@plasmicapp/cli
plasmic cli for syncing local code with Plasmic designs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@plasmicapp/react-web | AI (phantom-deps): Same-org sibling package, expected dependency. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): chalk is a standard CLI color dep, likely used indirectly; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/socket.io-client | AI (phantom-deps): Types-only package, not expected to be directly imported. | ai | |
| dependencies | unvetted-dep:@plasmicapp/code-merger | AI (dependencies): First-party sibling package from same publisher/org. | ai | |
| phantom-deps | phantom-dep:fast-glob | AI (phantom-deps): Likely used via dynamic/glob resolution; stable FP for this CLI package. | ai | |
| phantom-deps | phantom-dep:latest-version | AI (phantom-deps): Update-notifier related dep, plausibly used indirectly; stable FP. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @plasmicapp/cli; Levenshtein match to 'joi' is a false positive with no brand impersonation. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads user's next.config.js to detect Next.js version; standard CLI config detection pattern. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes image asset blobs to write to disk; legitimate CLI export functionality. | ai |
Versions (showing 43 of 143)
| Version | Deps | Published |
|---|---|---|
| 0.1.209 | 29 / 26 | |
| 0.1.208 | 29 / 26 | |
| 0.1.206 | 29 / 26 | |
| 0.1.205 | 29 / 26 | |
| 0.1.204 | 29 / 26 | |
| 0.1.203 | 29 / 26 | |
| 0.1.202 | 29 / 26 | |
| 0.1.201 | 29 / 26 | |
| 0.1.200 | 29 / 26 | |
| 0.1.199 | 29 / 26 | |
| 0.1.198 | 29 / 26 | |
| 0.1.197 | 29 / 26 | |
| 0.1.196 | 29 / 26 | |
| 0.1.195 | 29 / 26 | |
| 0.1.194 | 29 / 26 | |
| 0.1.193 | 29 / 26 | |
| 0.1.192 | 29 / 26 | |
| 0.1.186 | 31 / 26 | |
| 0.1.182 | 31 / 26 | |
| 0.1.180 | 31 / 26 | |
| 0.1.176 | 31 / 26 | |
| 0.1.166 | 31 / 26 | |
| 0.1.165 | 31 / 26 | |
| 0.1.158 | 29 / 26 | |
| 0.1.157 | 29 / 26 | |
| 0.1.156 | 29 / 26 | |
| 0.1.155 | 29 / 26 | |
| 0.1.67 | 24 / 25 | |
| 0.1.65 | 24 / 25 | |
| 0.1.57 | 30 / 21 | |
| 0.1.5 | 14 / 11 | |
| 0.1.4 | 14 / 11 | |
| 0.1.3 | 14 / 11 | |
| 0.1.2 | 14 / 11 | |
| 0.1.1 | 14 / 11 | |
| 0.1.0 | 14 / 11 | |
| 0.0.9 | 14 / 11 | |
| 0.0.8 | 14 / 11 | |
| 0.0.7 | 12 / 11 | |
| 0.0.5 | 12 / 11 | |
| 0.0.4 | 9 / 9 | |
| 0.0.3 | 9 / 9 | |
| 0.0.2 | 9 / 9 |
v0.1.209
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.208
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.206
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.205
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.204
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.203
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.202
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.201
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.200
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.199
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.198
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.197
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.196
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.195
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.194
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.193
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.192
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.186
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.182
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.180
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.176
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.166
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.165
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.158
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.157
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.156
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.155
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.67
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.65
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.57
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.