@espcompose/cli
ESPCompose CLI - Command-line tools for building ESPCompose projects
16
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
xmlguy74
Keywords
esphometypescriptclibuild-tool
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:assets/simulator-app/assets/index-CBg-HhJ3.js | AI (source-diff): Vite-bundled React simulator app asset; minification is expected for this package's frontend component. | ai | |
| source-diff | net-exec-file:assets/simulator-app/assets/index-CBg-HhJ3.js | AI (source-diff): Network calls are browser fetch for modulepreload; dynamic code execution is standard React runtime — not dropper behavior. | ai | |
| source-diff | net-exec-file:assets/simulator-app/assets/index-_rZ7OIFG.js | AI (source-diff): Network calls are fetch() for modulepreload; dynamic code is standard React/Vite bundle patterns, not dropper behavior. | ai | |
| source-diff | obfuscated-file:assets/simulator-app/assets/index-_rZ7OIFG.js | AI (source-diff): Standard Vite/React production bundle; React license header and modulepreload logic confirm legitimate minified output. | ai | |
| source-diff | obfuscated-file:dist/init-2DWVNZV6.js | AI (source-diff): tsup/esbuild bundled output; long lines are minified deps (handlebars etc.), not obfuscation. | ai | |
| source-diff | net-exec-file:assets/simulator-app/assets/index-DpThQxw0.js | AI (source-diff): Network calls and dynamic execution are normal browser app patterns in a bundled React simulator asset. | ai | |
| source-diff | obfuscated-file:assets/simulator-app/assets/index-DpThQxw0.js | AI (source-diff): Standard Vite/React production bundle; minification is expected for this simulator app asset. | ai | |
| source-diff | obfuscated-file:dist/init-KD462OAR.js | AI (source-diff): File is a tsup/esbuild bundle of legitimate deps (handlebars etc.); long lines are from bundling, not obfuscation. | ai | |
| phantom-deps | phantom-dep:which | AI (phantom-deps): which is a standard CLI utility dep; phantom-dep heuristic fires on indirect usage patterns. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): yaml is a common config-parsing dep; phantom-dep heuristic fires on indirect usage patterns in CLI tools. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped ESPHome build tool; no relation to joi. Levenshtein match is coincidental. | ai | |
| phantom-deps | phantom-dep:typescript-eslint | AI (phantom-deps): typescript-eslint is used in ESLint config files, not directly imported — stable false positive for this package. | ai |