@infernetprotocol/cli
GPU-node CLI / daemon for the Infernet Protocol — register a GPU server with a Supabase control plane and start earning.
20
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
chovy
Keywords
infernetgpuinferencep2pcryptoclidaemon
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is the publisher's own package, part of monorepo split. | ai | |
| dependencies | unvetted-dep:@infernetprotocol/discovery | AI (dependencies): First-party monorepo sibling pinned to same version. | ai | |
| dependencies | unvetted-dep:@infernetprotocol/rpc-adapter | AI (dependencies): First-party monorepo sibling pinned to same version. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv is declared in dependencies and used via config files; stable false positive. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode in nip44.js is part of NIP-44 crypto protocol implementation, not payload hiding. | ai | |
| semgrep | semgrep:silent-process-exec | AI (semgrep): Detached spawn opens a browser URL for OAuth login flow; not a reverse shell or miner. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @infernetprotocol/cli is not impersonating joi; Levenshtein match is a false positive. | ai | |
| semgrep | semgrep:silent-process-exec-var | AI (semgrep): Same browser-open pattern; stable false positive for this CLI package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Passing process.env to a daemon subprocess is expected behavior for a GPU daemon CLI. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): 127.0.0.1 is a localhost default for self-hosted Supabase; not an exfiltration endpoint. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 0.1.46 | 14 / 0 | |
| 0.1.45 | 15 / 0 | |
| 0.1.41 | 13 / 0 | |
| 0.1.40 | 13 / 0 | |
| 0.1.39 | 13 / 0 | |
| 0.1.38 | 13 / 0 | |
| 0.1.37 | 13 / 0 | |
| 0.1.36 | 13 / 0 | |
| 0.1.35 | 13 / 0 | |
| 0.1.34 | 13 / 0 | |
| 0.1.33 | 13 / 0 | |
| 0.1.32 | 13 / 0 | |
| 0.1.31 | 13 / 0 | |
| 0.1.30 | 13 / 0 | |
| 0.1.29 | 13 / 0 | |
| 0.1.28 | 13 / 0 | |
| 0.1.27 | 13 / 0 | |
| 0.1.26 | 13 / 0 | |
| 0.1.25 | 13 / 0 | |
| 0.1.22 | 13 / 0 |
v0.1.46
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.45
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.