← Home

@eclipse-glsp/cli

CLI Tooling & scripts for GLSP components

2
Versions
(EPL-2.0 OR GPL-2.0 WITH Classpath-exception-2.0)
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

tortmayrplangereclipse-glsp-botmfleckjfaltermeierndoscheklkoehler

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped Eclipse Foundation CLI package; Levenshtein match to 'joi' is coincidental and not a typosquat. ai

Versions (showing 2 of 2)

Version Deps Published
2.6.0 0 / 10
2.5.0 8 / 6

v2.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.