← Home

@doist/outline-cli

CLI for the Outline wiki/knowledge base API

11
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

ricardoisthenningmujvalenteantondoistjefcurtisdmgaweldoistbotfbidugoncalossilvaomar.doist.comscottatdoisternestodoist

Keywords

outlinewikicli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Doist org package with SLSA provenance; CI-published, maintainer change consistent with legitimate team rotation. ai
maintainer-change maintainer-removed AI (maintainer-change): Same rationale — org-level handoff, not a suspicious takeover signal given provenance attestation. ai
phantom-deps phantom-dep:marked-terminal-renderer AI (phantom-deps): Renderer likely passed as config/plugin to marked rather than directly imported; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:oauth4webapi AI (phantom-deps): oauth4webapi likely consumed via @doist/cli-core OAuth abstraction; indirect import pattern. ai
phantom-deps phantom-dep:marked AI (phantom-deps): marked is used indirectly via marked-terminal-renderer; phantom-dep heuristic fires on indirect usage patterns. ai
provenance publisher-changed AI (provenance): Doist org moved to GitHub Actions CI publishing; SLSA provenance attestation confirms legitimate automated release. ai
install-scripts install-script:postinstall AI (install-scripts): Doist org CLI with SLSA provenance; postinstall runs a local JS script, consistent with legitimate CLI setup. ai

Versions (showing 11 of 11)

Version Deps Published
1.10.3 8 / 10
1.10.0 8 / 10
1.9.0 8 / 10
1.5.2 7 / 10
1.5.1 7 / 10
1.5.0 7 / 10
1.3.0 7 / 10
1.0.2 7 / 13
1.0.1 6 / 13
1.0.0 6 / 12
0.0.1 0 / 0

v1.10.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.