@mintlify/cli
The Mintlify CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is first-party sibling, not third-party supply chain risk. | ai | |
| dependencies | unvetted-dep:@mintlify/editor | AI (dependencies): First-party Mintlify monorepo sibling package. | ai | |
| phantom-deps | phantom-dep:remark-mdx | AI (phantom-deps): Remark plugin, false positive. | ai | |
| phantom-deps | phantom-dep:remark-frontmatter | AI (phantom-deps): Remark plugin, false positive. | ai | |
| phantom-deps | phantom-dep:unist-util-visit | AI (phantom-deps): Remark ecosystem util, false positive. | ai | |
| phantom-deps | phantom-dep:is-absolute-url | AI (phantom-deps): Small utility dep, false positive. | ai | |
| phantom-deps | phantom-dep:remark | AI (phantom-deps): Standard markdown processing dep, false positive. | ai | |
| phantom-deps | phantom-dep:inquirer | AI (phantom-deps): Standard CLI prompt lib, false positive. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Remark plugin, false positive. | ai | |
| phantom-deps | phantom-dep:@mintlify/models | AI (phantom-deps): Same-org dep used in compiled source. | ai | |
| phantom-deps | phantom-dep:@mintlify/validation | AI (phantom-deps): Same-org dep used in compiled source. | ai | |
| phantom-deps | phantom-dep:openapi-types | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:vfile | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:favicons | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:gray-matter | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:remark-math | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:@apidevtools/swagger-parser | AI (phantom-deps): Used in compiled TS source; heuristic misses tsc-built imports. | ai | |
| phantom-deps | phantom-dep:front-matter | AI (phantom-deps): Front-matter is used indirectly for configuration parsing; expected for documentation CLI. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Semver is used indirectly through dependency resolution; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Chalk is used indirectly through the CLI's output formatting; phantom dependency pattern is normal for CLI tools. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): References are in test files validating that path traversal to /etc/passwd is correctly rejected. Security test, not credential harvesting. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @mintlify/cli from established Mintlify org is not a typosquat of 'joi'. False positive from short name Levenshtein match. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Standard CLI pattern: spreading process.env into child process spawn to pass environment through. Not exfiltration. | ai |
Versions (showing 51 of 1335)
| Version | Deps | Published |
|---|---|---|
| 4.0.1344 | 34 / 19 | |
| 4.0.1343 | 34 / 19 | |
| 4.0.1342 | 34 / 19 | |
| 4.0.1341 | 34 / 19 | |
| 4.0.1340 | 34 / 19 | |
| 4.0.1339 | 25 / 17 | |
| 4.0.1338 | 25 / 17 | |
| 4.0.1337 | 25 / 17 | |
| 4.0.1336 | 25 / 17 | |
| 4.0.1335 | 26 / 17 | |
| 4.0.1334 | 25 / 17 | |
| 4.0.1333 | 25 / 17 | |
| 4.0.1332 | 25 / 17 | |
| 4.0.1331 | 25 / 17 | |
| 4.0.1330 | 25 / 17 | |
| 4.0.1329 | 25 / 17 | |
| 4.0.1328 | 25 / 17 | |
| 4.0.1327 | 25 / 17 | |
| 4.0.1326 | 25 / 17 | |
| 4.0.1325 | 25 / 17 | |
| 4.0.1324 | 25 / 17 | |
| 4.0.1323 | 25 / 17 | |
| 4.0.1322 | 25 / 17 | |
| 4.0.1321 | 25 / 17 | |
| 4.0.1320 | 25 / 17 | |
| 4.0.1319 | 25 / 17 | |
| 4.0.1318 | 25 / 17 | |
| 4.0.1317 | 25 / 17 | |
| 4.0.1316 | 25 / 17 | |
| 4.0.1315 | 25 / 17 | |
| 4.0.1314 | 25 / 17 | |
| 4.0.1313 | 25 / 17 | |
| 4.0.1312 | 25 / 17 | |
| 4.0.1311 | 25 / 17 | |
| 4.0.1310 | 25 / 17 | |
| 4.0.1309 | 25 / 17 | |
| 4.0.1308 | 25 / 17 | |
| 4.0.1307 | 25 / 17 | |
| 4.0.1306 | 25 / 17 | |
| 4.0.1305 | 25 / 17 | |
| 4.0.1304 | 25 / 17 | |
| 4.0.1303 | 25 / 17 | |
| 4.0.1302 | 25 / 17 | |
| 4.0.1301 | 25 / 17 | |
| 4.0.1300 | 25 / 17 | |
| 4.0.1299 | 25 / 17 | |
| 4.0.1298 | 25 / 17 | |
| 4.0.1297 | 25 / 17 | |
| 4.0.1296 | 25 / 17 | |
| 4.0.1295 | 25 / 17 | |
| 4.0.1294 | 25 / 17 |
v4.0.1344
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1343
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1342
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1341
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1340
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1339
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1338
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1337
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1336
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1335
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1334
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1333
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1332
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1331
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1330
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1329
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1328
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1327
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1326
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1325
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1324
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1323
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1322
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1321
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1320
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1319
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1318
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1317
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1316
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1315
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1314
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1313
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1312
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1311
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1310
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1309
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1308
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1307
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1306
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1305
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1304
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1303
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1302
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1301
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1300
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1299
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1298
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1297
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1296
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1295
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.1294
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.