← Home

@dxos/cli

DXOS CLI

4
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mykola-vrmchkdxos-botgcolottisebikap-gm2richburdonegorgripasovmarik_drzad-pyivladmeschzarconontolwittjosiah

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Intentional migration from dxos-bot to GitHub Actions CI/CD; SLSA attestation confirms legitimate pipeline. ai
source-diff source-size-dropped AI (source-diff): Package refactored to thin platform-dispatch shim; size drop is architectural, not malicious. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used to exec platform-specific binary — core design of the shim, not arbitrary code execution. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with CI/CD pipeline takeover of publishing; SLSA attestation supports legitimacy. ai
phantom-deps phantom-dep:platform AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/debug AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@dxos/compute AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@dxos/process AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@octokit/core AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:extensionless AI (phantom-deps): Used in manifest script; phantom-dep heuristic false positive. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @dxos/cli is a scoped DXOS CLI tool; Levenshtein proximity to 'joi' is purely incidental. ai
phantom-deps phantom-dep:@dxos/cli-composer AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/observability AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@oclif/plugin-update AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/network-manager AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@oclif/plugin-plugins AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@oclif/plugin-autocomplete AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/node-std AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:ws AI (phantom-deps): ws is a declared dep used transitively in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:pkg-up AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai

Versions (showing 4 of 4)

Version Deps Published
0.10.0 0 / 0
0.9.0 0 / 0
0.8.3 53 / 11
0.8.2 52 / 11

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.