← Home

@fedify/cli

CLI toolchain for Fedify and debugging ActivityPub

64
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

hongminhee

Keywords

fedifyactivitypubclifediverse

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): Automated CI/CD release pipeline with SLSA provenance; rapid publish is expected. ai
source-diff source-size-dropped AI (source-diff): Package intentionally restructured as a binary-fetching stub; size drop is expected and stable. ai
phantom-deps phantom-dep:@standard-schema/spec AI (phantom-deps): Type-only/config usage of @standard-schema/spec is expected; not a runtime import concern. ai
dependencies unvetted-dep:icojs AI (dependencies): ICO image parsing library; consistent with CLI avatar/icon handling use case. ai
dependencies unvetted-dep:@poppanator/http-constants AI (dependencies): HTTP constants utility; benign helper library for HTTP-based ActivityPub tooling. ai
dependencies unvetted-dep:@jimp/wasm-webp AI (dependencies): WebP image codec for jimp; consistent with image processing in ActivityPub CLI. ai
source-diff large-new-source-files AI (source-diff): New source files correspond to new features in v2 major release. ai
publish-pattern new-deps-added AI (publish-pattern): v2 major release with documented new features; SLSA provenance confirms CI/CD build integrity. ai
source-diff source-size-tripled AI (source-diff): Major version bump with 37 new deps; size increase is expected, not injected payload. ai
dependencies unvetted-dep:@hongminhee/localtunnel AI (dependencies): @hongminhee is the same author as this package (Hong Minhee); this is a first-party dependency. ai
publish-pattern dormant-publish AI (publish-pattern): Package has SLSA provenance attestation via CI/CD and a legitimate established repository (fedify-dev/fedify). 301 versions in registry confirms active development history; dormancy is a release cadence artifact, not a takeover signal. ai
provenance slsa-provenance AI (provenance): Package consistently published via CI/CD with SLSA provenance attestation; stable supply chain integrity signal for this package. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall runs node src/install.mjs to set up platform-specific CLI binaries; consistent with declared os/cpu constraints and backed by SLSA provenance attestation. ai
phantom-deps phantom-dep:fetch-mock AI (phantom-deps): fetch-mock is a legitimate declared dependency used for testing/mocking in the CLI. Not a security concern. ai
phantom-deps phantom-dep:inquirer AI (phantom-deps): CLI tool; inquirer is a legitimate declared dependency. Phantom-dep finding is a false positive for this package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @fedify/cli is a scoped package for the Fedify ActivityPub framework; no relation to 'joi'. Levenshtein match is a false positive for this well-known package. ai
phantom-deps phantom-dep:enquirer AI (phantom-deps): CLI tool; enquirer is a legitimate declared dependency used conditionally or indirectly. Not a security concern. ai
phantom-deps phantom-dep:@inquirer/prompts AI (phantom-deps): @inquirer/prompts is a legitimate declared dependency for CLI prompts. Phantom-dep finding is a false positive. ai
phantom-deps phantom-dep:inquirer-toggle AI (phantom-deps): inquirer-toggle is a legitimate declared dependency for CLI prompts. Phantom-dep finding is a false positive. ai

Versions (showing 64 of 64)

Version Deps Published
2.2.4 38 / 4
2.2.3 38 / 4
2.2.2 38 / 4
2.2.1 38 / 4
2.2.0 38 / 4
2.1.16 37 / 4
2.1.15 37 / 4
2.1.14 37 / 4
2.1.13 37 / 4
2.1.12 37 / 4
2.1.11 37 / 4
2.1.10 37 / 4
2.1.9 37 / 4
2.1.8 37 / 4
2.1.7 37 / 4
2.1.6 37 / 4
2.1.5 37 / 4
2.1.4 37 / 4
2.1.3 37 / 4
2.1.2 37 / 4
2.1.1 37 / 4
2.1.0 37 / 4
2.0.20 37 / 4
2.0.19 37 / 4
2.0.18 37 / 4
2.0.17 37 / 4
2.0.16 37 / 4
2.0.15 37 / 4
2.0.14 37 / 4
2.0.13 37 / 4
2.0.12 37 / 4
2.0.11 37 / 4
2.0.10 37 / 4
2.0.9 37 / 4
2.0.8 37 / 4
2.0.7 37 / 4
2.0.6 37 / 4
2.0.5 37 / 4
2.0.4 37 / 4
2.0.3 37 / 4
2.0.2 37 / 4
2.0.1 37 / 4
2.0.0 37 / 4
1.10.11 0 / 0
1.10.8 0 / 0
1.10.7 0 / 0
1.10.5 0 / 0
1.10.3 0 / 0
1.10.2 0 / 0
1.10.1 0 / 0
1.10.0 0 / 0
1.9.12 0 / 0
1.9.10 0 / 0
1.9.9 0 / 0
1.9.8 0 / 0
1.9.7 0 / 0
1.9.6 0 / 0
1.9.4 0 / 0
1.9.3 0 / 0
1.9.1 0 / 0
1.7.16 0 / 0
1.7.15 0 / 0
1.7.14 0 / 0
1.6.15 0 / 0

v2.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.20

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.19

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.16

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.8

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.7

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.5

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.9

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.8

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.7

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.6

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.1

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node src/install.mjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.