@lightdash/cli
Lightdash CLI tool
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@types/nunjucks | AI (phantom-deps): Type-only dep used by convention, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/inquirer | AI (phantom-deps): Type-only dep used by convention, not directly imported. | ai | |
| provenance | publisher-changed | AI (provenance): CI/CD publisher transition with SLSA provenance, an improvement not a compromise. | ai | |
| install-behavior | install-behavior:native-compile | AI (install-behavior): Misclassified telemetry script (curl uuid + platform detection), no compilation occurs. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @aws-sdk/credential-providers is a well-known official AWS package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large diff vs an old baseline reflects normal feature growth over many skipped versions. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): ajv-formats is a peer/plugin of ajv; loaded by convention, not direct import. Stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/columnify | AI (dependencies): @types/columnify is a type-definition-only package with no runtime impact; stable false positive for this package. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Runs bundled track.sh for install telemetry; file is explicitly listed in package files, not a remote fetch. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @lightdash/cli package; Levenshtein match to 'joi' is a false positive. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Same track.sh telemetry pattern; stable across Lightdash CLI versions. | ai | |
| phantom-deps | phantom-dep:@types/columnify | AI (phantom-deps): @types packages are type-only and not directly imported at runtime; stable false positive for this package. | ai |
Versions (showing 7 of 112)
| Version | Deps | Published |
|---|---|---|
| 0.113.0 | 13 / 13 | |
| 0.112.0 | 13 / 13 | |
| 0.111.0 | 13 / 13 | |
| 0.110.1 | 1 / 13 | |
| 0.110.0 | 1 / 13 | |
| 0.109.6 | 1 / 13 | |
| 0.109.5 | 1 / 13 |
v0.113.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.112.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.111.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.110.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.109.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.109.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.