@contrail/cli
VibeIQ's Contrail Platform CLI.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-removed | AI (maintainer-change): Team roster churn within same org (VibeIQ), not a takeover pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Same-org @contrail/loader dep, bundled, benign. | ai | |
| phantom-deps | phantom-dep:@contrail/loader | AI (phantom-deps): Same org scope, bundled dependency. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Publisher change confirmed as known maintainer manual publish, not takeover. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth matches bundledDependencies list in package.json. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundled dependencies (lodash, csv-parse, aws-sdk libs) account for size, not injected code. | ai | |
| source-diff | obfuscated-file:node_modules/validate-color/lib/index.js | AI (source-diff): Standard webpack bundle for validate-color color-validation library; no malicious indicators. | ai | |
| phantom-deps | phantom-dep:aws-sdk | AI (phantom-deps): aws-sdk is used via amazon-cognito-identity-js and config references; stable false positive for this CLI package. | ai | |
| dependencies | unvetted-dep:@contrail/loader | AI (dependencies): First-party @contrail-scoped dependency bundled with the package; stable across versions. | ai | |
| dependencies | unvetted-dep:json2csv | AI (dependencies): Standard CSV export library; consistent with CLI data-loading functionality across versions. | ai | |
| dependencies | unvetted-dep:pkg-install | AI (dependencies): Used for plugin/package installation in CLI context; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@contrail/org-config-migration | AI (dependencies): First-party @contrail-scoped dependency bundled with the package; stable across versions. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @contrail/cli is a scoped platform CLI with no relation to joi; Levenshtein match is coincidental. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): Dev/lint tooling referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:command-line-usage | AI (phantom-deps): command-line-usage referenced in config; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): execa referenced in config files; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:arg | AI (phantom-deps): arg referenced in config files; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:esm | AI (phantom-deps): esm is a loader referenced in config, not directly imported; stable false positive. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-autocomplete | AI (phantom-deps): oclif plugins are referenced in oclif config block, not direct imports; expected pattern. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): oclif plugins are referenced in oclif config block, not direct imports; expected pattern. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 3.5.2 | 31 / 17 | |
| 3.5.1 | 31 / 17 | |
| 3.5.0 | 31 / 17 | |
| 3.4.10 | 31 / 17 | |
| 3.4.9 | 31 / 17 | |
| 3.4.6 | 31 / 17 | |
| 3.4.5 | 31 / 17 | |
| 3.4.4 | 30 / 17 | |
| 3.4.0 | 29 / 17 | |
| 3.3.5 | 29 / 17 | |
| 3.3.4 | 29 / 17 | |
| 3.3.3 | 29 / 17 | |
| 3.3.2 | 29 / 17 | |
| 3.3.1 | 29 / 17 | |
| 3.3.0 | 29 / 17 | |
| 3.2.0 | 29 / 17 | |
| 3.1.8 | 29 / 17 | |
| 3.1.7 | 29 / 17 | |
| 3.1.6 | 29 / 17 | |
| 3.1.4 | 29 / 17 | |
| 3.1.3 | 29 / 17 | |
| 3.1.2 | 29 / 17 | |
| 3.1.1 | 29 / 17 | |
| 3.1.0 | 29 / 17 | |
| 3.0.6 | 30 / 17 | |
| 3.0.5 | 30 / 17 | |
| 3.0.4 | 30 / 17 | |
| 3.0.3 | 30 / 17 | |
| 3.0.2 | 30 / 17 | |
| 3.0.1 | 30 / 17 | |
| 3.0.0 | 30 / 17 |
v3.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zachsibert_vibeiq) than the most recent previously approved version (mattvitello) on 2026-04-15, but zachsibert_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.4.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zachsibert_vibeiq) than the most recent previously approved version (mattvitello) on 2026-03-23, but zachsibert_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.4.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zachsibert_vibeiq) than the most recent previously approved version (mattvitello) on 2026-03-23, but zachsibert_vibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.3.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adamvibeiq) than the most recent previously approved version (ashutoshvibeiq) on 2025-10-30, but adamvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.3.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ashutoshvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-10-28, but ashutoshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.3.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ashutoshvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-10-15, but ashutoshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.3.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (adamvibeiq) on 2025-10-03, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adamvibeiq) than the most recent previously approved version (kamalvibeiq) on 2025-09-20, but adamvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-06-25, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.1.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-06-25, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.1.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (prashantvibeiq) than the most recent previously approved version (kamalvibeiq) on 2025-06-24, but prashantvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (kamalvibeiq) than the most recent previously approved version (rakeshvibeiq) on 2025-06-16, but kamalvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.0.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (prashantvibeiq) than the most recent previously approved version (rakeshvibeiq) on 2025-06-09, but prashantvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.0.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rakeshvibeiq) than the most recent previously approved version (prashantvibeiq) on 2025-06-02, but rakeshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (rakeshvibeiq) than the most recent previously approved version (btosadoprater) on 2025-04-30, but rakeshvibeiq is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.0.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (btosadoprater) than the most recent previously approved version (kartikisahu) on 2025-03-24, but btosadoprater is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.