@lightdash/cli
Lightdash CLI tool
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/nunjucks | AI (phantom-deps): Type-only dep used by convention, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/inquirer | AI (phantom-deps): Type-only dep used by convention, not directly imported. | ai | |
| provenance | publisher-changed | AI (provenance): CI/CD publisher transition with SLSA provenance, an improvement not a compromise. | ai | |
| install-behavior | install-behavior:native-compile | AI (install-behavior): Misclassified telemetry script (curl uuid + platform detection), no compilation occurs. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @aws-sdk/credential-providers is a well-known official AWS package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large diff vs an old baseline reflects normal feature growth over many skipped versions. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): ajv-formats is a peer/plugin of ajv; loaded by convention, not direct import. Stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/columnify | AI (dependencies): @types/columnify is a type-definition-only package with no runtime impact; stable false positive for this package. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Runs bundled track.sh for install telemetry; file is explicitly listed in package files, not a remote fetch. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @lightdash/cli package; Levenshtein match to 'joi' is a false positive. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Same track.sh telemetry pattern; stable across Lightdash CLI versions. | ai | |
| phantom-deps | phantom-dep:@types/columnify | AI (phantom-deps): @types packages are type-only and not directly imported at runtime; stable false positive for this package. | ai |
Versions (showing 51 of 101)
| Version | Deps | Published |
|---|---|---|
| 0.3429.1 | 27 / 14 | |
| 0.3327.0 | 27 / 14 | |
| 0.3322.0 | 26 / 14 | |
| 0.3316.1 | 26 / 14 | |
| 0.3316.0 | 26 / 14 | |
| 0.3315.5 | 26 / 14 | |
| 0.3313.0 | 26 / 14 | |
| 0.3310.1 | 26 / 14 | |
| 0.3294.1 | 26 / 14 | |
| 0.3292.0 | 26 / 14 | |
| 0.3291.0 | 26 / 14 | |
| 0.3290.0 | 26 / 14 | |
| 0.3288.0 | 26 / 13 | |
| 0.3287.0 | 26 / 13 | |
| 0.3285.1 | 26 / 13 | |
| 0.3284.0 | 26 / 13 | |
| 0.3280.0 | 26 / 13 | |
| 0.3275.0 | 26 / 13 | |
| 0.3268.0 | 26 / 13 | |
| 0.3262.2 | 26 / 13 | |
| 0.3261.1 | 26 / 13 | |
| 0.3260.2 | 26 / 12 | |
| 0.3260.0 | 26 / 12 | |
| 0.3259.1 | 26 / 12 | |
| 0.3257.0 | 26 / 12 | |
| 0.3254.2 | 26 / 12 | |
| 0.3249.1 | 26 / 12 | |
| 0.3246.0 | 26 / 12 | |
| 0.3244.1 | 26 / 12 | |
| 0.3244.0 | 26 / 12 | |
| 0.3243.0 | 26 / 12 | |
| 0.3241.3 | 26 / 12 | |
| 0.3241.2 | 26 / 12 | |
| 0.3241.1 | 26 / 12 | |
| 0.3241.0 | 26 / 12 | |
| 0.3146.0 | 26 / 12 | |
| 0.3077.0 | 26 / 11 | |
| 0.3049.0 | 26 / 11 | |
| 0.3044.0 | 26 / 11 | |
| 0.3022.2 | 26 / 11 | |
| 0.3007.2 | 26 / 11 | |
| 0.2960.1 | 26 / 11 | |
| 0.2897.0 | 26 / 11 | |
| 0.2896.0 | 26 / 11 | |
| 0.2890.1 | 26 / 11 | |
| 0.2854.0 | 26 / 11 | |
| 0.2847.0 | 26 / 11 | |
| 0.2838.0 | 26 / 11 | |
| 0.2822.1 | 26 / 11 | |
| 0.2793.0 | 26 / 11 | |
| 0.2790.1 | 26 / 11 |
v0.3429.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3327.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3322.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3316.1
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3316.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3315.5
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3313.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3310.1
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3294.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3292.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3291.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3290.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3288.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3287.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3285.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3284.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3280.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3275.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3268.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3262.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3261.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3260.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3260.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3259.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3049.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3022.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2854.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2822.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2793.0
2 findingsThis version was published by a different npm account than previous versions on 2026-04-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2790.1
2 findingsThis version was published by a different npm account than previous versions on 2026-04-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.