@doist/todoist-cli
TypeScript CLI for Todoist
27
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
ricardoisthenningmujvalenteantondoistjefcurtisdmgaweldoistbotfbidugoncalossilvaomar.doist.comscottatdoisternestodoist
Keywords
todoistclitodotasks
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): @doist/todoist-sdk is a first-party Doist replacement for @doist/todoist-api-typescript; not a suspicious third-party dep. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Paired with maintainer-added; provenance attestation confirms no hostile takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): SLSA provenance attestation and CI/CD publish confirm legitimate org-internal maintainer change. | ai | |
| phantom-deps | phantom-dep:@napi-rs/keyring | AI (phantom-deps): Native keyring binding likely loaded conditionally at runtime; stable false positive for this CLI. | ai | |
| phantom-deps | phantom-dep:marked-terminal-renderer | AI (phantom-deps): Paired with marked for terminal rendering; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:oauth4webapi | AI (phantom-deps): Likely used indirectly via @doist/cli-core or dynamic import; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Rendering dependency likely loaded conditionally; stable false positive for this CLI package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance from official Doist org repo; expected pattern. | ai | |
| source-diff | obfuscated-file:dist/lib/skills/content.d.ts | AI (source-diff): Long line is a readable string constant (CLI help text), not obfuscated code. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): CLI tool using @pnpm/tabtab; postinstall runs bundled scripts/postinstall.js for tab-completion setup — stable pattern for this package. | ai |
Versions (showing 27 of 27)
| Version | Deps | Published |
|---|---|---|
| 1.75.1 | 11 / 11 | |
| 1.71.0 | 11 / 11 | |
| 1.60.3 | 10 / 11 | |
| 1.60.0 | 10 / 11 | |
| 1.59.0 | 10 / 11 | |
| 1.38.0 | 10 / 11 | |
| 1.30.0 | 10 / 11 | |
| 1.29.5 | 10 / 11 | |
| 1.20.0 | 9 / 7 | |
| 1.18.0 | 9 / 7 | |
| 1.16.0 | 9 / 7 | |
| 1.14.0 | 9 / 7 | |
| 1.13.0 | 9 / 7 | |
| 1.12.0 | 8 / 7 | |
| 1.11.0 | 8 / 7 | |
| 1.10.0 | 8 / 7 | |
| 1.9.0 | 8 / 7 | |
| 1.8.1 | 8 / 7 | |
| 1.8.0 | 8 / 7 | |
| 1.7.0 | 8 / 7 | |
| 1.6.1 | 8 / 7 | |
| 1.6.0 | 8 / 7 | |
| 1.5.0 | 7 / 7 | |
| 1.4.0 | 7 / 7 | |
| 1.3.0 | 7 / 7 | |
| 1.2.0 | 7 / 7 | |
| 1.1.2 | 7 / 7 |
v1.38.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.18.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.