@assetpipe/cli
14
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
koteelok
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @assetpipe/cli has no semantic or functional resemblance to joi; Levenshtein match is a false positive. | ai | |
| phantom-deps | phantom-dep:@assetpipe/core | AI (phantom-deps): Same-org sibling dependency; phantom-dep heuristic unreliable for monorepo workspace packages. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): CLI tool; commander is a declared dep likely used via the bin entry point, not a direct import in analyzed files. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is a runtime loader commonly invoked via config files rather than direct import; stable false positive for this package. | ai |