@inkeep/agents-cli
Inkeep CLI tool
51
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
abraham-inkeepnick-inkeeprobert-inkeepsarah-inkeepandrew-inkeepomar-inkeepmiles-inkeep
Keywords
cliinkeepagent
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:keytar | AI (phantom-deps): keytar is a declared runtime dependency used via the postinstall script; phantom-dep heuristic is a false positive here. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs ensure-keytar.mjs to set up native keytar module; benign and consistent with keytar's documented install flow. | ai | |
| phantom-deps | phantom-dep:ts-morph | AI (phantom-deps): Code transform lib used indirectly; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:ast-types | AI (phantom-deps): Peer/transitive dep of recast; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/types | AI (phantom-deps): Framework-scoped, loaded by convention per analyzer note; stable false positive. | ai | |
| phantom-deps | phantom-dep:@inkeep/agents-manage-ui | AI (phantom-deps): Same org scope; may be loaded dynamically or via CLI dispatch; stable false positive. | ai | |
| phantom-deps | phantom-dep:inquirer-autocomplete-prompt | AI (phantom-deps): Inquirer plugin loaded by convention/registration; stable false positive. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): Framework-scoped, loaded by convention per analyzer note; stable false positive. | ai | |
| phantom-deps | phantom-dep:recast | AI (phantom-deps): AST transform lib likely used indirectly by build tooling; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ai | AI (phantom-deps): `ai` is explicitly listed in package.json dependencies; phantom-dep is a false positive here. | ai |
Versions (showing 51 of 174)
| Version | Deps | Published |
|---|---|---|
| 0.80.5 | 21 / 8 | |
| 0.80.4 | 21 / 8 | |
| 0.80.3 | 21 / 8 | |
| 0.80.2 | 21 / 8 | |
| 0.80.0 | 21 / 8 | |
| 0.79.1 | 21 / 8 | |
| 0.79.0 | 21 / 8 | |
| 0.78.5 | 21 / 8 | |
| 0.78.4 | 21 / 8 | |
| 0.78.3 | 21 / 8 | |
| 0.78.2 | 21 / 8 | |
| 0.78.1 | 21 / 8 | |
| 0.78.0 | 21 / 8 | |
| 0.77.1 | 21 / 8 | |
| 0.77.0 | 21 / 8 | |
| 0.75.4 | 21 / 8 | |
| 0.75.3 | 21 / 8 | |
| 0.75.0 | 21 / 8 | |
| 0.74.4 | 21 / 8 | |
| 0.74.3 | 21 / 8 | |
| 0.74.2 | 21 / 8 | |
| 0.74.1 | 21 / 8 | |
| 0.74.0 | 21 / 8 | |
| 0.73.5 | 21 / 8 | |
| 0.73.4 | 21 / 8 | |
| 0.73.3 | 21 / 8 | |
| 0.73.2 | 21 / 8 | |
| 0.73.1 | 21 / 8 | |
| 0.73.0 | 21 / 8 | |
| 0.72.2 | 21 / 8 | |
| 0.72.1 | 21 / 8 | |
| 0.72.0 | 21 / 8 | |
| 0.71.0 | 21 / 8 | |
| 0.70.8 | 21 / 8 | |
| 0.70.7 | 21 / 8 | |
| 0.70.5 | 21 / 8 | |
| 0.70.4 | 21 / 8 | |
| 0.70.3 | 21 / 8 | |
| 0.70.2 | 21 / 8 | |
| 0.70.1 | 21 / 8 | |
| 0.70.0 | 21 / 8 | |
| 0.69.0 | 21 / 8 | |
| 0.68.4 | 21 / 8 | |
| 0.68.3 | 21 / 8 | |
| 0.68.2 | 21 / 8 | |
| 0.68.1 | 21 / 8 | |
| 0.68.0 | 21 / 8 | |
| 0.67.4 | 21 / 8 | |
| 0.67.3 | 21 / 8 | |
| 0.67.2 | 21 / 8 | |
| 0.67.1 | 21 / 8 |
v0.80.5
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.4
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.3
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.