← Home

@copass/cli

Command-line interface for the [Olane Network](https://olane.dev) — interact with the Copass knowledge graph, ingest code and documentation, and query your project's ontology.

34
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

brendon_olane

Keywords

copasscliknowledge-graphsdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:ignore AI (phantom-deps): ignore referenced in config; stable false positive. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): chokidar used for file watching via config; stable false positive. ai
phantom-deps phantom-dep:@copass/management AI (phantom-deps): Same-org package; newly added runtime dep, phantom-dep is a false positive. ai
phantom-deps phantom-dep:open AI (phantom-deps): CLI tool; deps referenced in scripts/config rather than direct imports is normal. ai
phantom-deps phantom-dep:archy AI (phantom-deps): CLI utility dep; referenced in config/scripts pattern. ai
phantom-deps phantom-dep:figlet AI (phantom-deps): figlet is a runtime dep used for CLI banners; stable false positive. ai
phantom-deps phantom-dep:@types/figlet AI (phantom-deps): Type package; framework-scoped, stable false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @copass/cli is a scoped CLI package from Olane Inc., not a typosquat of joi. ai
phantom-deps phantom-dep:@supabase/supabase-js AI (phantom-deps): Listed as runtime dep; phantom-dep heuristic misfires for this package. ai
phantom-deps phantom-dep:validate-npm-package-name AI (phantom-deps): Config-referenced dep; stable false positive for this package. ai
phantom-deps phantom-dep:child_process AI (phantom-deps): child_process is a Node built-in wrapper; stable false positive. ai
phantom-deps phantom-dep:aegir AI (phantom-deps): aegir is a dev/test tool referenced in scripts; phantom-dep heuristic misfires here. ai
phantom-deps phantom-dep:debug AI (phantom-deps): debug is a transitive/config-referenced dep; stable false positive for this package. ai
phantom-deps phantom-dep:touch AI (phantom-deps): touch is a utility dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): dotenv is config-referenced; stable false positive for this package. ai

Versions (showing 34 of 34)

Version Deps Published
3.3.6 34 / 21
3.3.5 34 / 21
3.3.4 34 / 21
3.2.0 28 / 21
3.1.2 32 / 19
3.1.0 32 / 19
2.3.15 30 / 18
2.3.14 30 / 18
2.3.13 30 / 18
2.3.12 30 / 18
2.3.11 30 / 18
2.3.10 30 / 18
2.3.9 30 / 18
2.3.8 30 / 18
2.3.7 30 / 18
2.3.6 26 / 18
2.3.5 26 / 18
2.3.4 26 / 18
2.3.3 26 / 18
2.3.2 25 / 18
2.3.1 25 / 18
2.3.0 25 / 18
2.2.15 24 / 18
2.2.14 24 / 18
2.2.13 24 / 18
2.2.12 24 / 18
2.2.11 24 / 18
2.2.10 24 / 18
2.2.9 24 / 18
2.2.8 24 / 18
2.2.7 24 / 18
2.2.6 24 / 18
2.2.5 24 / 18
2.2.4 24 / 18

v3.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.