← Home

@fern-api/generator-cli

94
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

sandeep-fernelizabeth.fungwillkendall01postman-admin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@fern-api/fs-utils AI (phantom-deps): Monorepo workspace dep; not directly imported at source level but resolved via workspace linking. ai
dependencies unvetted-dep:@fern-api/github AI (dependencies): Workspace-internal sibling package in the same fern-api monorepo; not an external dependency risk. ai
dependencies unvetted-dep:@fern-api/fs-utils AI (dependencies): Workspace-internal sibling package in the same fern-api monorepo; not an external dependency risk. ai
phantom-deps phantom-dep:@fern-api/github AI (phantom-deps): Monorepo workspace dep; not directly imported at source level but resolved via workspace linking. ai
bogus-package bogus-package AI (bogus-package): Internal monorepo CLI tool; missing metadata is a cosmetic issue, not a malice indicator for this established package. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms CI/CD publish; fern-api is an established org with 104 versions and matching repo. ai
npm-metadata no-description AI (npm-metadata): Stable fern-api tooling package; missing description is a cosmetic issue, not a risk indicator. ai
phantom-deps phantom-dep:semver AI (phantom-deps): semver is a declared runtime dep; phantom-dep heuristic false positive for this package. ai

Versions (showing 94 of 94)

Version Deps Published
0.9.53 6 / 0
0.9.52 6 / 0
0.9.51 6 / 0
0.9.50 6 / 0
0.9.49 6 / 0
0.9.48 6 / 0
0.9.47 6 / 0
0.9.46 6 / 0
0.9.45 6 / 0
0.9.44 6 / 0
0.9.43 6 / 0
0.9.42 6 / 0
0.9.41 6 / 0
0.9.40 6 / 0
0.9.39 6 / 0
0.9.37 6 / 0
0.9.36 6 / 0
0.9.35 6 / 0
0.9.34 6 / 0
0.9.33 6 / 0
0.9.32 6 / 0
0.9.31 6 / 0
0.9.30 6 / 0
0.9.29 6 / 0
0.9.28 6 / 0
0.9.27 6 / 0
0.9.26 6 / 0
0.9.25 6 / 0
0.9.24 6 / 0
0.9.23 6 / 0
0.9.22 6 / 0
0.9.21 6 / 0
0.9.20 6 / 0
0.9.19 6 / 0
0.9.18 6 / 0
0.9.17 6 / 0
0.9.16 6 / 0
0.9.15 6 / 0
0.9.14 6 / 0
0.9.13 6 / 0
0.9.11 4 / 0
0.9.10 4 / 0
0.9.9 4 / 0
0.9.8 4 / 0
0.9.7 4 / 0
0.9.6 4 / 0
0.9.5 4 / 0
0.9.4 4 / 0
0.9.3 4 / 0
0.9.2 4 / 0
0.9.1 4 / 0
0.9.0 4 / 0
0.8.1 4 / 0
0.8.0 4 / 0
0.5.0 0 / 16
0.4.6 0 / 16
0.4.5 0 / 16
0.4.3 4 / 12
0.3.1 2 / 13
0.1.5 2 / 13
0.1.4 2 / 13
0.1.3 2 / 13
0.1.2 2 / 13
0.1.1 2 / 13
0.1.0 2 / 13
0.0.42 2 / 13
0.0.41 2 / 13
0.0.40 2 / 13
0.0.33 2 / 13
0.0.32 2 / 13
0.0.31 2 / 13
0.0.30 1 / 13
0.0.29 1 / 13
0.0.28 1 / 13
0.0.27 1 / 13
0.0.26 1 / 13
0.0.25 1 / 13
0.0.24 1 / 13
0.0.23 1 / 13
0.0.22 1 / 13
0.0.21 1 / 13
0.0.20 1 / 13
0.0.19 1 / 13
0.0.18 0 / 19
0.0.17 0 / 19
0.0.9 0 / 18
0.0.8 0 / 18
0.0.7 0 / 18
0.0.6 0 / 18
0.0.5 0 / 18
0.0.4 0 / 17
0.0.3 0 / 17
0.0.2 0 / 17
0.0.1 0 / 17

v0.9.53

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.52

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.51

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.50

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.49

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.48

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.47

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.46

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.45

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.44

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.43

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.42

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.