← Home

@lightdash/cli

Lightdash CLI tool

7
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

ligthdash_javierjose-lightdashowlaslight-irakli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@types/nunjucks AI (phantom-deps): Type-only dep used by convention, not directly imported. ai
phantom-deps phantom-dep:@types/inquirer AI (phantom-deps): Type-only dep used by convention, not directly imported. ai
provenance publisher-changed AI (provenance): CI/CD publisher transition with SLSA provenance, an improvement not a compromise. ai
install-behavior install-behavior:native-compile AI (install-behavior): Misclassified telemetry script (curl uuid + platform detection), no compilation occurs. ai
publish-pattern new-deps-added AI (publish-pattern): @aws-sdk/credential-providers is a well-known official AWS package. ai
source-diff large-new-source-files AI (source-diff): Large diff vs an old baseline reflects normal feature growth over many skipped versions. ai
phantom-deps phantom-dep:ajv-formats AI (phantom-deps): ajv-formats is a peer/plugin of ajv; loaded by convention, not direct import. Stable false positive for this package. ai
dependencies unvetted-dep:@types/columnify AI (dependencies): @types/columnify is a type-definition-only package with no runtime impact; stable false positive for this package. ai
install-scripts install-script:preinstall AI (install-scripts): Runs bundled track.sh for install telemetry; file is explicitly listed in package files, not a remote fetch. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @lightdash/cli package; Levenshtein match to 'joi' is a false positive. ai
install-scripts install-script:postinstall AI (install-scripts): Same track.sh telemetry pattern; stable across Lightdash CLI versions. ai
phantom-deps phantom-dep:@types/columnify AI (phantom-deps): @types packages are type-only and not directly imported at runtime; stable false positive for this package. ai

Versions (showing 7 of 112)

Version Deps Published
0.113.0 13 / 13
0.112.0 13 / 13
0.111.0 13 / 13
0.110.1 1 / 13
0.110.0 1 / 13
0.109.6 1 / 13
0.109.5 1 / 13

v0.113.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.112.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.111.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.110.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.110.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.109.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.109.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.