← Home

@dxos/cli

DXOS CLI

2
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

mykola-vrmchkdxos-botgcolottisebikap-gm2richburdonegorgripasovmarik_drzad-pyivladmeschzarconontolwittjosiah

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:joi AI (typosquat): @dxos/cli is a scoped DXOS CLI tool; Levenshtein proximity to 'joi' is purely incidental. ai
phantom-deps phantom-dep:ws AI (phantom-deps): ws is a declared dep used transitively in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:pkg-up AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:platform AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/debug AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@dxos/compute AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@dxos/process AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@octokit/core AI (phantom-deps): Declared dep in DXOS monorepo; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:extensionless AI (phantom-deps): Used in manifest script; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/node-std AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@dxos/cli-composer AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/observability AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@oclif/plugin-update AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@dxos/network-manager AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic false positive for monorepo packages. ai
phantom-deps phantom-dep:@oclif/plugin-plugins AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@oclif/plugin-autocomplete AI (phantom-deps): Declared oclif plugin dep; phantom-dep heuristic false positive. ai

Versions (showing 2 of 2)

Version Deps Published
0.8.3 53 / 11
0.8.2 52 / 11

v0.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.