@doist/outline-cli
CLI for the Outline wiki/knowledge base API
11
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
ricardoisthenningmujvalenteantondoistjefcurtisdmgaweldoistbotfbidugoncalossilvaomar.doist.comscottatdoisternestodoist
Keywords
outlinewikicli
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Doist org package with SLSA provenance; CI-published, maintainer change consistent with legitimate team rotation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same rationale — org-level handoff, not a suspicious takeover signal given provenance attestation. | ai | |
| phantom-deps | phantom-dep:marked-terminal-renderer | AI (phantom-deps): Renderer likely passed as config/plugin to marked rather than directly imported; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:oauth4webapi | AI (phantom-deps): oauth4webapi likely consumed via @doist/cli-core OAuth abstraction; indirect import pattern. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): marked is used indirectly via marked-terminal-renderer; phantom-dep heuristic fires on indirect usage patterns. | ai | |
| provenance | publisher-changed | AI (provenance): Doist org moved to GitHub Actions CI publishing; SLSA provenance attestation confirms legitimate automated release. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Doist org CLI with SLSA provenance; postinstall runs a local JS script, consistent with legitimate CLI setup. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 1.10.3 | 8 / 10 | |
| 1.10.0 | 8 / 10 | |
| 1.9.0 | 8 / 10 | |
| 1.5.2 | 7 / 10 | |
| 1.5.1 | 7 / 10 | |
| 1.5.0 | 7 / 10 | |
| 1.3.0 | 7 / 10 | |
| 1.0.2 | 7 / 13 | |
| 1.0.1 | 6 / 13 | |
| 1.0.0 | 6 / 12 | |
| 0.0.1 | 0 / 0 |
v1.10.3
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.