← Home

@oclif/parser

arg and flag parser for oclif

44
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

rodespmdonnalleyrasphilcodickeyxxxamphrochadiansalesforce-releases

Keywords

oclif

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@heroku/linewrap AI (dependencies): @heroku/linewrap is from Heroku (reputable org); new dependency is legitimate for text wrapping in CLI parser. ai
provenance missing-githead AI (provenance): Long-standing oclif package from a trusted publisher; missing gitHead reflects a publish environment change, not a supply chain compromise. Stable judgment for this package. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are oclif team members consistent with the Salesforce/Heroku CLI org growth. Legitimate team expansion, not a takeover signal. ai
publish-pattern new-deps-added AI (publish-pattern): @oclif/errors is a first-party sibling package in the oclif org; adding it is low risk and consistent with the ecosystem's modular design. ai
provenance publisher-changed AI (provenance): Publisher change from oclif-bot to rasphilco occurred in 2018 and is a historical legitimate maintainer transition within the oclif org. rasphilco has a strong track record. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in deps.js is a standard caching pattern for optional dependencies in CLI tools; not a security risk. ai
typosquat typosquat.levenshtein:parcel AI (typosquat): Scoped @oclif/parser package with clear distinct purpose; no brand confusion or typosquat intent. ai

Versions (showing 44 of 44)

Version Deps Published
3.8.17 4 / 14
3.8.16 4 / 14
3.8.15 4 / 14
3.8.14 4 / 14
3.8.13 4 / 14
3.8.12 4 / 14
3.8.11 4 / 14
3.8.10 4 / 14
3.8.9 4 / 14
3.8.8 4 / 14
3.8.7 4 / 14
3.8.6 4 / 14
3.8.5 4 / 14
3.8.4 3 / 16
3.8.3 3 / 16
3.8.2 3 / 16
3.8.1 3 / 16
3.8.0 3 / 16
3.7.3 3 / 16
3.7.2 3 / 16
3.7.0 3 / 15
3.6.3 3 / 15
3.6.2 3 / 15
3.6.1 3 / 15
3.6.0 3 / 16
3.5.3 3 / 16
3.5.2 2 / 16
3.5.1 2 / 16
3.5.0 2 / 16
3.4.1 2 / 16
3.4.0 2 / 16
3.3.3 2 / 16
3.3.2 2 / 16
3.3.1 2 / 16
3.3.0 2 / 16
3.2.13 2 / 16
3.2.12 2 / 16
3.2.11 2 / 16
3.2.10 1 / 17
3.2.9 1 / 17
3.2.8 0 / 17
3.2.7 0 / 17
3.2.6 0 / 17
3.2.5 0 / 17