← Home

@heroku-cli/color

17
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sbosio_sfk80bowmaneblackmarsheroku-johnnymichael.malaveerika.wallace

Keywords

herokuheroku-cli-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-takeover AI (maintainer-change): Transition from individual maintainers to a large Heroku/Salesforce team is consistent with corporate ownership transfer, not a malicious hijack. New maintainer list matches known Heroku CLI contributors. ai
provenance publisher-changed AI (provenance): Publisher change dickeyxxx→rasphilco occurred in Jan 2018 (7+ years ago), rasphilco has strong track record (873 approved), settled Heroku org transition. ai
maintainer-change maintainer-added AI (maintainer-change): rasphilco is a long-standing publisher with strong track record; this is a historical Heroku org maintainer transition, not a suspicious takeover. ai
publish-pattern new-deps-added AI (publish-pattern): strip-ansi is a well-known, widely-trusted sindresorhus package; its addition is consistent with this CLI color utility's purpose. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): chalk is an explicit runtime dependency used for color output; phantom-dep flag is a false positive for this package. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is an explicit runtime dependency; phantom-dep flag is a false positive for this package. ai
phantom-deps phantom-dep:ansi-styles AI (phantom-deps): ansi-styles is an explicit runtime dependency used for color manipulation; phantom-dep flag is a false positive. ai
phantom-deps phantom-dep:supports-color AI (phantom-deps): supports-color is an explicit runtime dependency; phantom-dep flag is a false positive for this package. ai

Versions (showing 17 of 17)

Version Deps Published
2.0.7 4 / 9
2.0.6 4 / 9
2.0.5 4 / 9
2.0.4 4 / 9
2.0.3 4 / 9
2.0.2 4 / 9
2.0.1 4 / 11
2.0.0 4 / 11
1.1.15 5 / 13
1.1.9 5 / 16
1.1.3 4 / 15
1.1.2 4 / 15
1.1.1 4 / 15
1.1.0 4 / 15
1.0.5 4 / 9
1.0.4 3 / 9
1.0.3 3 / 9

v2.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.