@fedify/cli
CLI toolchain for Fedify and debugging ActivityPub
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD release pipeline with SLSA provenance; rapid publish is expected. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Package intentionally restructured as a binary-fetching stub; size drop is expected and stable. | ai | |
| phantom-deps | phantom-dep:@standard-schema/spec | AI (phantom-deps): Type-only/config usage of @standard-schema/spec is expected; not a runtime import concern. | ai | |
| dependencies | unvetted-dep:icojs | AI (dependencies): ICO image parsing library; consistent with CLI avatar/icon handling use case. | ai | |
| dependencies | unvetted-dep:@poppanator/http-constants | AI (dependencies): HTTP constants utility; benign helper library for HTTP-based ActivityPub tooling. | ai | |
| dependencies | unvetted-dep:@jimp/wasm-webp | AI (dependencies): WebP image codec for jimp; consistent with image processing in ActivityPub CLI. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New source files correspond to new features in v2 major release. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): v2 major release with documented new features; SLSA provenance confirms CI/CD build integrity. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Major version bump with 37 new deps; size increase is expected, not injected payload. | ai | |
| dependencies | unvetted-dep:@hongminhee/localtunnel | AI (dependencies): @hongminhee is the same author as this package (Hong Minhee); this is a first-party dependency. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Package has SLSA provenance attestation via CI/CD and a legitimate established repository (fedify-dev/fedify). 301 versions in registry confirms active development history; dormancy is a release cadence artifact, not a takeover signal. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published via CI/CD with SLSA provenance attestation; stable supply chain integrity signal for this package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs node src/install.mjs to set up platform-specific CLI binaries; consistent with declared os/cpu constraints and backed by SLSA provenance attestation. | ai | |
| phantom-deps | phantom-dep:fetch-mock | AI (phantom-deps): fetch-mock is a legitimate declared dependency used for testing/mocking in the CLI. Not a security concern. | ai | |
| phantom-deps | phantom-dep:inquirer | AI (phantom-deps): CLI tool; inquirer is a legitimate declared dependency. Phantom-dep finding is a false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @fedify/cli is a scoped package for the Fedify ActivityPub framework; no relation to 'joi'. Levenshtein match is a false positive for this well-known package. | ai | |
| phantom-deps | phantom-dep:enquirer | AI (phantom-deps): CLI tool; enquirer is a legitimate declared dependency used conditionally or indirectly. Not a security concern. | ai | |
| phantom-deps | phantom-dep:@inquirer/prompts | AI (phantom-deps): @inquirer/prompts is a legitimate declared dependency for CLI prompts. Phantom-dep finding is a false positive. | ai | |
| phantom-deps | phantom-dep:inquirer-toggle | AI (phantom-deps): inquirer-toggle is a legitimate declared dependency for CLI prompts. Phantom-dep finding is a false positive. | ai |
Versions (showing 64 of 64)
| Version | Deps | Published |
|---|---|---|
| 2.2.4 | 38 / 4 | |
| 2.2.3 | 38 / 4 | |
| 2.2.2 | 38 / 4 | |
| 2.2.1 | 38 / 4 | |
| 2.2.0 | 38 / 4 | |
| 2.1.16 | 37 / 4 | |
| 2.1.15 | 37 / 4 | |
| 2.1.14 | 37 / 4 | |
| 2.1.13 | 37 / 4 | |
| 2.1.12 | 37 / 4 | |
| 2.1.11 | 37 / 4 | |
| 2.1.10 | 37 / 4 | |
| 2.1.9 | 37 / 4 | |
| 2.1.8 | 37 / 4 | |
| 2.1.7 | 37 / 4 | |
| 2.1.6 | 37 / 4 | |
| 2.1.5 | 37 / 4 | |
| 2.1.4 | 37 / 4 | |
| 2.1.3 | 37 / 4 | |
| 2.1.2 | 37 / 4 | |
| 2.1.1 | 37 / 4 | |
| 2.1.0 | 37 / 4 | |
| 2.0.20 | 37 / 4 | |
| 2.0.19 | 37 / 4 | |
| 2.0.18 | 37 / 4 | |
| 2.0.17 | 37 / 4 | |
| 2.0.16 | 37 / 4 | |
| 2.0.15 | 37 / 4 | |
| 2.0.14 | 37 / 4 | |
| 2.0.13 | 37 / 4 | |
| 2.0.12 | 37 / 4 | |
| 2.0.11 | 37 / 4 | |
| 2.0.10 | 37 / 4 | |
| 2.0.9 | 37 / 4 | |
| 2.0.8 | 37 / 4 | |
| 2.0.7 | 37 / 4 | |
| 2.0.6 | 37 / 4 | |
| 2.0.5 | 37 / 4 | |
| 2.0.4 | 37 / 4 | |
| 2.0.3 | 37 / 4 | |
| 2.0.2 | 37 / 4 | |
| 2.0.1 | 37 / 4 | |
| 2.0.0 | 37 / 4 | |
| 1.10.11 | 0 / 0 | |
| 1.10.8 | 0 / 0 | |
| 1.10.7 | 0 / 0 | |
| 1.10.5 | 0 / 0 | |
| 1.10.3 | 0 / 0 | |
| 1.10.2 | 0 / 0 | |
| 1.10.1 | 0 / 0 | |
| 1.10.0 | 0 / 0 | |
| 1.9.12 | 0 / 0 | |
| 1.9.10 | 0 / 0 | |
| 1.9.9 | 0 / 0 | |
| 1.9.8 | 0 / 0 | |
| 1.9.7 | 0 / 0 | |
| 1.9.6 | 0 / 0 | |
| 1.9.4 | 0 / 0 | |
| 1.9.3 | 0 / 0 | |
| 1.9.1 | 0 / 0 | |
| 1.7.16 | 0 / 0 | |
| 1.7.15 | 0 / 0 | |
| 1.7.14 | 0 / 0 | |
| 1.6.15 | 0 / 0 |
v2.2.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.8
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.7
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.5
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.9
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.8
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.7
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.6
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.1
2 findingsScript: node src/install.mjs
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.