@cerefox/codefactory
Cerefox Code Factory (cf²) -- deterministic orchestration harness for AI coding agents
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/cfcf.js | AI (source-diff): Encoded strings are base64 help/documentation content stored in HELP_TOPICS.contentBase64 fields, not obfuscated payloads. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall installs shell completions via the package's own CLI binary; no network fetch or arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:hono | AI (phantom-deps): hono is a declared runtime dependency; phantom-dep heuristic is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander is a declared runtime dependency; phantom-dep heuristic is a false positive for this package. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.24.5 | 3 / 0 | |
| 0.24.1 | 3 / 0 | |
| 0.23.1 | 3 / 0 | |
| 0.23.0 | 3 / 0 | |
| 0.19.0 | 3 / 0 | |
| 0.16.4 | 3 / 0 | |
| 0.16.2 | 3 / 0 |
v0.24.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.1
2 findingsModified file contains 12 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.0
2 findingsModified file contains 12 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.19.0
2 findingsScript: bun ./bin/cfcf.js completion install || true
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.4
2 findingsScript: bun ./bin/cfcf.js completion install || true
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.16.2
2 findingsScript: bun ./bin/cfcf.js completion install || true
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.