@lightdash/cli
Lightdash CLI tool
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/nunjucks | AI (phantom-deps): Type-only dep used by convention, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/inquirer | AI (phantom-deps): Type-only dep used by convention, not directly imported. | ai | |
| provenance | publisher-changed | AI (provenance): CI/CD publisher transition with SLSA provenance, an improvement not a compromise. | ai | |
| install-behavior | install-behavior:native-compile | AI (install-behavior): Misclassified telemetry script (curl uuid + platform detection), no compilation occurs. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @aws-sdk/credential-providers is a well-known official AWS package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large diff vs an old baseline reflects normal feature growth over many skipped versions. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): ajv-formats is a peer/plugin of ajv; loaded by convention, not direct import. Stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/columnify | AI (dependencies): @types/columnify is a type-definition-only package with no runtime impact; stable false positive for this package. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Runs bundled track.sh for install telemetry; file is explicitly listed in package files, not a remote fetch. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @lightdash/cli package; Levenshtein match to 'joi' is a false positive. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Same track.sh telemetry pattern; stable across Lightdash CLI versions. | ai | |
| phantom-deps | phantom-dep:@types/columnify | AI (phantom-deps): @types packages are type-only and not directly imported at runtime; stable false positive for this package. | ai |
Versions (showing 100 of 107)
| Version | Deps | Published |
|---|---|---|
| 1.5.1 | 27 / 14 | |
| 1.5.0 | 27 / 14 | |
| 1.4.1 | 27 / 14 | |
| 1.4.0 | 27 / 14 | |
| 1.3.0 | 27 / 14 | |
| 1.2.0 | 27 / 14 | |
| 0.3429.1 | 27 / 14 | |
| 0.3327.0 | 27 / 14 | |
| 0.3322.0 | 26 / 14 | |
| 0.3316.1 | 26 / 14 | |
| 0.3316.0 | 26 / 14 | |
| 0.3315.5 | 26 / 14 | |
| 0.3313.0 | 26 / 14 | |
| 0.3310.1 | 26 / 14 | |
| 0.3294.1 | 26 / 14 | |
| 0.3292.0 | 26 / 14 | |
| 0.3291.0 | 26 / 14 | |
| 0.3290.0 | 26 / 14 | |
| 0.3288.0 | 26 / 13 | |
| 0.3287.0 | 26 / 13 | |
| 0.3285.1 | 26 / 13 | |
| 0.3284.0 | 26 / 13 | |
| 0.3280.0 | 26 / 13 | |
| 0.3275.0 | 26 / 13 | |
| 0.3268.0 | 26 / 13 | |
| 0.3262.2 | 26 / 13 | |
| 0.3261.1 | 26 / 13 | |
| 0.3260.2 | 26 / 12 | |
| 0.3260.0 | 26 / 12 | |
| 0.3259.1 | 26 / 12 | |
| 0.3257.0 | 26 / 12 | |
| 0.3254.2 | 26 / 12 | |
| 0.3249.1 | 26 / 12 | |
| 0.3246.0 | 26 / 12 | |
| 0.3244.1 | 26 / 12 | |
| 0.3244.0 | 26 / 12 | |
| 0.3243.0 | 26 / 12 | |
| 0.3241.3 | 26 / 12 | |
| 0.3241.2 | 26 / 12 | |
| 0.3241.1 | 26 / 12 | |
| 0.3241.0 | 26 / 12 | |
| 0.3146.0 | 26 / 12 | |
| 0.3077.0 | 26 / 11 | |
| 0.3049.0 | 26 / 11 | |
| 0.3044.0 | 26 / 11 | |
| 0.3022.2 | 26 / 11 | |
| 0.3007.2 | 26 / 11 | |
| 0.2960.1 | 26 / 11 | |
| 0.2897.0 | 26 / 11 | |
| 0.2896.0 | 26 / 11 | |
| 0.2890.1 | 26 / 11 | |
| 0.2854.0 | 26 / 11 | |
| 0.2847.0 | 26 / 11 | |
| 0.2838.0 | 26 / 11 | |
| 0.2822.1 | 26 / 11 | |
| 0.2793.0 | 26 / 11 | |
| 0.2790.1 | 26 / 11 | |
| 0.2769.0 | 26 / 11 | |
| 0.2709.8 | 26 / 11 | |
| 0.1728.0 | 22 / 7 | |
| 0.1641.0 | 22 / 7 | |
| 0.1639.1 | 22 / 7 | |
| 0.1639.0 | 22 / 7 | |
| 0.1638.3 | 22 / 7 | |
| 0.1634.0 | 22 / 7 | |
| 0.1627.1 | 22 / 7 | |
| 0.1622.0 | 22 / 7 | |
| 0.1604.1 | 22 / 7 | |
| 0.130.0 | 15 / 13 | |
| 0.129.2 | 13 / 13 | |
| 0.129.1 | 13 / 13 | |
| 0.129.0 | 13 / 13 | |
| 0.128.0 | 13 / 13 | |
| 0.127.0 | 13 / 13 | |
| 0.126.3 | 13 / 13 | |
| 0.126.2 | 13 / 13 | |
| 0.126.1 | 13 / 13 | |
| 0.126.0 | 13 / 13 | |
| 0.125.0 | 13 / 13 | |
| 0.124.1 | 13 / 13 | |
| 0.124.0 | 13 / 13 | |
| 0.123.0 | 13 / 13 | |
| 0.122.0 | 13 / 13 | |
| 0.121.0 | 13 / 13 | |
| 0.120.1 | 13 / 13 | |
| 0.120.0 | 13 / 13 | |
| 0.119.3 | 13 / 13 | |
| 0.119.2 | 13 / 13 | |
| 0.119.1 | 13 / 13 | |
| 0.119.0 | 13 / 13 | |
| 0.118.1 | 13 / 13 | |
| 0.118.0 | 13 / 13 | |
| 0.117.0 | 13 / 13 | |
| 0.116.0 | 13 / 13 | |
| 0.115.2 | 13 / 13 | |
| 0.115.1 | 13 / 13 | |
| 0.115.0 | 13 / 13 | |
| 0.114.1 | 13 / 13 | |
| 0.114.0 | 13 / 13 | |
| 0.113.1 | 13 / 13 |
v1.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3429.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3327.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3322.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3316.1
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3316.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3315.5
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3313.0
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3310.1
2 findingsDetected raw native compilation in install lifecycle script(s): 'preinstall', 'postinstall'.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3294.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3292.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3291.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3290.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3288.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3287.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3285.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3284.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3280.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3275.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3268.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3262.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3261.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3260.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3260.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3259.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3049.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3022.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2854.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2822.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2793.0
2 findingsThis version was published by a different npm account than previous versions on 2026-04-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2790.1
2 findingsThis version was published by a different npm account than previous versions on 2026-04-23. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2769.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-04-20. This could indicate a legitimate maintainer transition or an account compromise.
v0.2709.8
2 findingsThis version was published by a different npm account than previous versions on 2026-04-02. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1634.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1627.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1622.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.130.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.129.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.129.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.129.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.128.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.127.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.126.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.126.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.126.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.126.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.125.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.124.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.124.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.123.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.122.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.121.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.120.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.120.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.119.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.118.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.118.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.117.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.116.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.115.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.115.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (owlas) than the most recent previously approved version (ligthdash_javier) on 2022-05-24, but owlas is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.115.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.114.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ligthdash_javier) than the most recent previously approved version (owlas) on 2022-05-24, but ligthdash_javier is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.114.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.113.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.