← Home

@open-mercato/cli

The command-line toolbox for Open Mercato developers.

13
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

pat-lewczukpatryk.andrzejewskipiotrkarwatka

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-bulk-read AI (semgrep): Config init snapshot of env in a CLI entrypoint; benign. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Referenced in config, not imported; stable FP. ai
provenance missing-githead AI (provenance): Superseded by IMPROVED provenance direction (manual->CI/CD attested) this version. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-defined module registry index files; documented plugin-loader pattern for this CLI tool. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Appears in a test file as a SQL injection / path traversal test vector, not actual credential harvesting. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package @open-mercato/cli is not a plausible typosquat of joi; edit distance comparison is misleading here. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): All raw IPs are localhost (127.0.0.1) in test files; not external exfiltration. ai
semgrep semgrep:env-spread AI (semgrep): Occurs in integration test helpers passing env to child processes; not production credential exfiltration. ai

Versions (showing 13 of 13)

Version Deps Published
0.6.6 13 / 4
0.6.5 13 / 4
0.6.4 13 / 4
0.6.3 13 / 4
0.6.2 13 / 4
0.6.1 13 / 4
0.6.0 13 / 4
0.4.10 8 / 4
0.4.9 8 / 4
0.4.8 7 / 4
0.4.7 7 / 4
0.4.6 7 / 3
0.4.5 7 / 3

v0.6.6

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: piotrkarwatka.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: piotrkarwatka.