← Home

@codefast/cli

Developer CLI for the Codefast monorepo (arrange, mirror, tag)

11
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

thevuong

Keywords

clicodefastmonorepotailwindtailwindcsstypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps (zod, jiti, @codefast/di) are established packages consistent with CLI feature expansion. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package in a legitimate monorepo; name similarity to joi is coincidental. ai
dependencies unvetted-dep:@codefast/di AI (dependencies): Sibling package from the same codefastlabs monorepo; not an external unvetted dependency. ai

Versions (showing 11 of 11)

Version Deps Published
0.4.0 6 / 8
0.3.15 7 / 9
0.3.14 7 / 9
0.3.13 7 / 9
0.3.12 4 / 8
0.3.5 8 / 9
0.3.4 8 / 9
0.3.3 8 / 9
0.3.2 8 / 9
0.3.1 8 / 9
0.3.0 6 / 9

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.