← Home

@google/gemini-cli-core

Gemini CLI Core

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

google-wombotofrobotsmrdoob

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/bundled/third_party/index.js AI (source-diff): Browser-automation bundle inherently uses net+exec APIs; no malicious target found. ai
source-diff obfuscated-file:dist/bundled/chrome-devtools-mcp.mjs AI (source-diff): Bundled devDep chrome-devtools-mcp output, standard bundler banner. ai
source-diff net-exec-file:dist/bundled/chrome-devtools-mcp.mjs AI (source-diff): Expected for a browser MCP bundle; matches declared dependency purpose. ai
source-diff obfuscated-file:dist/bundled/third_party/index.js AI (source-diff): Bundled third-party (lighthouse/devtools) code, minified not obfuscated. ai
provenance missing-githead AI (provenance): Monorepo build artifact quirk, not a provenance regression for this trusted publisher. ai
source-diff obfuscated-file:dist/src/tools/write-todos.d.ts AI (source-diff): Long line is an embedded prompt string in a .d.ts file, not obfuscated executable code. ai
npm-metadata url-dep:@google/gemini-cli-test-utils AI (npm-metadata): Dev-only monorepo-relative test-utils dep, benign. ai
phantom-deps phantom-dep:proper-lockfile AI (phantom-deps): Config-referenced utility; stable pattern for this package. ai
dependencies unvetted-dep:get-ripgrep AI (dependencies): Monorepo-internal vendored dep (file:../../third_party/get-ripgrep); not a registry bypass risk for this Google-published package. ai
npm-metadata url-dep:get-ripgrep AI (npm-metadata): File-path dep is intentional monorepo vendoring by Google; stable pattern for this package. ai
source-diff large-new-source-files AI (source-diff): Large version jump (0.3.3→0.5.1) from an active Google project; file growth is expected. ai
publish-pattern new-deps-added AI (publish-pattern): Google-published CLI tool; new deps are established utilities with clear purpose. ai
phantom-deps phantom-dep:@opentelemetry/resource-detector-gcp AI (phantom-deps): OpenTelemetry GCP detector loaded conditionally; expected for Google Cloud CLI. ai
phantom-deps phantom-dep:ws AI (phantom-deps): WebSocket dependency loaded conditionally; typical for CLI tools with optional features. ai
phantom-deps phantom-dep:fast-uri AI (phantom-deps): URI parsing dependency referenced in config; expected for Google Cloud integration. ai
phantom-deps phantom-dep:@types/glob AI (phantom-deps): Type package loaded by convention; stable pattern for this package. ai
dependencies unvetted-dep:fast-levenshtein AI (dependencies): fast-levenshtein is a well-known, widely-used string distance utility with no malicious history; safe for this package. ai
provenance no-provenance AI (provenance): Google-published package via google-wombot automation; lack of Sigstore provenance is common and not a disqualifier for this established publisher. ai
dependencies unvetted-dep:systeminformation AI (dependencies): systeminformation is a popular, legitimate system info library with millions of weekly downloads; no active advisories or malicious signals. ai
phantom-deps phantom-dep:puppeteer-core AI (phantom-deps): Browser automation is a documented feature of Gemini CLI; may be loaded conditionally or via dynamic import. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Markdown rendering is expected in a CLI tool; may be used indirectly or in bundled output. ai
bogus-package bogus-package AI (bogus-package): Legitimate Google Gemini CLI core package with proper GitHub repo. README link density reflects extensive documentation links, not a phishing link farm. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Large CLI tool; dotenv may be used in bundled/generated code or loaded by convention. Not a security concern. ai
phantom-deps phantom-dep:@types/html-to-text AI (phantom-deps): Type-only package; framework-scoped, loaded by convention as noted by the analyzer. ai
phantom-deps phantom-dep:@bufbuild/protobuf AI (phantom-deps): Used by gRPC/protobuf stack; may be loaded transitively or via dynamic import in this ESM package. ai

Versions (showing 100 of 175)

Version Deps Published
0.52.0 69 / 9
0.51.0 69 / 9
0.50.0 69 / 9
0.49.0 69 / 9
0.47.0 69 / 9
0.46.0 69 / 9
0.45.3 69 / 9
0.45.0 69 / 9
0.44.1 69 / 9
0.44.0 69 / 9
0.43.0 69 / 9
0.42.0 69 / 9
0.41.2 69 / 9
0.41.0 69 / 9
0.40.1 68 / 9
0.40.0 68 / 9
0.39.1 67 / 9
0.39.0 67 / 9
0.38.2 66 / 9
0.38.1 66 / 9
0.38.0 66 / 9
0.37.2 66 / 9
0.37.1 66 / 9
0.37.0 66 / 9
0.36.0 66 / 9
0.35.3 66 / 9
0.35.2 66 / 9
0.35.1 66 / 9
0.35.0 66 / 9
0.34.0 64 / 7
0.33.2 62 / 7
0.33.1 62 / 7
0.33.0 62 / 7
0.32.1 61 / 7
0.32.0 61 / 7
0.31.0 61 / 7
0.30.1 60 / 7
0.30.0 58 / 7
0.29.7 50 / 8
0.29.6 50 / 8
0.29.5 50 / 8
0.29.4 50 / 8
0.29.3 50 / 8
0.29.2 50 / 8
0.29.1 50 / 8
0.29.0 50 / 8
0.28.2 50 / 8
0.28.1 50 / 8
0.28.0 50 / 8
0.27.4 49 / 8
0.27.3 49 / 8
0.27.2 49 / 8
0.27.1 49 / 8
0.27.0 49 / 8
0.26.0 49 / 9
0.25.2 49 / 9
0.25.1 49 / 9
0.25.0 49 / 9
0.24.5 48 / 9
0.24.4 48 / 9
0.24.3 48 / 9
0.24.2 48 / 9
0.24.1 48 / 9
0.24.0 48 / 9
0.23.0 45 / 8
0.22.5 48 / 10
0.22.4 48 / 10
0.22.3 48 / 10
0.22.2 48 / 10
0.22.1 48 / 10
0.22.0 48 / 10
0.21.3 48 / 10
0.21.2 48 / 10
0.21.1 48 / 10
0.21.0 48 / 10
0.20.2 48 / 10
0.20.1 48 / 10
0.20.0 48 / 10
0.19.4 48 / 10
0.19.3 48 / 10
0.19.2 48 / 10
0.19.1 48 / 10
0.19.0 48 / 10
0.18.4 48 / 10
0.18.3 48 / 10
0.18.2 48 / 10
0.18.1 48 / 10
0.18.0 48 / 10
0.17.1 48 / 10
0.17.0 48 / 10
0.16.0 48 / 10
0.15.4 48 / 10
0.15.3 48 / 10
0.15.2 48 / 10
0.15.1 48 / 10
0.15.0 48 / 10
0.14.0 48 / 10
0.13.0 48 / 10
0.12.0 45 / 10
0.11.3 45 / 10
Showing 100 of 175 Next page →

v0.52.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.51.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.50.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.42.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.41.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.35.0

5 findings
HIGH New obfuscated file: dist/bundled/third_party/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bundled/third_party/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/bundled/chrome-devtools-mcp.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/bundled/chrome-devtools-mcp.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.34.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.33.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.32.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.31.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.30.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.30.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.28.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.27.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.23.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.22.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.15.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.13.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.