← Home

@heroku-cli/command

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sbosio_sfk80bowmaneblackmarsheroku-johnnymichael.malaveerika.wallace

Keywords

heroku

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:dynamic-require AI (semgrep): Lazy-loading cache pattern in deps.js; stable and benign for this CLI utility package. ai
semgrep semgrep:child-process-import AI (semgrep): CLI tool executing git commands via child_process; expected and documented behavior. ai
semgrep semgrep:env-spread AI (semgrep): env-spread is in spawnSync call for secret-tool credential management — standard child process env passing, not exfiltration. ai
typosquat typosquat.levenshtein:commander AI (typosquat): Scoped @heroku-cli/command is the official Heroku CLI base class, not a typosquat of commander. ai

Versions (showing 20 of 20)

Version Deps Published
13.0.1 12 / 28
13.0.0 12 / 28
12.4.2 12 / 28
12.4.1 12 / 28
12.4.0 12 / 28
12.3.3 9 / 24
12.3.2 9 / 24
12.3.1 9 / 24
12.3.0 11 / 31
12.2.3 9 / 24
12.2.2 9 / 27
12.2.1 9 / 27
12.2.0 9 / 29
12.1.3 9 / 29
12.1.2 9 / 29
12.1.1 9 / 29
12.1.0 9 / 29
12.0.2 9 / 29
12.0.1 9 / 30
12.0.0 10 / 29

v13.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v13.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v12.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.