@opentabs-dev/cli
CLI for OpenTabs — start the MCP server, manage plugins, and configure your AI agent browser bridge
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @opentabs-dev/cli; Levenshtein match to 'joi' is coincidental, not a squatting attempt. | ai | |
| phantom-deps | phantom-dep:@opentabs-dev/mcp-server | AI (phantom-deps): Same org scope; likely used transitively or via CLI dispatch rather than direct import. | ai | |
| phantom-deps | phantom-dep:@opentabs-dev/plugin-tools | AI (phantom-deps): Same org scope; phantom-dep heuristic unreliable for CLI packages with dynamic dispatch. | ai | |
| phantom-deps | phantom-dep:@opentabs-dev/browser-extension | AI (phantom-deps): Same org scope; consistent with CLI orchestrating browser extension assets. | ai |
Versions (showing 9 of 109)
| Version | Deps | Published |
|---|---|---|
| 0.0.9 | 5 / 1 | |
| 0.0.8 | 5 / 1 | |
| 0.0.7 | 5 / 1 | |
| 0.0.6 | 5 / 1 | |
| 0.0.5 | 5 / 1 | |
| 0.0.4 | 5 / 1 | |
| 0.0.3 | 5 / 1 | |
| 0.0.2 | 5 / 1 | |
| 0.0.1 | 5 / 1 |
v0.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.