← Home

@n8n/node-cli

Official CLI for developing community nodes for n8n

35
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cornelius_n8n_ion8n-matsuuutomin8njan_n8n_ion8n-charliekolb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): eslint/@eslint/js are standard tooling matching this CLI's own eslint config exports. ai
publish-pattern rapid-publish AI (publish-pattern): Automated CI/CD publishing via GitHub Actions with SLSA provenance; rapid publish is expected behavior for this package. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation from n8n-io org; legitimate automation change. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are n8n org members; consistent with org-level team transition. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers part of same org transition; not indicative of hostile takeover given SLSA provenance. ai
phantom-deps phantom-dep:@n8n/eslint-plugin-community-nodes AI (phantom-deps): Same-org dep re-exported via ./eslint export path; not directly imported in source but legitimately bundled. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is a well-established templating library; pinned to 4.7.8 which has no active critical advisories. ai
dependencies unvetted-dep:eslint-plugin-n8n-nodes-base AI (dependencies): First-party n8n ESLint plugin; expected dependency for this CLI tool. ai
bogus-package bogus-package AI (bogus-package): Official n8n org CLI; README/keyword signals are false positives for a scoped monorepo package. ai
phantom-deps phantom-dep:prompts AI (phantom-deps): prompts is declared in dependencies; phantom-dep heuristic misfires on CLI tools using it indirectly. ai

Versions (showing 35 of 35)

Version Deps Published
0.41.2 18 / 8
0.41.1 18 / 8
0.41.0 18 / 8
0.40.3 18 / 7
0.40.2 18 / 7
0.40.1 18 / 7
0.40.0 18 / 7
0.39.3 18 / 7
0.39.2 18 / 7
0.39.1 18 / 7
0.38.8 18 / 7
0.38.7 18 / 7
0.38.5 18 / 7
0.36.1 16 / 8
0.33.1 16 / 8
0.33.0 16 / 8
0.32.1 16 / 8
0.31.1 16 / 8
0.31.0 16 / 8
0.30.1 16 / 8
0.28.0 16 / 8
0.27.0 16 / 8
0.25.0 16 / 8
0.24.0 16 / 8
0.22.0 16 / 8
0.18.0 15 / 8
0.17.2 15 / 8
0.17.1 15 / 8
0.16.0 15 / 8
0.15.0 15 / 8
0.10.0 15 / 7
0.9.0 14 / 7
0.2.0 14 / 7
0.1.1 14 / 7
0.1.0 7 / 12

v0.41.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.41.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.40.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.40.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.40.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.40.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.39.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.39.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.39.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.38.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.38.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.38.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.