@google/gemini-cli
Gemini CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:bundle/chunk-Z7C7OBI2.js | AI (source-diff): Bundled CLI tooling chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-6DSAZLFF.js | AI (source-diff): Bundled CLI tooling chunk; net+exec is build output, recurs every release. | ai | |
| source-diff | net-exec-file:bundle/chunk-FWECAYR3.js | AI (source-diff): Bundled CLI tooling chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-PBNB5XZ6.js | AI (source-diff): Bundled CLI tooling chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-B2OARGJJ.js | AI (source-diff): Bundled CLI agent tooling; net+exec inherent to gemini-cli, filenames change per build. | ai | |
| source-diff | net-exec-file:bundle/chunk-B2LNN6KY.js | AI (source-diff): Bundled CLI chunk; net+exec is build output, no hostile target. | ai | |
| source-diff | net-exec-file:bundle/chunk-CSDNDSTO.js | AI (source-diff): Bundled CLI chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-GLO32GZ3.js | AI (source-diff): Bundled CLI chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-SAJ72M2G.js | AI (source-diff): ajv/websocket bundle chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-XRLFHCHC.js | AI (source-diff): ajv/websocket bundle chunk; benign build output. | ai | |
| provenance | missing-githead | AI (provenance): Metadata-only; official Google publisher, not a malicious signal. | ai | |
| source-diff | net-exec-file:bundle/chunk-IQDAUFS5.js | AI (source-diff): Bundled esbuild chunk of official CLI; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-BG2B4WV5.js | AI (source-diff): Bundled esbuild chunk of official CLI; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-7LQRUKPT.js | AI (source-diff): Bundled esbuild chunk of official CLI; net+require are legit deps (websocket/proxy-agent). | ai | |
| source-diff | net-exec-file:bundle/chunk-RTKRL6Y5.js | AI (source-diff): Bundled CLI chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-67TFD6HC.js | AI (source-diff): Bundled CLI chunk; ajv/websocket, benign. | ai | |
| source-diff | net-exec-file:bundle/chunk-QM5IP3NK.js | AI (source-diff): Bundled CLI chunk; ajv/websocket, benign. | ai | |
| source-diff | net-exec-file:bundle/chunk-UQGLVPZQ.js | AI (source-diff): Bundled CLI chunk; benign build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-3YUTTNJ7.js | AI (source-diff): Bundled CLI chunk; net+exec is normal agent tooling, no hostile target. | ai | |
| source-diff | net-exec-file:bundle/chunk-DHQ53XVO.js | AI (source-diff): Bundled esbuild chunk; build output. | ai | |
| source-diff | obfuscated-file:bundle/src-XZYPU6PJ.js | AI (source-diff): Minified esbuild bundle (ws lib), not obfuscation. | ai | |
| source-diff | net-exec-file:bundle/gemini-PPWSIUOX.js | AI (source-diff): Bundled CLI entry chunk; build output. | ai | |
| source-diff | net-exec-file:bundle/gemini-FJJIUT3T.js | AI (source-diff): Bundled CLI entry chunk; build output. | ai | |
| source-diff | net-exec-file:bundle/gemini-EVKJWIDN.js | AI (source-diff): Bundled CLI entry chunk; build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-OW353XI3.js | AI (source-diff): Bundled esbuild chunk; build output. | ai | |
| source-diff | net-exec-file:bundle/chunk-AWR3APYV.js | AI (source-diff): Bundled esbuild chunk (proxy-agent/ws/toml); build output, not a dropper. | ai | |
| source-diff | net-exec-file:bundle/chunk-G33JEOEV.js | AI (source-diff): Bundled CLI chunks with network+exec are expected for this package's architecture. | ai | |
| source-diff | net-exec-file:bundle/chunk-RCJSF5RP.js | AI (source-diff): Bundled CLI chunks with network+exec are expected for this package's architecture. | ai | |
| source-diff | net-exec-file:bundle/chunk-6ZHP2EJW.js | AI (source-diff): Bundled CLI chunks with network+exec are expected for this package's architecture. | ai | |
| source-diff | net-exec-file:bundle/chunk-GIZG2CGQ.js | AI (source-diff): Bundled CLI chunk with node_modules; network+exec is normal for this package's architecture. | ai | |
| source-diff | net-exec-file:bundle/chunk-6HYYI5PZ.js | AI (source-diff): Bundled CLI chunk with node_modules; network+exec is normal for this package's architecture. | ai | |
| source-diff | net-exec-file:bundle/chunk-FFUBQCSE.js | AI (source-diff): Bundled CLI chunk with node_modules; network+exec is normal for this package's architecture. | ai | |
| source-diff | net-exec-file:bundle/chunk-VXAIUB7K.js | AI (source-diff): Bundled CLI chunk with node_modules; network+exec is normal for this package's architecture. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost 127.0.0.1 for local OAuth callback server; not an external IP. | ai | |
| phantom-deps | phantom-dep:ink-select-input | AI (phantom-deps): Same as ink-big-text — conditional JSX rendering not detected by static import analysis. | ai | |
| source-diff | net-exec-file:bundle/chunk-UHHRGNIO.js | AI (source-diff): Bundled app chunk with standard CLI logic; not a dropper. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Standard crypto decrypt routine in CLI tool. | ai | |
| source-diff | net-exec-file:bundle/chunk-FRSESBS3.js | AI (source-diff): Bundled app chunk with standard CLI logic; not a dropper. | ai | |
| source-diff | net-exec-file:bundle/chunk-F73F75XM.js | AI (source-diff): Bundled app chunk with standard CLI logic; not a dropper. | ai | |
| source-diff | net-exec-file:bundle/chunk-3OSQ5US4.js | AI (source-diff): Bundled app chunk with standard CLI logic; not a dropper. | ai | |
| source-diff | net-exec-file:bundle/chunk-SZYCJREE.js | AI (source-diff): Bundled app chunk with standard CLI logic; not a dropper. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Rapidly evolving Google CLI; large file additions reflect legitimate feature growth across minor versions. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are well-known OSS packages consistent with a terminal UI CLI tool; no suspicious additions. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Size drop explained by code split into @google/gemini-cli-core sibling package. | ai | |
| dependencies | unvetted-dep:ink-big-text | AI (dependencies): ink-big-text is a legitimate ink ecosystem UI package; expected for a CLI tool built on ink/react. | ai | |
| phantom-deps | phantom-dep:mime-types | AI (phantom-deps): Declared dep in Google's official CLI; likely used in @google/gemini-cli-core or subcomponents. | ai | |
| phantom-deps | phantom-dep:ink-text-input | AI (phantom-deps): Ink UI component; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:ink-big-text | AI (phantom-deps): Ink UI component for CLI splash screen; phantom detection is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:ink-link | AI (phantom-deps): Monorepo CLI package; ink-link likely used in subcomponents or transitively; stable false positive. | ai | |
| phantom-deps | phantom-dep:@google/gemini-cli | AI (phantom-deps): Self-referencing dep in monorepo workspace pattern; same-org scope, benign. | ai | |
| source-diff | encoded-string-file:bundle/gemini.js | AI (source-diff): undici llhttp WASM base64 blob; standard HTTP parser bundled into the CLI. | ai | |
| dependencies | unvetted-dep:tinygradient | AI (dependencies): tinygradient is a well-known color gradient utility used for terminal UI rendering in this CLI; no malicious signals. | ai | |
| phantom-deps | phantom-dep:read-package-up | AI (phantom-deps): Common in TypeScript monorepo CLIs; declared for type resolution or indirect use, not a security concern. | ai | |
| npm-metadata | url-dep:@google/gemini-cli-core | AI (npm-metadata): file:../core is a monorepo workspace pattern in the google-gemini/gemini-cli repo; resolved at build time and not a supply-chain risk in the published artifact. | ai | |
| provenance | no-provenance | AI (provenance): google-wombot is a well-established Google publisher with 2600+ days of history; absence of Sigstore provenance is not a meaningful risk signal for this package. | ai | |
| phantom-deps | phantom-dep:@types/update-notifier | AI (phantom-deps): Framework-scoped type package loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:wrap-ansi | AI (phantom-deps): wrap-ansi is a standard dependency for CLI formatting; phantom-dep finding is expected for this package. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): diff is a legitimate dependency used in CLI tools; phantom-dep finding is a false positive for this package type. | ai | |
| phantom-deps | phantom-dep:color-convert | AI (phantom-deps): color-convert is a benign utility declared as a dependency; indirect usage pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): highlight.js is declared as a dependency and used indirectly via lowlight/bundling; not a security concern for this package. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Bundled `debug` library filtering for DEBUG_ env vars; canonical pattern, stable for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() in Proxy get trap is idiomatic JS Proxy usage, not obfuscation. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): CLI tool legitimately spreads process.env for sandbox/child process configuration; standard pattern for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard esbuild/bundler shim (__toBinaryNode) for binary asset handling; build artifact, not obfuscation. | ai |
Versions (showing 51 of 95)
| Version | Deps | Published |
|---|---|---|
| 0.52.0 | 0 / 0 | |
| 0.51.0 | 0 / 0 | |
| 0.46.0 | 0 / 0 | |
| 0.45.1 | 0 / 0 | |
| 0.41.2 | 0 / 0 | |
| 0.41.0 | 0 / 0 | |
| 0.40.1 | 0 / 0 | |
| 0.40.0 | 0 / 0 | |
| 0.39.1 | 0 / 0 | |
| 0.39.0 | 0 / 0 | |
| 0.38.2 | 0 / 0 | |
| 0.38.1 | 0 / 0 | |
| 0.38.0 | 0 / 0 | |
| 0.37.2 | 0 / 0 | |
| 0.37.1 | 0 / 0 | |
| 0.37.0 | 0 / 0 | |
| 0.36.0 | 0 / 0 | |
| 0.35.2 | 40 / 12 | |
| 0.35.1 | 40 / 12 | |
| 0.28.0 | 39 / 18 | |
| 0.24.2 | 37 / 19 | |
| 0.22.2 | 36 / 19 | |
| 0.12.0 | 34 / 21 | |
| 0.11.3 | 33 / 21 | |
| 0.11.2 | 33 / 21 | |
| 0.11.1 | 33 / 21 | |
| 0.11.0 | 33 / 21 | |
| 0.10.0 | 33 / 21 | |
| 0.9.0 | 33 / 21 | |
| 0.8.2 | 32 / 21 | |
| 0.8.1 | 32 / 21 | |
| 0.8.0 | 32 / 21 | |
| 0.7.1 | 28 / 18 | |
| 0.7.0 | 29 / 18 | |
| 0.6.1 | 29 / 18 | |
| 0.6.0 | 29 / 18 | |
| 0.5.5 | 28 / 18 | |
| 0.5.4 | 27 / 18 | |
| 0.5.3 | 27 / 18 | |
| 0.5.1 | 27 / 18 | |
| 0.5.0 | 27 / 18 | |
| 0.4.1 | 27 / 18 | |
| 0.4.0 | 27 / 18 | |
| 0.3.4 | 29 / 19 | |
| 0.3.3 | 29 / 19 | |
| 0.3.2 | 29 / 19 | |
| 0.3.1 | 29 / 19 | |
| 0.3.0 | 29 / 19 | |
| 0.2.2 | 29 / 18 | |
| 0.2.1 | 29 / 18 | |
| 0.1.22 | 29 / 18 |
v0.52.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: google-wombot.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.0
9 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: google-wombot.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.2
7 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.1
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.