← Home

@getmikk/cli

> The `mikk` command — initialize, analyze, watch, query, and guard your codebase architecture.

25
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ansh_dhanani

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:zod AI (phantom-deps): Bundled via esbuild into dist, not directly imported at source level. ai
phantom-deps phantom-dep:oxc-resolver AI (phantom-deps): Bundled via esbuild into dist, not directly imported at source level. ai
phantom-deps phantom-dep:oxc-parser AI (phantom-deps): Bundled via esbuild into dist, not directly imported at source level. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): Bundled via esbuild into dist, not directly imported at source level. ai
phantom-deps phantom-dep:@modelcontextprotocol/sdk AI (phantom-deps): Official SDK, used via config. ai
phantom-deps phantom-dep:@getmikk/diagram-generator AI (phantom-deps): Same-org sibling package. ai
phantom-deps phantom-dep:better-sqlite3 AI (phantom-deps): Used via config, not direct import; native binding pattern. ai
phantom-deps phantom-dep:web-tree-sitter AI (phantom-deps): Used via config, not direct import. ai
phantom-deps phantom-dep:@xenova/transformers AI (phantom-deps): Used via config, not direct import. ai
phantom-deps phantom-dep:@getmikk/core AI (phantom-deps): Same-org sibling package, expected monorepo pattern. ai
phantom-deps phantom-dep:@getmikk/watcher AI (phantom-deps): Same-org sibling package. ai
phantom-deps phantom-dep:@getmikk/ai-context AI (phantom-deps): Same-org sibling package. ai
phantom-deps phantom-dep:@getmikk/mcp-server AI (phantom-deps): Same-org sibling package. ai
phantom-deps phantom-dep:@getmikk/intent-engine AI (phantom-deps): Same-org sibling package. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Bundled via esbuild; not directly imported in source but included in the bundle output. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Bundled via esbuild; not directly imported in source but included in the bundle output. ai
phantom-deps phantom-dep:ora AI (phantom-deps): Bundled via esbuild; not directly imported in source but included in the bundle output. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @getmikk/* package; Levenshtein match to 'joi' is coincidental, not impersonation. ai

Versions (showing 25 of 25)

Version Deps Published
2.1.5 14 / 4
2.1.4 14 / 4
2.1.3 14 / 4
2.1.2 14 / 4
2.1.1 14 / 4
2.1.0 14 / 4
2.0.18 12 / 4
2.0.17 12 / 4
2.0.16 12 / 4
2.0.15 12 / 4
2.0.14 8 / 9
2.0.13 8 / 9
2.0.12 8 / 9
2.0.11 8 / 4
2.0.10 8 / 3
2.0.0 13 / 3
1.9.1 13 / 3
1.9.0 13 / 3
1.8.2 3 / 13
1.8.1 3 / 13
1.5.0 1 / 11
1.3.2 1 / 11
1.3.1 8 / 3
1.3.0 7 / 3
1.2.1 7 / 3

v2.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.