@decantr/cli
Decantr CLI — scaffold, audit, and maintain Decantr projects from the terminal
2
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
davidaimi
Keywords
decantrdecantr-aiai-codingai-frontend-governancecliproject-healthtyped-graphcontract-capsuledesign-governanceui-verificationdrift-detectionscaffoldingbrownfieldcursorclaude-codewindsurf
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to CI/CD-attested publishing, an improvement per provenance direction. | ai | |
| provenance | missing-githead | AI (provenance): Expected side-effect of switching to GitHub Actions CI publish with SLSA attestation. | ai | |
| provenance | no-provenance | AI (provenance): Package has never shipped Sigstore provenance; stable state, not a regression. | ai | |
| phantom-deps | phantom-dep:@decantr/content | AI (phantom-deps): Same-org monorepo package, likely re-exported not directly imported. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are same-org packages and ajv; not third-party supply-chain risk. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @decantr/* package for a distinct product; name similarity to 'joi' is coincidental, not impersonation. | ai |