@cleocode/nexus
CLEO project registry and code intelligence — unified nexus package
51
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
kryptobaseddev
Keywords
cleonexuscode-intelligencetree-sitterproject-registry
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:graphology-communities-louvain | AI (phantom-deps): Config-file-only reference; consistent with how tree-sitter and graphology plugins are declared but loaded dynamically. | ai | |
| phantom-deps | phantom-dep:tree-sitter-c | AI (phantom-deps): Tree-sitter language bindings are dynamically loaded; phantom-dep pattern is expected for this package type. | ai | |
| phantom-deps | phantom-dep:tree-sitter-go | AI (phantom-deps): Tree-sitter language bindings are dynamically loaded; phantom-dep pattern is expected for this package type. | ai | |
| phantom-deps | phantom-dep:tree-sitter-cpp | AI (phantom-deps): Tree-sitter language bindings are dynamically loaded; phantom-dep pattern is expected for this package type. | ai | |
| phantom-deps | phantom-dep:tree-sitter-java | AI (phantom-deps): Tree-sitter language bindings are dynamically loaded; phantom-dep pattern is expected for this package type. | ai | |
| phantom-deps | phantom-dep:tree-sitter-rust | AI (phantom-deps): Tree-sitter language bindings are dynamically loaded; phantom-dep pattern is expected for this package type. | ai | |
| phantom-deps | phantom-dep:tree-sitter-python | AI (phantom-deps): Tree-sitter language bindings are dynamically loaded; phantom-dep pattern is expected for this package type. | ai | |
| phantom-deps | phantom-dep:graphology-types | AI (phantom-deps): Type definitions for graphology; phantom-dep pattern is expected for TypeScript type packages. | ai | |
| phantom-deps | phantom-dep:tree-sitter-ruby | AI (phantom-deps): Tree-sitter language bindings are dynamically loaded; phantom-dep pattern is expected for this package type. | ai | |
| typosquat | typosquat.levenshtein:next | AI (typosquat): Package is scoped under @cleocode and is a code intelligence nexus/hub package — not an impersonation of Next.js. Edit distance of 2 is coincidental given the different namespace and purpose. | ai |
Versions (showing 51 of 236)
| Version | Deps | Published |
|---|---|---|
| 2026.7.2 | 16 / 3 | |
| 2026.7.1 | 16 / 3 | |
| 2026.6.19 | 16 / 3 | |
| 2026.6.18 | 16 / 3 | |
| 2026.6.17 | 16 / 3 | |
| 2026.6.15 | 16 / 3 | |
| 2026.6.14 | 16 / 3 | |
| 2026.6.13 | 16 / 3 | |
| 2026.6.12 | 16 / 3 | |
| 2026.6.11 | 16 / 3 | |
| 2026.6.10 | 16 / 3 | |
| 2026.6.9 | 16 / 3 | |
| 2026.6.8 | 16 / 3 | |
| 2026.6.7 | 16 / 3 | |
| 2026.6.6 | 16 / 3 | |
| 2026.6.5 | 16 / 3 | |
| 2026.6.4 | 16 / 3 | |
| 2026.6.3 | 16 / 3 | |
| 2026.6.2 | 16 / 3 | |
| 2026.6.1 | 16 / 3 | |
| 2026.6.0 | 16 / 3 | |
| 2026.5.134 | 16 / 3 | |
| 2026.5.133 | 16 / 3 | |
| 2026.5.132 | 16 / 3 | |
| 2026.5.131 | 16 / 3 | |
| 2026.5.130 | 16 / 3 | |
| 2026.5.129 | 16 / 3 | |
| 2026.5.128 | 16 / 3 | |
| 2026.5.127 | 16 / 3 | |
| 2026.5.126 | 16 / 3 | |
| 2026.5.125 | 16 / 3 | |
| 2026.5.124 | 16 / 3 | |
| 2026.5.123 | 16 / 3 | |
| 2026.5.122 | 16 / 3 | |
| 2026.5.121 | 16 / 3 | |
| 2026.5.120 | 16 / 3 | |
| 2026.5.114 | 16 / 3 | |
| 2026.5.113 | 16 / 3 | |
| 2026.5.112 | 16 / 3 | |
| 2026.5.111 | 16 / 3 | |
| 2026.5.110 | 16 / 3 | |
| 2026.5.109 | 16 / 3 | |
| 2026.5.108 | 16 / 3 | |
| 2026.5.107 | 16 / 3 | |
| 2026.5.106 | 16 / 3 | |
| 2026.5.105 | 16 / 3 | |
| 2026.5.104 | 16 / 3 | |
| 2026.5.103 | 16 / 3 | |
| 2026.5.102 | 16 / 3 | |
| 2026.5.101 | 16 / 3 | |
| 2026.5.100 | 16 / 3 |
v2026.7.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.7.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2026.6.19
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.