@kb-labs/cli-bin
KB Labs CLI tool for project management and automation
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Publisher has 1099 approved packages; likely a CI environment change rather than a supply chain concern. | ai | |
| dependencies | unvetted-dep:@kb-labs/plugin-manifest | AI (dependencies): link: protocol monorepo workspace dep; not a registry dependency, no supply-chain risk. | ai | |
| phantom-deps | phantom-dep:@kb-labs/core-config | AI (phantom-deps): Same-org monorepo dep; phantom-dep heuristic is a stable false positive. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Same as above — bundled CLI pattern. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): Same as above — bundled CLI pattern. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Same as above — bundled CLI pattern. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Same as above — bundled CLI pattern. | ai | |
| phantom-deps | phantom-dep:colorette | AI (phantom-deps): Same as above — bundled CLI pattern. | ai | |
| phantom-deps | phantom-dep:cli-table3 | AI (phantom-deps): Same as above — bundled CLI pattern. | ai | |
| phantom-deps | phantom-dep:@kb-labs/core-sandbox | AI (phantom-deps): Same-org dep consumed transitively in bundled output; stable false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/plugin-runtime | AI (phantom-deps): Same-org dep consumed transitively in bundled output; stable false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/shared-command-kit | AI (phantom-deps): Same-org dep consumed transitively in bundled output; stable false positive. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Same as above — bundled CLI pattern. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Bundled CLI; deps consumed transitively, not directly imported. Stable false positive for this package. | ai |
Versions (showing 51 of 79)
| Version | Deps | Published |
|---|---|---|
| 2.94.0 | 18 / 8 | |
| 2.93.0 | 18 / 8 | |
| 2.89.2 | 18 / 8 | |
| 2.89.1 | 18 / 8 | |
| 2.89.0 | 18 / 8 | |
| 2.88.0 | 18 / 8 | |
| 2.87.0 | 18 / 8 | |
| 2.82.0 | 18 / 8 | |
| 2.81.0 | 18 / 8 | |
| 2.80.0 | 18 / 8 | |
| 2.79.0 | 18 / 8 | |
| 2.78.0 | 18 / 8 | |
| 2.77.0 | 18 / 8 | |
| 2.76.0 | 18 / 8 | |
| 2.75.0 | 18 / 8 | |
| 2.74.0 | 18 / 8 | |
| 2.73.0 | 18 / 8 | |
| 2.72.0 | 18 / 8 | |
| 2.69.0 | 18 / 8 | |
| 2.68.0 | 18 / 8 | |
| 2.67.0 | 18 / 8 | |
| 2.66.0 | 18 / 8 | |
| 2.65.0 | 18 / 8 | |
| 2.64.0 | 18 / 8 | |
| 2.63.0 | 18 / 8 | |
| 2.62.0 | 18 / 8 | |
| 2.61.0 | 18 / 8 | |
| 2.60.0 | 18 / 8 | |
| 2.59.0 | 18 / 8 | |
| 2.58.0 | 18 / 8 | |
| 2.57.0 | 18 / 8 | |
| 2.56.0 | 18 / 8 | |
| 2.55.0 | 18 / 8 | |
| 2.54.0 | 18 / 8 | |
| 2.53.0 | 18 / 8 | |
| 2.47.0 | 18 / 8 | |
| 2.46.0 | 18 / 8 | |
| 2.45.0 | 18 / 8 | |
| 2.44.0 | 18 / 8 | |
| 2.43.0 | 18 / 8 | |
| 2.42.0 | 18 / 8 | |
| 2.41.0 | 18 / 8 | |
| 2.40.0 | 18 / 8 | |
| 2.39.0 | 18 / 8 | |
| 2.38.0 | 18 / 8 | |
| 2.37.0 | 18 / 8 | |
| 2.36.0 | 18 / 8 | |
| 2.35.0 | 18 / 8 | |
| 2.34.0 | 18 / 8 | |
| 2.33.0 | 18 / 8 | |
| 2.32.0 | 18 / 8 |
v2.94.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.93.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.89.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.89.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.89.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.88.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.87.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.82.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.81.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.80.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.79.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.78.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.77.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.76.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.75.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.74.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.73.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.72.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.69.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.68.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.67.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.66.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.65.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.63.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.62.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.61.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.60.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.59.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.58.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.57.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.56.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.55.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.54.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.53.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.47.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.46.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.45.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.44.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.43.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.42.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.33.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.