← Home

@decantr/cli

Decantr CLI — scaffold, audit, and maintain Decantr projects from the terminal

2
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

davidaimi

Keywords

decantrdecantr-aiai-codingai-frontend-governancecliproject-healthtyped-graphcontract-capsuledesign-governanceui-verificationdrift-detectionscaffoldingbrownfieldcursorclaude-codewindsurf

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to CI/CD-attested publishing, an improvement per provenance direction. ai
provenance missing-githead AI (provenance): Expected side-effect of switching to GitHub Actions CI publish with SLSA attestation. ai
provenance no-provenance AI (provenance): Package has never shipped Sigstore provenance; stable state, not a regression. ai
phantom-deps phantom-dep:@decantr/content AI (phantom-deps): Same-org monorepo package, likely re-exported not directly imported. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are same-org packages and ajv; not third-party supply-chain risk. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @decantr/* package for a distinct product; name similarity to 'joi' is coincidental, not impersonation. ai

Versions (showing 2 of 102)

Version Deps Published
1.1.0 2 / 0
1.0.0 2 / 0