 0 | |
| 1.0.6 | 40 / 0 | |
| 1.0.5 | 40 / 0 | |
| 1.0.4 | 40 / 0 | |
| 1.0.3 | 40 / 0 | |
| 1.0.2 | 40 / 0 | |
| 1.0.1 | 40 / 0 | |
| 1.0.0 | 40 / 0 | |
| 0.9.59 | 39 / 0 | |
| 0.9.58 | 39 / 0 | |
| 0.9.57 | 39 / 0 | |
| 0.9.56 | 39 / 0 | |
| 0.9.55 | 39 / 0 |
v2.3.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.