@proofkit/cli
Create web application with the ProofKit stack
7
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
eluce3
Keywords
proofkitfilemakerottomaticproofgeistproofshnext.jstypescript
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Passing process.env to spawnSync is standard CLI child-process pattern, not exfiltration. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP is 127.0.0.1 (localhost default) in a template file; not a malicious remote endpoint. | ai | |
| phantom-deps | phantom-dep:@clack/core | AI (phantom-deps): Referenced in config files; CLI tool pattern, stable false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @proofkit/cli is unrelated to joi; Levenshtein match is a false positive for this namespace. | ai | |
| phantom-deps | phantom-dep:@ianvs/prettier-plugin-sort-imports | AI (phantom-deps): Prettier plugin loaded via config convention, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/glob | AI (phantom-deps): Type-only package loaded by framework convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): CLI tooling commonly uses jiti for config loading by convention; stable false positive. | ai |