@pks-cli/cli
The next agentic CLI for .NET developers
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped CLI package for .NET devs; no semantic or brand overlap with joi validation library. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall selects platform-specific prebuilt binary from optional deps; standard pattern for cross-platform CLI tools. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used in CLI bin entry point to spawn the native binary; expected for this package type. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 6.13.0 | 0 / 0 | |
| 6.12.0 | 0 / 0 | |
| 6.11.0 | 0 / 0 | |
| 6.10.0 | 0 / 0 | |
| 6.5.2 | 0 / 0 | |
| 6.5.0 | 0 / 0 | |
| 6.3.0 | 0 / 0 |
v6.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.12.0
2 findingsScript: node postinstall.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.11.0
2 findingsScript: node postinstall.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.10.0
2 findingsScript: node postinstall.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.5.2
2 findingsScript: node postinstall.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.5.0
2 findingsScript: node postinstall.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.3.0
2 findingsScript: node postinstall.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.