@poncho-ai/cli
CLI for building and deploying AI agents
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-exfil-services | AI (semgrep): Documentation snippet showing user-configured Telegram webhook setup, not exfil code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): jose is a standard, well-known JWT/crypto library. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes file upload data for storage; no obfuscation or code execution involved. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @poncho-ai/cli is an AI agent CLI, not a typosquat of joi; Levenshtein match is coincidental. | ai | |
| phantom-deps | phantom-dep:react-devtools-core | AI (phantom-deps): react-devtools-core is a declared dep; indirect usage is expected in this CLI context. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): ink is a declared runtime dep for terminal UI rendering; indirect usage pattern is expected in CLI tools. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): react is a peer/runtime dep required by ink for terminal rendering; indirect import is expected. | ai |
Versions (showing 63 of 63)
| Version | Deps | Published |
|---|---|---|
| 0.40.53 | 14 / 4 | |
| 0.40.52 | 14 / 4 | |
| 0.40.51 | 14 / 4 | |
| 0.40.50 | 14 / 4 | |
| 0.40.49 | 14 / 4 | |
| 0.21.9 | 13 / 4 | |
| 0.21.8 | 13 / 4 | |
| 0.21.7 | 13 / 4 | |
| 0.21.6 | 13 / 4 | |
| 0.21.5 | 13 / 4 | |
| 0.21.4 | 13 / 4 | |
| 0.21.3 | 13 / 4 | |
| 0.21.2 | 13 / 4 | |
| 0.21.1 | 13 / 4 | |
| 0.21.0 | 13 / 4 | |
| 0.20.3 | 13 / 4 | |
| 0.20.2 | 13 / 4 | |
| 0.20.1 | 13 / 4 | |
| 0.20.0 | 13 / 4 | |
| 0.19.1 | 13 / 4 | |
| 0.19.0 | 13 / 4 | |
| 0.18.0 | 13 / 4 | |
| 0.17.0 | 13 / 4 | |
| 0.16.5 | 13 / 4 | |
| 0.16.4 | 13 / 4 | |
| 0.16.3 | 13 / 4 | |
| 0.16.2 | 13 / 4 | |
| 0.16.1 | 13 / 4 | |
| 0.16.0 | 13 / 4 | |
| 0.15.0 | 13 / 4 | |
| 0.14.1 | 13 / 4 | |
| 0.14.0 | 13 / 4 | |
| 0.13.0 | 13 / 4 | |
| 0.12.0 | 12 / 4 | |
| 0.11.1 | 11 / 4 | |
| 0.11.0 | 11 / 4 | |
| 0.10.2 | 10 / 3 | |
| 0.10.1 | 10 / 3 | |
| 0.10.0 | 10 / 3 | |
| 0.9.4 | 10 / 3 | |
| 0.9.3 | 10 / 3 | |
| 0.9.2 | 10 / 3 | |
| 0.9.1 | 10 / 3 | |
| 0.9.0 | 10 / 3 | |
| 0.8.3 | 11 / 3 | |
| 0.8.2 | 11 / 3 | |
| 0.8.1 | 11 / 3 | |
| 0.8.0 | 11 / 3 | |
| 0.7.1 | 11 / 3 | |
| 0.7.0 | 11 / 3 | |
| 0.6.3 | 11 / 3 | |
| 0.6.2 | 11 / 3 | |
| 0.6.1 | 11 / 3 | |
| 0.6.0 | 11 / 3 | |
| 0.5.1 | 11 / 3 | |
| 0.5.0 | 11 / 3 | |
| 0.4.2 | 10 / 3 | |
| 0.4.1 | 10 / 3 | |
| 0.4.0 | 10 / 3 | |
| 0.3.2 | 10 / 3 | |
| 0.3.1 | 10 / 3 | |
| 0.3.0 | 10 / 3 | |
| 0.2.0 | 10 / 3 |
v0.40.53
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.52
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.51
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.50
2 findingsURL pointing to known exfiltration/tunneling service 421 | 5. Register the webhook after deploying: 422 | \`\`\`bash > 423 | curl -X POST "https://api.telegram.org/bot<TOKEN>/setWebhook" \\ 424 | -H "Content-Type: application/json" \\ 425 | -d '{"url": "https://<your-url>/api/messaging/telegram", "secret_token": "<SECRET>"}'
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.49
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.