@n8n/node-cli
Official CLI for developing community nodes for n8n
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): eslint/@eslint/js are standard tooling matching this CLI's own eslint config exports. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD publishing via GitHub Actions with SLSA provenance; rapid publish is expected behavior for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation from n8n-io org; legitimate automation change. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are n8n org members; consistent with org-level team transition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removed maintainers part of same org transition; not indicative of hostile takeover given SLSA provenance. | ai | |
| phantom-deps | phantom-dep:@n8n/eslint-plugin-community-nodes | AI (phantom-deps): Same-org dep re-exported via ./eslint export path; not directly imported in source but legitimately bundled. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Handlebars is a well-established templating library; pinned to 4.7.8 which has no active critical advisories. | ai | |
| dependencies | unvetted-dep:eslint-plugin-n8n-nodes-base | AI (dependencies): First-party n8n ESLint plugin; expected dependency for this CLI tool. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Official n8n org CLI; README/keyword signals are false positives for a scoped monorepo package. | ai | |
| phantom-deps | phantom-dep:prompts | AI (phantom-deps): prompts is declared in dependencies; phantom-dep heuristic misfires on CLI tools using it indirectly. | ai |
Versions (showing 35 of 35)
| Version | Deps | Published |
|---|---|---|
| 0.41.2 | 18 / 8 | |
| 0.41.1 | 18 / 8 | |
| 0.41.0 | 18 / 8 | |
| 0.40.3 | 18 / 7 | |
| 0.40.2 | 18 / 7 | |
| 0.40.1 | 18 / 7 | |
| 0.40.0 | 18 / 7 | |
| 0.39.3 | 18 / 7 | |
| 0.39.2 | 18 / 7 | |
| 0.39.1 | 18 / 7 | |
| 0.38.8 | 18 / 7 | |
| 0.38.7 | 18 / 7 | |
| 0.38.5 | 18 / 7 | |
| 0.36.1 | 16 / 8 | |
| 0.33.1 | 16 / 8 | |
| 0.33.0 | 16 / 8 | |
| 0.32.1 | 16 / 8 | |
| 0.31.1 | 16 / 8 | |
| 0.31.0 | 16 / 8 | |
| 0.30.1 | 16 / 8 | |
| 0.28.0 | 16 / 8 | |
| 0.27.0 | 16 / 8 | |
| 0.25.0 | 16 / 8 | |
| 0.24.0 | 16 / 8 | |
| 0.22.0 | 16 / 8 | |
| 0.18.0 | 15 / 8 | |
| 0.17.2 | 15 / 8 | |
| 0.17.1 | 15 / 8 | |
| 0.16.0 | 15 / 8 | |
| 0.15.0 | 15 / 8 | |
| 0.10.0 | 15 / 7 | |
| 0.9.0 | 14 / 7 | |
| 0.2.0 | 14 / 7 | |
| 0.1.1 | 14 / 7 | |
| 0.1.0 | 7 / 12 |
v0.41.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.41.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.41.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.40.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.40.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.40.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.40.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.39.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.39.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.39.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.38.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.