@epilot/cli
CLI for epilot APIs
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Single new maintainer at established org, no other risk signals. | ai | |
| source-diff | obfuscated-file:dist/auth-login-7EWYCAZ7.js | AI (source-diff): tsup bundle output of auth-login command, not true obfuscation; no malicious behavior. | ai | |
| provenance | missing-githead | AI (provenance): CI-published, provenance unchanged vs prior approved; metadata gap not a behavior signal. | ai | |
| source-diff | net-exec-file:dist/init-QZTZF2JC.js | AI (source-diff): File only uses fs/path to scaffold project files; no network calls or dynamic execution present. | ai | |
| source-diff | obfuscated-file:dist/auth-login-NHWG3STD.js | AI (source-diff): tsup bundle with readable source comments; not obfuscated, just minified CLI output. | ai | |
| source-diff | obfuscated-file:dist/auth-login-X2GRQW6N.js | AI (source-diff): tsup build output with long lines from bundling; readable source comments confirm legitimate CLI code, not obfuscation. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @epilot/cli is not a plausible typosquat of joi; Levenshtein match is spurious. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): axios is a declared runtime dependency; phantom-dep heuristic fires incorrectly for this package. | ai |
Versions (showing 59 of 59)
| Version | Deps | Published |
|---|---|---|
| 0.1.78 | 9 / 5 | |
| 0.1.77 | 9 / 5 | |
| 0.1.76 | 9 / 5 | |
| 0.1.75 | 9 / 5 | |
| 0.1.74 | 9 / 5 | |
| 0.1.73 | 9 / 5 | |
| 0.1.72 | 9 / 5 | |
| 0.1.71 | 9 / 5 | |
| 0.1.70 | 9 / 5 | |
| 0.1.69 | 9 / 5 | |
| 0.1.68 | 9 / 5 | |
| 0.1.67 | 9 / 5 | |
| 0.1.66 | 9 / 5 | |
| 0.1.65 | 9 / 5 | |
| 0.1.64 | 9 / 5 | |
| 0.1.63 | 9 / 5 | |
| 0.1.62 | 9 / 5 | |
| 0.1.61 | 9 / 5 | |
| 0.1.60 | 9 / 5 | |
| 0.1.59 | 9 / 5 | |
| 0.1.58 | 9 / 5 | |
| 0.1.57 | 9 / 5 | |
| 0.1.56 | 9 / 5 | |
| 0.1.55 | 9 / 5 | |
| 0.1.54 | 9 / 5 | |
| 0.1.53 | 9 / 5 | |
| 0.1.52 | 9 / 5 | |
| 0.1.50 | 9 / 5 | |
| 0.1.49 | 9 / 5 | |
| 0.1.48 | 9 / 5 | |
| 0.1.47 | 9 / 5 | |
| 0.1.46 | 9 / 5 | |
| 0.1.45 | 9 / 5 | |
| 0.1.44 | 9 / 5 | |
| 0.1.43 | 9 / 5 | |
| 0.1.42 | 9 / 5 | |
| 0.1.41 | 9 / 5 | |
| 0.1.40 | 9 / 5 | |
| 0.1.39 | 9 / 5 | |
| 0.1.38 | 9 / 5 | |
| 0.1.37 | 9 / 5 | |
| 0.1.36 | 9 / 5 | |
| 0.1.35 | 9 / 5 | |
| 0.1.34 | 9 / 5 | |
| 0.1.33 | 9 / 5 | |
| 0.1.32 | 9 / 5 | |
| 0.1.28 | 9 / 5 | |
| 0.1.24 | 9 / 5 | |
| 0.1.23 | 9 / 5 | |
| 0.1.22 | 9 / 5 | |
| 0.1.21 | 9 / 5 | |
| 0.1.20 | 9 / 5 | |
| 0.1.19 | 9 / 5 | |
| 0.1.18 | 9 / 5 | |
| 0.1.17 | 9 / 5 | |
| 0.1.16 | 9 / 5 | |
| 0.1.15 | 9 / 5 | |
| 0.1.12 | 9 / 5 | |
| 0.1.0 | 8 / 5 |
v0.1.78
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.77
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.76
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.75
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.74
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.73
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.72
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.71
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.70
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.69
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.68
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.67
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.66
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.65
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.64
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.