@celilo/cli
Celilo — home lab orchestration CLI
5
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
peba2
Keywords
celilohomelaborchestrationansibleterraform
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): Diff tool flags test/source count; no scripts or deps changed vs prior approved version. | ai | |
| dependencies | unvetted-dep:@celilo/core | AI (dependencies): Internal workspace sibling package, not third-party. | ai | |
| dependencies | unvetted-dep:@celilo/capabilities | AI (dependencies): Internal workspace sibling package, not third-party. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Fires in a validator unit test accepting LAN IPs (192.168.x.x) for a Proxmox homelab URL — expected usage. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used to read a brand symbol on a hook object in tests; not evasion. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Used to pass process.env to subprocess (ansible-lint); standard pattern, not credential exfiltration. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @celilo/cli for a homelab CLI; edit-distance match to 'joi' is coincidental. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decoding backup data after decryption in backup-restore.ts; legitimate crypto/storage pattern. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Fires in a test asserting that /etc/passwd path traversal is rejected — the opposite of credential harvesting. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Decoding a master key from hex in encryption/integration test code; legitimate crypto usage. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 0.12.0 | 16 / 7 | |
| 0.11.0 | 15 / 7 | |
| 0.3.15 | 15 / 7 | |
| 0.3.13 | 15 / 7 | |
| 0.2.0 | 14 / 7 |
v0.12.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.15
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.