← Home

@contentstack/cli-migration

27
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mynkcloudaccounts

Keywords

oclif-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:dot-object AI (phantom-deps): Used via config, not a red flag. ai
maintainer-change maintainer-added AI (maintainer-change): Org-managed CLI package; roster changes are routine maintainer rotation. ai
maintainer-change maintainer-removed AI (maintainer-change): Consolidation of maintainer list for official contentstack org package. ai
publish-pattern new-deps-added AI (publish-pattern): concat-stream is a benign, widely-used stream utility. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Used via config, not a red flag. ai
semgrep semgrep:child-process-import AI (semgrep): Expected in a CLI tool; no evidence of malicious use. ai
phantom-deps phantom-dep:@oclif/core AI (phantom-deps): @oclif/core is a declared runtime dep used via oclif plugin framework config, not direct import. ai
phantom-deps phantom-dep:concat-stream AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): Intentional: loads user-provided migration scripts at runtime; core feature of this CLI migration tool. ai

Versions (showing 27 of 27)

Version Deps Published
1.12.4 10 / 15
1.12.3 10 / 15
1.12.2 10 / 15
1.12.1 11 / 15
1.12.0 11 / 15
1.11.0 11 / 15
1.10.3 11 / 8
1.10.2 11 / 8
1.10.1 11 / 8
1.10.0 11 / 8
1.9.0 11 / 8
1.8.2 11 / 8
1.8.1 11 / 8
1.8.0 11 / 8
1.7.3 9 / 8
1.7.2 9 / 8
1.7.1 9 / 8
1.7.0 9 / 7
1.6.6 9 / 7
1.6.5 9 / 7
1.6.4 11 / 11
1.6.3 10 / 11
1.6.2 10 / 11
1.6.1 10 / 11
1.6.0 10 / 11
1.5.6 10 / 11
1.5.5 10 / 11

v1.12.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.