← Home

@netlify/agent-runner-cli

CLI tool for running Netlify agents

11
Versions
MIT
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

seanrobertsbiilmanneduardoboucasnetlify-botsarahettermikewenkathmbeckhrishikeshkvitaliyrberdavyouvalvserhalp-netlifydomitriusanthonyakardettbarnseancdavismlgualtieri-gatsby

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:fastify AI (phantom-deps): fastify is a legitimate dep referenced in config files; consistent with other accepted phantom-deps in this package. ai
provenance no-provenance AI (provenance): Netlify internal tooling published via netlify-bot; provenance not yet enabled but publisher track record is strong. ai
bogus-package bogus-package AI (bogus-package): Internal Netlify CLI tool; sparse README/keywords expected for org-internal tooling. ai
phantom-deps phantom-dep:@netlify/otel AI (phantom-deps): Framework-scoped telemetry package loaded by convention; stable FP. ai
phantom-deps phantom-dep:@openai/codex AI (phantom-deps): Agent runner spawns codex as subprocess; not directly imported by design. ai
phantom-deps phantom-dep:@netlify/ts-cli AI (phantom-deps): Framework-scoped Netlify dep; stable FP for this package. ai
phantom-deps phantom-dep:@anthropic-ai/sdk AI (phantom-deps): AI SDK loaded by convention in agent runner; stable FP. ai
install-scripts install-script:postinstall AI (install-scripts): Netlify org package; postinstall runs a local script, consistent with build/setup tooling across all versions. ai
phantom-deps phantom-dep:@netlify/database-proxy AI (phantom-deps): Framework-scoped Netlify dep; stable FP for this package. ai
phantom-deps phantom-dep:@anthropic-ai/claude-code AI (phantom-deps): Agent runner spawns claude-code; not directly imported by design. ai
phantom-deps phantom-dep:@opentelemetry/exporter-trace-otlp-grpc AI (phantom-deps): OTel exporter loaded by convention via @netlify/otel; stable FP. ai
phantom-deps phantom-dep:@google/gemini-cli AI (phantom-deps): Agent runner spawns gemini-cli; not directly imported by design. ai
phantom-deps phantom-dep:openai AI (phantom-deps): AI SDK loaded by convention/config in agent runner; not a direct import by design. ai
phantom-deps phantom-dep:minimist AI (phantom-deps): CLI utility dep referenced in config; stable false positive for this package. ai

Versions (showing 11 of 11)

Version Deps Published
1.120.0 11 / 20
1.118.1 11 / 18
1.118.0 11 / 18
1.115.0 11 / 18
1.114.0 11 / 18
1.113.1 11 / 18
1.111.2 11 / 18
1.105.0 11 / 18
1.98.1 10 / 18
1.97.0 10 / 18
1.95.0 10 / 18

v1.120.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.118.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.118.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.115.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.114.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.111.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.105.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.98.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.97.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.95.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.