@open-mercato/cli
The command-line toolbox for Open Mercato developers.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-bulk-read | AI (semgrep): Config init snapshot of env in a CLI entrypoint; benign. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Referenced in config, not imported; stable FP. | ai | |
| provenance | missing-githead | AI (provenance): Superseded by IMPROVED provenance direction (manual->CI/CD attested) this version. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads user-defined module registry index files; documented plugin-loader pattern for this CLI tool. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Appears in a test file as a SQL injection / path traversal test vector, not actual credential harvesting. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @open-mercato/cli is not a plausible typosquat of joi; edit distance comparison is misleading here. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All raw IPs are localhost (127.0.0.1) in test files; not external exfiltration. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Occurs in integration test helpers passing env to child processes; not production credential exfiltration. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 0.6.6 | 13 / 4 | |
| 0.6.5 | 13 / 4 | |
| 0.6.4 | 13 / 4 | |
| 0.6.3 | 13 / 4 | |
| 0.6.2 | 13 / 4 | |
| 0.6.1 | 13 / 4 | |
| 0.6.0 | 13 / 4 | |
| 0.4.10 | 8 / 4 | |
| 0.4.9 | 8 / 4 | |
| 0.4.8 | 7 / 4 | |
| 0.4.7 | 7 / 4 | |
| 0.4.6 | 7 / 3 | |
| 0.4.5 | 7 / 3 |
v0.6.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: piotrkarwatka.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: piotrkarwatka.