@qoder-ai/qodercli
qodercli - npm installer
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Minor metadata regression from a trusted publisher with strong track record. | ai | |
| phantom-deps | phantom-dep:sharp | AI (phantom-deps): sharp is a known implicit/binary dependency, flagged as such by the analyzer itself. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): ripgrep prebuilt binary is a common, well-known CLI dependency, not a backdoor. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): execSync used only to check for ripgrep binary presence; not arbitrary execution. | ai | |
| source-diff | obfuscated-file:bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.d.ts | AI (source-diff): Type declaration file embedding the same minified client JS string; benign build artifact. | ai | |
| source-diff | obfuscated-file:bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.js | AI (source-diff): esbuild-minified React bundle with Google LLC license header; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:bundle/node_modules/@google/gemini-cli-devtools/dist/client/main.js | AI (source-diff): esbuild-minified React bundle; recognizable React internals, no malicious indicators. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall fetches versioned prebuilt binaries with SHA256 integrity checks; standard CLI installer pattern. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used to run the downloaded binary; consistent with documented installer behavior. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread passes process.env to child_process for binary execution; no exfiltration path evident. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 1.0.37 | 1 / 0 | |
| 1.0.36 | 1 / 0 | |
| 1.0.35 | 1 / 0 | |
| 1.0.34 | 1 / 0 | |
| 1.0.33 | 1 / 0 | |
| 1.0.32 | 1 / 0 | |
| 1.0.31 | 1 / 0 | |
| 1.0.30 | 1 / 0 | |
| 1.0.29 | 1 / 0 | |
| 1.0.27 | 1 / 0 | |
| 1.0.26 | 1 / 0 | |
| 1.0.24 | 1 / 0 | |
| 1.0.23 | 1 / 0 | |
| 1.0.20 | 1 / 0 | |
| 1.0.13 | 0 / 0 | |
| 1.0.12 | 0 / 0 | |
| 1.0.11 | 0 / 0 | |
| 1.0.10 | 0 / 0 | |
| 1.0.7 | 0 / 0 | |
| 1.0.4 | 0 / 0 | |
| 1.0.3 | 0 / 0 | |
| 1.0.1 | 0 / 0 | |
| 0.2.17 | 0 / 0 | |
| 0.2.16 | 0 / 0 | |
| 0.2.15 | 0 / 0 | |
| 0.2.6 | 2 / 0 | |
| 0.2.5 | 2 / 0 | |
| 0.2.4 | 2 / 0 | |
| 0.1.38 | 2 / 0 | |
| 0.1.22 | 2 / 0 | |
| 0.1.5 | 2 / 0 | |
| 0.1.4 | 2 / 0 | |
| 0.1.3 | 2 / 0 | |
| 0.1.2 | 2 / 0 | |
| 0.1.1 | 2 / 0 | |
| 0.0.16 | 0 / 0 |
v1.0.37
2 findingsPackage contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.36
2 findingsPackage contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.35
2 findingsPackage contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.34
2 findingsPackage contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.33
2 findingsPackage contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.32
2 findingsPackage contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.31
2 findingsPackage contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.