@optimizely/ocp-cli-v2
Optimizely Connect Platform command line interface
10
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
optimizely-eng
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): yaml is a well-established package; addition is consistent with CLI feature expansion alongside existing js-yaml dep. | ai | |
| dependencies | unvetted-dep:oclif | AI (dependencies): oclif is a well-known CLI framework; its use here is expected and documented in package.json oclif config. | ai | |
| dependencies | unvetted-dep:fast-levenshtein | AI (dependencies): Widely-used string distance utility; no security concerns for this CLI package. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-autocomplete | AI (phantom-deps): Declared as oclif plugin in config block, not imported directly — standard oclif pattern. | ai | |
| phantom-deps | phantom-dep:oclif | AI (phantom-deps): oclif is referenced in oclif config block, not direct imports — expected pattern for oclif CLIs. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-warn-if-update-available | AI (phantom-deps): Declared as oclif plugin in config block, not imported directly — standard oclif pattern. | ai | |
| phantom-deps | phantom-dep:deepmerge | AI (phantom-deps): Used transitively via oclif config; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-update | AI (phantom-deps): Declared as oclif plugin in config block, not imported directly — standard oclif pattern. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 2.0.10 | 26 / 23 | |
| 2.0.9 | 26 / 23 | |
| 2.0.8 | 26 / 23 | |
| 2.0.7 | 26 / 23 | |
| 2.0.6 | 26 / 23 | |
| 2.0.5 | 26 / 23 | |
| 2.0.4 | 25 / 23 | |
| 2.0.3 | 25 / 23 | |
| 2.0.2 | 25 / 23 | |
| 2.0.1 | 25 / 23 |
v2.0.10
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.9
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.