← Home

@contractspec/app.cli-contractspec

CLI tool for creating, building, and validating contract specifications

4
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

farzim

Keywords

clicontractscode-generationaitypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@contractspec/lib.schema AI (phantom-deps): Same-org dep bundled at build time. ai
phantom-deps phantom-dep:@contractspec/lib.harness AI (phantom-deps): Same-org dep bundled at build time. ai
phantom-deps phantom-dep:@contractspec/lib.plugins AI (phantom-deps): Same-org dep bundled at build time. ai
phantom-deps phantom-dep:@contractspec/lib.testing AI (phantom-deps): Same-org dep bundled at build time. ai
phantom-deps phantom-dep:@contractspec/lib.ai-agent AI (phantom-deps): Same-org dep bundled at build time. ai
phantom-deps phantom-dep:@contractspec/module.ai-chat AI (phantom-deps): Same-org dep bundled at build time. ai
phantom-deps phantom-dep:@contractspec/module.examples AI (phantom-deps): Same-org dep bundled at build time. ai
phantom-deps phantom-dep:ai AI (phantom-deps): Bundled CLI app; deps consumed at build time via bun build. ai
phantom-deps phantom-dep:pg AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:ora AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:@ai-sdk/mistral AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:@ai-sdk/anthropic AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:@inquirer/prompts AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai
phantom-deps phantom-dep:ollama-ai-provider AI (phantom-deps): Bundled CLI app; deps consumed at build time. ai

Versions (showing 4 of 4)

Version Deps Published
6.3.1 31 / 8
6.1.1 28 / 7
6.1.0 28 / 7
5.0.0 29 / 6

v6.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.