@brna/cli
brna CLI — agent-friendly snapshot and action surface for React Native apps
22
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
leolin310148
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Move to GitHub Actions CI with SLSA attestation; provenance improvement. | ai | |
| dependencies | unvetted-dep:@brna/local-usage | AI (dependencies): First-party sibling package in same monorepo/scope, version-locked to this release. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Added dep is an internal @brna scoped package, not a third-party supply-chain risk. | ai | |
| source-diff | net-exec-file:dist/brna.js | AI (source-diff): Bun-bundled CLI entry point; network+exec from bundled dependencies is expected. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase from adding bun-built bundle; expected for CLI packages. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Config env-replacement helper in CLI; not exfiltration. | ai | |
| semgrep | semgrep:silent-process-exec | AI (semgrep): Daemon self-respawn pattern using process.execPath; standard CLI daemon lifecycle. | ai | |
| semgrep | semgrep:silent-process-exec-var | AI (semgrep): Same daemon spawn as silent-process-exec; not malicious. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Fires exclusively in test files spreading process.env for test harness setup — not a runtime secret leak. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): No brand similarity between @brna/cli and joi; weak Levenshtein match only. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All instances reference 127.0.0.1 in integration test setup — localhost loopback, not exfiltration. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 0.1.20 | 4 / 0 | |
| 0.1.18 | 3 / 0 | |
| 0.1.17 | 3 / 0 | |
| 0.1.16 | 3 / 0 | |
| 0.1.14 | 3 / 0 | |
| 0.1.13 | 3 / 0 | |
| 0.1.12 | 3 / 0 | |
| 0.1.11 | 3 / 0 | |
| 0.1.10 | 3 / 0 | |
| 0.1.9 | 3 / 0 | |
| 0.1.8 | 3 / 0 | |
| 0.1.7 | 3 / 0 | |
| 0.1.6 | 3 / 0 | |
| 0.1.5 | 3 / 0 | |
| 0.1.4 | 3 / 0 | |
| 0.1.3 | 3 / 0 | |
| 0.1.2 | 3 / 0 | |
| 0.1.1 | 3 / 0 | |
| 0.1.0 | 3 / 0 | |
| 0.0.10 | 3 / 0 | |
| 0.0.3 | 3 / 0 | |
| 0.0.2 | 3 / 0 |
v0.1.20
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.18
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.17
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.