@lightdash/cli
Lightdash CLI tool
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): ajv-formats is a peer/plugin of ajv; loaded by convention, not direct import. Stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/columnify | AI (dependencies): @types/columnify is a type-definition-only package with no runtime impact; stable false positive for this package. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Runs bundled track.sh for install telemetry; file is explicitly listed in package files, not a remote fetch. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Same track.sh telemetry pattern; stable across Lightdash CLI versions. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @lightdash/cli package; Levenshtein match to 'joi' is a false positive. | ai | |
| phantom-deps | phantom-dep:@types/columnify | AI (phantom-deps): @types packages are type-only and not directly imported at runtime; stable false positive for this package. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 0.3007.2 | 26 / 11 | |
| 0.2960.1 | 26 / 11 | |
| 0.2847.0 | 26 / 11 | |
| 0.2838.0 | 26 / 11 | |
| 0.1728.0 | 22 / 7 | |
| 0.1641.0 | 22 / 7 | |
| 0.1639.1 | 22 / 7 | |
| 0.1639.0 | 22 / 7 | |
| 0.1638.3 | 22 / 7 | |
| 0.1604.1 | 22 / 7 |
v0.3007.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2960.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1728.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1641.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1639.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1639.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1638.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1604.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.