← Home

@contrail/cli

VibeIQ's Contrail Platform CLI.

31
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

grant.hallbrian.lindauercfvibeiqbtosadopraterchris_vibeiqzileevamattvitellomazairajprashantvibeiqkartikisahuadamvibeiqzachsibert_vibeiqjaime-vibeiqmelba.lewisricardojsiscolrakeshvibeiqvadim-kozdanielurchuknwilde-vibeiqashutoshvibeiqraghuvibeiq

Keywords

clicontrail-cli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Team roster churn within same org (VibeIQ), not a takeover pattern. ai
publish-pattern new-deps-added AI (publish-pattern): Same-org @contrail/loader dep, bundled, benign. ai
phantom-deps phantom-dep:@contrail/loader AI (phantom-deps): Same org scope, bundled dependency. ai
maintainer-change maintainer-added AI (maintainer-change): Publisher change confirmed as known maintainer manual publish, not takeover. ai
source-diff source-size-tripled AI (source-diff): Growth matches bundledDependencies list in package.json. ai
source-diff large-new-source-files AI (source-diff): Bundled dependencies (lodash, csv-parse, aws-sdk libs) account for size, not injected code. ai
source-diff obfuscated-file:node_modules/validate-color/lib/index.js AI (source-diff): Standard webpack bundle for validate-color color-validation library; no malicious indicators. ai
phantom-deps phantom-dep:aws-sdk AI (phantom-deps): aws-sdk is used via amazon-cognito-identity-js and config references; stable false positive for this CLI package. ai
dependencies unvetted-dep:@contrail/loader AI (dependencies): First-party @contrail-scoped dependency bundled with the package; stable across versions. ai
dependencies unvetted-dep:json2csv AI (dependencies): Standard CSV export library; consistent with CLI data-loading functionality across versions. ai
dependencies unvetted-dep:pkg-install AI (dependencies): Used for plugin/package installation in CLI context; stable pattern across versions. ai
dependencies unvetted-dep:@contrail/org-config-migration AI (dependencies): First-party @contrail-scoped dependency bundled with the package; stable across versions. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @contrail/cli is a scoped platform CLI with no relation to joi; Levenshtein match is coincidental. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): Dev/lint tooling referenced in config; stable false positive. ai
phantom-deps phantom-dep:command-line-usage AI (phantom-deps): command-line-usage referenced in config; stable false positive for this CLI package. ai
phantom-deps phantom-dep:execa AI (phantom-deps): execa referenced in config files; stable false positive for this CLI package. ai
phantom-deps phantom-dep:arg AI (phantom-deps): arg referenced in config files; stable false positive for this CLI package. ai
phantom-deps phantom-dep:esm AI (phantom-deps): esm is a loader referenced in config, not directly imported; stable false positive. ai
phantom-deps phantom-dep:@oclif/plugin-autocomplete AI (phantom-deps): oclif plugins are referenced in oclif config block, not direct imports; expected pattern. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): oclif plugins are referenced in oclif config block, not direct imports; expected pattern. ai

Versions (showing 31 of 31)

Version Deps Published
3.5.2 31 / 17
3.5.1 31 / 17
3.5.0 31 / 17
3.4.10 31 / 17
3.4.9 31 / 17
3.4.6 31 / 17
3.4.5 31 / 17
3.4.4 30 / 17
3.4.0 29 / 17
3.3.5 29 / 17
3.3.4 29 / 17
3.3.3 29 / 17
3.3.2 29 / 17
3.3.1 29 / 17
3.3.0 29 / 17
3.2.0 29 / 17
3.1.8 29 / 17
3.1.7 29 / 17
3.1.6 29 / 17
3.1.4 29 / 17
3.1.3 29 / 17
3.1.2 29 / 17
3.1.1 29 / 17
3.1.0 29 / 17
3.0.6 30 / 17
3.0.5 30 / 17
3.0.4 30 / 17
3.0.3 30 / 17
3.0.2 30 / 17
3.0.1 30 / 17
3.0.0 30 / 17

v3.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mattvitello → zachsibert_vibeiq (on 2026-04-15, known maintainer) provenance

This version was published by a different npm account (zachsibert_vibeiq) than the most recent previously approved version (mattvitello) on 2026-04-15, but zachsibert_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.4.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mattvitello → zachsibert_vibeiq (on 2026-03-23, known maintainer) provenance

This version was published by a different npm account (zachsibert_vibeiq) than the most recent previously approved version (mattvitello) on 2026-03-23, but zachsibert_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.4.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: mattvitello → zachsibert_vibeiq (on 2026-03-23, known maintainer) provenance

This version was published by a different npm account (zachsibert_vibeiq) than the most recent previously approved version (mattvitello) on 2026-03-23, but zachsibert_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.3.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ashutoshvibeiq → adamvibeiq (on 2025-10-30, known maintainer) provenance

This version was published by a different npm account (adamvibeiq) than the most recent previously approved version (ashutoshvibeiq) on 2025-10-30, but adamvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.3.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: prashantvibeiq → ashutoshvibeiq (on 2025-10-28, known maintainer) provenance

This version was published by a different npm account (ashutoshvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-10-28, but ashutoshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.3.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: prashantvibeiq → ashutoshvibeiq (on 2025-10-15, known maintainer) provenance

This version was published by a different npm account (ashutoshvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-10-15, but ashutoshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.3.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: adamvibeiq → btosadoprater (on 2025-10-03, known maintainer) provenance

This version was published by a different npm account (btosadoprater) than the most recent previously approved version (adamvibeiq) on 2025-10-03, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.3.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kamalvibeiq → adamvibeiq (on 2025-09-20, known maintainer) provenance

This version was published by a different npm account (adamvibeiq) than the most recent previously approved version (kamalvibeiq) on 2025-09-20, but adamvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: prashantvibeiq → kamalvibeiq (on 2025-06-25, known maintainer) provenance

This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-06-25, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: prashantvibeiq → kamalvibeiq (on 2025-06-25, known maintainer) provenance

This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-06-25, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kamalvibeiq → prashantvibeiq (on 2025-06-24, known maintainer) provenance

This version was published by a different npm account (prashantvibeiq) than the most recent previously approved version (kamalvibeiq) on 2025-06-24, but prashantvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rakeshvibeiq → kamalvibeiq (on 2025-06-16, known maintainer) provenance

This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (rakeshvibeiq) on 2025-06-16, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.0.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: rakeshvibeiq → prashantvibeiq (on 2025-06-09, known maintainer) provenance

This version was published by a different npm account (prashantvibeiq) than the most recent previously approved version (rakeshvibeiq) on 2025-06-09, but prashantvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.0.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: prashantvibeiq → rakeshvibeiq (on 2025-06-02, known maintainer) provenance

This version was published by a different npm account (rakeshvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-06-02, but rakeshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: btosadoprater → rakeshvibeiq (on 2025-04-30, known maintainer) provenance

This version was published by a different npm account (rakeshvibeiq) than the most recent previously approved version (btosadoprater) on 2025-04-30, but rakeshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.0.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: kartikisahu → btosadoprater (on 2025-03-24, known maintainer) provenance

This version was published by a different npm account (btosadoprater) than the most recent previously approved version (kartikisahu) on 2025-03-24, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.