← Home

@canonical/pragma-cli

CLI and MCP server for Canonical's design system.

7
Versions
GPL-3.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

ilayda21frankbanhuwshimianthonydillonsteverydzamylily1011bartazjpmartinsptpetesfrenchjmuzinamtrujedlerdabehniacanonical-organizationedisile-canonicalsteciuk-canonicalad.vlengr-aliando.gqninfa_jeonndv99goulin-canonicalimmortalcodesalvaromateoonibenjo-canonical

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:oxigraph AI (phantom-deps): Used via config/CLI reference, not direct import; heuristic FP. ai
source-diff obfuscated-file:src/capabilities/create/templates.embedded.generated.ts AI (source-diff): Auto-generated template inliner with source comment explaining purpose; not true obfuscation. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of individual maintainer in favor of CI/CD publishing is expected for org-managed packages. ai
phantom-deps phantom-dep:@canonical/anatomy-dsl AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for transitive/indirect usage patterns. ai
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD is a provenance improvement, not a takeover signal. ai
phantom-deps phantom-dep:@canonical/design-system AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for transitive/indirect usage patterns. ai
phantom-deps phantom-dep:@canonical/code-standards AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for transitive/indirect usage patterns. ai
semgrep semgrep:silent-process-exec-var AI (semgrep): Same test-file context as silent-process-exec; not a runtime concern. ai
semgrep semgrep:silent-process-exec AI (semgrep): Fires only in test files; spawning a local completions server for integration testing, not malicious. ai
semgrep semgrep:env-spread AI (semgrep): Pattern is in test setup/teardown to save and restore process.env; standard testing practice. ai

Versions (showing 7 of 7)

Version Deps Published
0.32.0 14 / 9
0.31.0 20 / 10
0.30.0 18 / 10
0.29.0 18 / 10
0.27.0 14 / 10
0.20.0 11 / 9
0.18.0 11 / 9

v0.32.0

2 findings
HIGH New obfuscated file: src/capabilities/create/templates.embedded.generated.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.31.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.30.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.29.0

2 findings
HIGH Publisher changed: mariadias143 → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.