@fugood/bricks-cli
BRICKS CLI - Command-line interface for BRICKS Workspace API
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Webpack-bundled CLI; runtime deps are bundled, not directly imported at module level. Stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@fugood/bricks-config-core | AI (phantom-deps): Same-org dep bundled via webpack; phantom-dep heuristic is a false positive for this build pattern. | ai | |
| phantom-deps | phantom-dep:conf | AI (phantom-deps): Webpack-bundled CLI; deps inlined in bundle, not directly imported at module level. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside webpack bundle output; standard bundler pattern for this CLI package. | ai | |
| phantom-deps | phantom-dep:ink-picture | AI (phantom-deps): Webpack-bundled CLI; deps inlined in bundle, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Webpack-bundled CLI; deps inlined in bundle, not directly imported at module level. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Webpack-bundled CLI; deps inlined in bundle, not directly imported at module level. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 2.24.6 | 6 / 17 | |
| 2.24.5 | 6 / 17 | |
| 2.24.4 | 6 / 17 | |
| 2.24.3 | 6 / 17 | |
| 2.24.2 | 6 / 16 | |
| 2.24.1 | 6 / 16 | |
| 2.24.0 | 6 / 16 | |
| 2.23.9 | 5 / 16 | |
| 2.23.8 | 5 / 16 | |
| 2.23.7 | 5 / 15 | |
| 2.23.6 | 5 / 15 | |
| 2.23.5 | 6 / 15 | |
| 2.23.4 | 5 / 15 | |
| 2.23.3 | 5 / 14 | |
| 2.23.2 | 5 / 14 | |
| 2.23.0 | 5 / 14 |
v2.24.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.23.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.