@photon-ai/photon
Photon CLI — typed terminal UI for the Photon Dashboard. Binary: `photon` (alias `pho`).
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:open | AI (phantom-deps): CLI tool; open is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): CLI tool; commander is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:cli-table3 | AI (phantom-deps): CLI tool; cli-table3 is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:picocolors | AI (phantom-deps): CLI tool; picocolors is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:better-auth | AI (phantom-deps): CLI tool; better-auth is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:@clack/prompts | AI (phantom-deps): CLI tool; @clack/prompts is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:@elysiajs/eden | AI (phantom-deps): CLI tool; @elysiajs/eden is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:update-notifier | AI (phantom-deps): CLI tool; update-notifier is used in config initialization, not direct imports. | ai | |
| phantom-deps | phantom-dep:@commander-js/extra-typings | AI (phantom-deps): CLI tool; @commander-js/extra-typings is used in config initialization, not direct imports. | ai |
v0.1.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.