← Home

@eclipse-scout/cli

CLI for Eclipse Scout

12
Versions
EPL-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

andre.wegmuellerclaudio.guglielmodaniel.schmidmvilligereclipsescoutaeg

Keywords

scouteclipse-scoutclicommand lineconsoleargscommand

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@metahub/karma-jasmine-jquery AI (dependencies): Karma/Jasmine integration plugin; expected test tooling. ai
dependencies unvetted-dep:@cyclonedx/webpack-plugin AI (dependencies): SBOM generation plugin; legitimate build tooling for this CLI. ai
dependencies unvetted-dep:jasmine-jquery AI (dependencies): Standard test dependency for Eclipse Scout CLI; stable pattern across versions. ai
dependencies unvetted-dep:karma-jasmine-ajax AI (dependencies): Standard Karma test plugin; expected for this CLI package. ai
dependencies unvetted-dep:karma-junit-reporter AI (dependencies): Standard Karma reporter; expected for this CLI package. ai
dependencies unvetted-dep:fork-ts-checker-notifier-webpack-plugin AI (dependencies): TypeScript webpack plugin; standard build tooling for this CLI. ai
phantom-deps phantom-dep:jasmine-jquery AI (phantom-deps): Referenced in karma config files; phantom-dep heuristic false positive for this test tooling package. ai
phantom-deps phantom-dep:less AI (phantom-deps): less is a declared runtime dep used via less-loader config; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:esbuild AI (phantom-deps): esbuild is a known implicit binary dependency; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped package loaded by convention via babel-loader; stable false positive. ai
phantom-deps phantom-dep:jasmine-core AI (phantom-deps): Referenced in karma config files; phantom-dep heuristic false positive for this test tooling package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped Eclipse Scout CLI package; Levenshtein match to 'joi' is a false positive with no brand confusion. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require of user-supplied webpack config file is the documented CLI pattern; not arbitrary code loading. ai
semgrep semgrep:child-process-import AI (semgrep): CLI build tool legitimately uses child_process to run build commands; stable pattern for this package. ai

Versions (showing 12 of 12)

Version Deps Published
26.1.16 32 / 1
26.1.15 32 / 1
26.1.12 32 / 1
26.1.9 32 / 1
26.1.7 32 / 1
26.1.6 32 / 1
26.1.3 32 / 1
26.1.1 32 / 1
25.2.20 32 / 1
25.2.16 32 / 1
25.2.15 32 / 1
25.2.14 32 / 1

v26.1.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.1.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v26.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v26.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v26.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.2.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.2.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v25.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v25.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.