← Home

@epicdm/flowstate-cli

Command-line interface for Epic FlowState project management and initialization

14
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

spencer.epic

Keywords

epic-flowflowstatecliproject-managementtypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:gray-matter AI (phantom-deps): Config-referenced, not a security concern. ai
phantom-deps phantom-dep:cli-table3 AI (phantom-deps): Config-referenced, not a security concern. ai
phantom-deps phantom-dep:fast-glob AI (phantom-deps): Config-referenced, not a security concern. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Config-referenced, not a security concern. ai
phantom-deps phantom-dep:ethers AI (phantom-deps): Config-referenced, fits crypto CLI feature set. ai
phantom-deps phantom-dep:inquirer AI (phantom-deps): Config-referenced, not a security concern. ai
phantom-deps phantom-dep:@solana/web3.js AI (phantom-deps): Config-referenced, fits crypto CLI feature set. ai
phantom-deps phantom-dep:archiver AI (phantom-deps): Config-referenced, not a security concern. ai
phantom-deps phantom-dep:@epicdm/gateway-routes AI (phantom-deps): Same org scope, monorepo dependency graph. ai
phantom-deps phantom-dep:@epicdm/flowstate-app-framework AI (phantom-deps): Same org scope, monorepo dependency graph. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Standard markdown lib, bundling hides direct import. ai
phantom-deps phantom-dep:open AI (phantom-deps): Monorepo bundler resolves imports indirectly; well-known package. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Standard CLI dep, bundling hides direct import. ai
phantom-deps phantom-dep:@inquirer/prompts AI (phantom-deps): Standard CLI prompt lib. ai
phantom-deps phantom-dep:marked-terminal AI (phantom-deps): Standard CLI markdown renderer. ai
dependencies unvetted-dep:@epicdm/connector-core AI (dependencies): Same-org first-party dep, consistent with package function. ai
phantom-deps phantom-dep:@epicdm/connector-core AI (phantom-deps): Same-org workspace package, expected pattern. ai
phantom-deps phantom-dep:viem AI (phantom-deps): Fits stated CLI functionality, no exfil behavior. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Config-referenced schema dep, not a real risk. ai
phantom-deps phantom-dep:ora AI (phantom-deps): Config-referenced CLI dep, not a real risk. ai
phantom-deps phantom-dep:@types/archiver AI (phantom-deps): @types package declared as runtime dep; harmless misplacement, stable for this package. ai

Versions (showing 14 of 14)

Version Deps Published
1.1.11 35 / 12
1.1.10 35 / 12
1.1.9 35 / 12
1.1.8 36 / 11
1.1.7 36 / 11
1.1.6 36 / 11
1.1.5 36 / 11
1.1.4 36 / 11
1.1.3 36 / 11
1.1.2 36 / 11
1.1.1 35 / 11
1.1.0 35 / 11
1.0.0 32 / 11
0.1.0 17 / 0

v1.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.