← Home

@optimizely/ocp-cli-v2

Optimizely Connect Platform command line interface

10
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

optimizely-eng

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): yaml is a well-established package; addition is consistent with CLI feature expansion alongside existing js-yaml dep. ai
dependencies unvetted-dep:oclif AI (dependencies): oclif is a well-known CLI framework; its use here is expected and documented in package.json oclif config. ai
dependencies unvetted-dep:fast-levenshtein AI (dependencies): Widely-used string distance utility; no security concerns for this CLI package. ai
phantom-deps phantom-dep:@oclif/plugin-autocomplete AI (phantom-deps): Declared as oclif plugin in config block, not imported directly — standard oclif pattern. ai
phantom-deps phantom-dep:oclif AI (phantom-deps): oclif is referenced in oclif config block, not direct imports — expected pattern for oclif CLIs. ai
phantom-deps phantom-dep:@oclif/plugin-warn-if-update-available AI (phantom-deps): Declared as oclif plugin in config block, not imported directly — standard oclif pattern. ai
phantom-deps phantom-dep:deepmerge AI (phantom-deps): Used transitively via oclif config; not directly imported but legitimately declared. ai
phantom-deps phantom-dep:@oclif/plugin-update AI (phantom-deps): Declared as oclif plugin in config block, not imported directly — standard oclif pattern. ai

Versions (showing 10 of 10)

Version Deps Published
2.0.10 26 / 23
2.0.9 26 / 23
2.0.8 26 / 23
2.0.7 26 / 23
2.0.6 26 / 23
2.0.5 26 / 23
2.0.4 25 / 23
2.0.3 25 / 23
2.0.2 25 / 23
2.0.1 25 / 23

v2.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.