← Home

@circlesac/cgrok

🚀 An ngrok-like CLI that uses Cloudflare for secure tunneling

3
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

circlesac-devygpark80

Keywords

clitunnelcloudflarengrokproxy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:cloudflare AI (dependencies): cloudflare SDK is the core dependency for this Cloudflare tunneling CLI; expected and intentional. ai
phantom-deps phantom-dep:react AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:tldts AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:ink AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:ink-spinner AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:@tszen/trycatch AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:moment-timezone AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:ink-select-input AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai
phantom-deps phantom-dep:cloudflare AI (phantom-deps): Bundled CLI tool; deps compiled into dist/main.js, not directly imported in source. ai

Versions (showing 3 of 3)

Version Deps Published
26.5.0 10 / 9
26.2.1 10 / 9
26.2.0 10 / 9

v26.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v26.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v26.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.