@alwaysmeticulous/cli
The Meticulous CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@alwaysmeticulous/session-filters | AI (dependencies): First-party monorepo dep: same org/maintainer/repo, version-locked to package version. | ai | |
| provenance | regressed-provenance | AI (provenance): Manual publish by known maintainer meticulous.eng (listed on prior approved versions); no malicious code corroborates compromise. | ai | |
| phantom-deps | phantom-dep:@alwaysmeticulous/session-filters | AI (phantom-deps): Same-org monorepo alignment dep not directly imported; benign. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): puppeteer-core is a well-known Google-maintained package; appropriate for a browser replay/automation CLI. | ai | |
| provenance | missing-githead | AI (provenance): Package has SLSA provenance attestation; missing gitHead is a minor metadata gap, not a supply chain risk for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Transition to GitHub Actions publishing makes individual maintainer accounts redundant; consistent with CI automation. | ai | |
| provenance | publisher-changed | AI (provenance): Package publishes via GitHub Actions CI with SLSA attestation; this is the documented automated release pattern. | ai | |
| dependencies | unvetted-dep:@alwaysmeticulous/replay-orchestrator-launcher | AI (dependencies): First-party monorepo dep from the same publisher; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@alwaysmeticulous/remote-replay-launcher | AI (dependencies): First-party monorepo dep from the same publisher; stable pattern across all versions. | ai | |
| dependencies | unvetted-dep:@alwaysmeticulous/client | AI (dependencies): First-party monorepo dep from the same publisher; stable pattern across all versions. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @alwaysmeticulous namespace; levenshtein match to 'joi' is a false positive for this established package. | ai |
Versions (showing 26 of 326)
| Version | Deps | Published |
|---|---|---|
| 2.146.1 | 20 / 2 | |
| 2.146.0 | 20 / 2 | |
| 2.145.0 | 20 / 2 | |
| 2.144.0 | 20 / 2 | |
| 2.143.0 | 20 / 2 | |
| 2.142.0 | 20 / 2 | |
| 2.141.2 | 20 / 2 | |
| 2.141.1 | 20 / 2 | |
| 2.141.0 | 20 / 2 | |
| 2.140.0 | 20 / 2 | |
| 2.139.0 | 20 / 2 | |
| 2.138.0 | 20 / 2 | |
| 2.137.0 | 20 / 2 | |
| 2.136.1 | 20 / 2 | |
| 2.136.0 | 20 / 2 | |
| 2.135.0 | 20 / 2 | |
| 2.134.0 | 20 / 2 | |
| 2.133.0 | 20 / 2 | |
| 2.132.0 | 20 / 2 | |
| 2.131.0 | 20 / 2 | |
| 2.130.1 | 20 / 2 | |
| 2.130.0 | 20 / 2 | |
| 2.129.1 | 20 / 2 | |
| 2.129.0 | 20 / 2 | |
| 2.128.0 | 20 / 2 | |
| 2.127.0 | 20 / 2 |
v2.146.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.146.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.145.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.144.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.143.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.142.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.141.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.141.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.141.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.140.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.139.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.138.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.137.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.136.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.136.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.135.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.134.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.133.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.132.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.131.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.130.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.130.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.129.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.129.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.128.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.127.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.