← Home

@harness-engineering/cli

CLI for Harness Engineering toolkit

35
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

intense.visions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/chunk-33OU3LYX.js AI (source-diff): Bundled first-party CLI code (parsers/analyzers), not a loader; pattern-match false positive on minified bundle. ai
source-diff net-exec-file:dist/chunk-65M5R3X6.js AI (source-diff): Bundled internal CLI chunk (tsup), not injected dropper code. ai
source-diff net-exec-file:dist/chunk-2TGCYJMT.js AI (source-diff): Bundled tsup chunk with schema/crypto imports, not obfuscated dropper code. ai
source-diff net-exec-file:dist/chunk-4DWOMGUM.js AI (source-diff): Bundled tsup chunk with normal imports, not a dropper; no exfil/exec behavior in sample. ai
source-diff net-exec-file:dist/chunk-H4U2QNY2.js AI (source-diff): Bundled tsup chunk with legit imports (zod/fs/crypto), no obfuscation or hostile payload observed. ai
source-diff large-new-source-files AI (source-diff): Expected growth from bundling new first-party features/deps, not injected code. ai
source-diff net-exec-file:dist/chunk-YC4EYIER.js AI (source-diff): Bundled build chunk with legitimate imports; no fetched-binary or credential-exfil behavior in sample. ai
phantom-deps phantom-dep:better-sqlite3 AI (phantom-deps): Likely used via config/native binding, not a real risk. ai
publish-pattern new-deps-added AI (publish-pattern): better-sqlite3 is a well-known native dep, not suspicious. ai
provenance publisher-changed AI (provenance): Change is to CI/CD (GitHub Actions) publisher with SLSA attestation, not account takeover. ai
source-diff net-exec-file:dist/chunk-MMLQPHZ5.js AI (source-diff): Bundled tsup chunk with legit CLI exports, not a loader/dropper. ai
source-diff net-exec-file:dist/chunk-K4WRQTEF.js AI (source-diff): Large bundled CLI chunk; imports are standard well-known libs. SLSA provenance confirms CI/CD build integrity. ai
source-diff net-exec-file:dist/chunk-77EZGPSR.js AI (source-diff): Bundled ESM output for a CLI tool; imports are standard Node.js/npm modules, not dropper behavior. ai
source-diff net-exec-file:dist/chunk-KHMKAC6E.js AI (source-diff): File contains AST parsing (web-tree-sitter), file I/O, and crypto ops consistent with CLI code-analysis features; SLSA provenance confirms CI/CD build. ai
source-diff net-exec-file:dist/chunk-KQ6TDRPS.js AI (source-diff): Sample shows legitimate analysis/CLI tooling imports; SLSA provenance confirms CI/CD build integrity. ai
source-diff net-exec-file:dist/chunk-MI6MA6OP.js AI (source-diff): File contains standard ESM imports of known libraries for code analysis; no actual dropper/loader pattern present. ai
source-diff net-exec-file:dist/chunk-RFYF7TJS.js AI (source-diff): Bundled CLI tool; chunk imports are standard analysis libraries (zod, tree-sitter, eslint-parser), not malicious network+exec patterns. ai
source-diff net-exec-file:dist/chunk-MAFI6UWT.js AI (source-diff): Chunk imports are standard Node.js/ESM utilities (crypto, fs, path, zod, tree-sitter); consistent with a code-analysis CLI, not malware. ai
dependencies unvetted-dep:handlebars AI (dependencies): handlebars is a widely-used, well-maintained templating library; stable false positive for this package. ai
source-diff net-exec-file:dist/chunk-YYRQCQPZ.js AI (source-diff): Chunk contains legitimate CLI/analysis tooling code; SLSA provenance confirms CI/CD build integrity. ai
phantom-deps phantom-dep:tree-sitter-wasms AI (phantom-deps): Platform-specific binary package; phantom-dep heuristic is a known false positive for this type of dep. ai
phantom-deps phantom-dep:@harness-engineering/linter-gen AI (phantom-deps): Same-org monorepo dep; may be used indirectly or loaded at runtime without direct import. ai
phantom-deps phantom-dep:@harness-engineering/dashboard AI (phantom-deps): Same-org monorepo dep; may be used indirectly or loaded at runtime without direct import. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped org package @harness-engineering/cli cannot plausibly typosquat the unscoped 'joi'; levenshtein match is spurious. ai

Versions (showing 35 of 35)

Version Deps Published
4.2.0 24 / 5
4.0.1 23 / 5
2.6.1 22 / 5
2.5.0 22 / 5
2.4.5 22 / 5
2.4.2 22 / 5
2.3.0 22 / 5
2.2.0 22 / 5
2.1.1 22 / 5
2.1.0 22 / 5
2.0.0 21 / 5
1.28.1 21 / 5
1.27.1 21 / 5
1.26.1 21 / 5
1.26.0 21 / 5
1.25.5 21 / 5
1.25.1 21 / 5
1.24.3 21 / 5
1.24.0 20 / 5
1.19.0 20 / 5
1.18.0 20 / 5
1.17.0 19 / 5
1.16.0 20 / 5
1.13.0 17 / 5
1.12.0 17 / 5
1.9.0 12 / 5
1.8.2 12 / 5
1.7.0 9 / 8
1.6.1 9 / 4
1.4.0 8 / 4
1.1.1 8 / 4
1.1.0 8 / 4
1.0.2 8 / 4
1.0.1 8 / 4
1.0.0 8 / 4

v4.2.0

2 findings
HIGH New file with network + code execution: dist/chunk-33OU3LYX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

3 findings
HIGH Publisher changed: intense.visions → GitHub Actions (on 2026-07-01) provenance

This version was published by a different npm account than previous versions on 2026-07-01. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: dist/chunk-MMLQPHZ5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.