@genesislcap/foundation-cli
Genesis Foundation CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): High-velocity monorepo with ~2000 versions; rapid sequential publishes are expected CI behavior. | ai | |
| dependencies | unvetted-dep:inquirer-fuzzy-path | AI (dependencies): Inquirer UI plugin for fuzzy path selection; low-risk interactive prompt helper stable for this CLI package. | ai | |
| dependencies | unvetted-dep:inquirer-file-tree-selection-prompt | AI (dependencies): Inquirer UI plugin for file tree selection; low-risk interactive prompt helper stable for this CLI package. | ai | |
| dependencies | unvetted-dep:inquirer-select-directory | AI (dependencies): Inquirer UI plugin for directory selection; low-risk interactive prompt helper stable for this CLI package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established Genesis platform package; sparse README is a style choice, not spam. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Long-lived CLI package; postinstall runs a local node script, consistent with documented setup across many versions. | ai | |
| phantom-deps | phantom-dep:@microsoft/fast-router | AI (phantom-deps): Declared dep used indirectly via config/plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:liftoff | AI (phantom-deps): Declared dep used indirectly via config/plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:open | AI (phantom-deps): Declared dep used indirectly via config/plugin pattern; stable false positive for this package. | ai |
Versions (showing 51 of 154)
| Version | Deps | Published |
|---|---|---|
| 14.449.0 | 29 / 7 | |
| 14.445.2 | 29 / 7 | |
| 14.445.0 | 29 / 7 | |
| 14.444.1 | 29 / 7 | |
| 14.444.0 | 29 / 7 | |
| 14.443.1 | 29 / 7 | |
| 14.442.0 | 29 / 7 | |
| 14.439.3 | 29 / 7 | |
| 14.439.2 | 29 / 7 | |
| 14.439.1 | 29 / 7 | |
| 14.439.0 | 29 / 7 | |
| 14.438.1 | 29 / 7 | |
| 14.438.0 | 29 / 7 | |
| 14.437.6 | 29 / 7 | |
| 14.437.3 | 29 / 7 | |
| 14.432.1 | 29 / 7 | |
| 14.430.1 | 29 / 7 | |
| 14.430.0 | 29 / 7 | |
| 14.428.1 | 29 / 7 | |
| 14.428.0 | 29 / 7 | |
| 14.427.1 | 29 / 7 | |
| 14.425.0 | 29 / 7 | |
| 14.424.1 | 29 / 7 | |
| 14.422.1 | 29 / 7 | |
| 14.418.2 | 29 / 7 | |
| 14.418.0 | 29 / 7 | |
| 14.417.0 | 29 / 7 | |
| 14.416.0 | 29 / 7 | |
| 14.415.0 | 29 / 7 | |
| 14.408.0 | 29 / 7 | |
| 14.406.0 | 29 / 7 | |
| 14.403.0 | 29 / 7 | |
| 14.401.4 | 29 / 7 | |
| 14.401.3 | 29 / 7 | |
| 14.401.0 | 29 / 7 | |
| 14.400.0 | 29 / 7 | |
| 14.399.0 | 29 / 7 | |
| 14.398.0 | 29 / 7 | |
| 14.396.4 | 29 / 7 | |
| 14.393.4 | 29 / 7 | |
| 14.393.3 | 29 / 7 | |
| 14.393.1 | 29 / 7 | |
| 14.390.1 | 29 / 7 | |
| 14.389.0 | 29 / 7 | |
| 14.388.1 | 29 / 7 | |
| 14.387.0 | 29 / 6 | |
| 14.386.1 | 29 / 6 | |
| 14.385.0 | 29 / 6 | |
| 14.383.2 | 29 / 6 | |
| 14.383.1 | 29 / 6 | |
| 14.382.2 | 29 / 6 |
v14.449.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.445.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.445.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.444.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.444.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.443.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.442.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.439.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.438.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.438.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.437.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.437.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.432.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.430.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.430.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.428.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.428.0
2 findingsScript: node ./scripts/postinstall
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.427.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.425.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.424.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.422.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.418.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.418.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.417.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.416.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.415.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.408.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.406.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.403.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.401.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.401.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.401.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.400.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.399.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.398.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.396.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.393.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.393.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.393.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.390.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.389.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.388.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.387.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.386.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.385.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.383.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.383.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.382.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.