← Home

@qoder-ai/qodercli

qodercli - npm installer

36
Versions
SEE LICENSE IN README.md
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

yn_crqoder-dev

Keywords

qoderaiclicodingassistantgemini

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Minor metadata regression from a trusted publisher with strong track record. ai
phantom-deps phantom-dep:sharp AI (phantom-deps): sharp is a known implicit/binary dependency, flagged as such by the analyzer itself. ai
npm-metadata bundled-binaries AI (npm-metadata): ripgrep prebuilt binary is a common, well-known CLI dependency, not a backdoor. ai
semgrep semgrep:child-process-execsync AI (semgrep): execSync used only to check for ripgrep binary presence; not arbitrary execution. ai
source-diff obfuscated-file:bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.d.ts AI (source-diff): Type declaration file embedding the same minified client JS string; benign build artifact. ai
source-diff obfuscated-file:bundle/node_modules/@google/gemini-cli-devtools/dist/src/_client-assets.js AI (source-diff): esbuild-minified React bundle with Google LLC license header; not obfuscated malware. ai
source-diff obfuscated-file:bundle/node_modules/@google/gemini-cli-devtools/dist/client/main.js AI (source-diff): esbuild-minified React bundle; recognizable React internals, no malicious indicators. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall fetches versioned prebuilt binaries with SHA256 integrity checks; standard CLI installer pattern. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used to run the downloaded binary; consistent with documented installer behavior. ai
semgrep semgrep:env-spread AI (semgrep): env-spread passes process.env to child_process for binary execution; no exfiltration path evident. ai

Versions (showing 36 of 36)

Version Deps Published
1.0.37 1 / 0
1.0.36 1 / 0
1.0.35 1 / 0
1.0.34 1 / 0
1.0.33 1 / 0
1.0.32 1 / 0
1.0.31 1 / 0
1.0.30 1 / 0
1.0.29 1 / 0
1.0.27 1 / 0
1.0.26 1 / 0
1.0.24 1 / 0
1.0.23 1 / 0
1.0.20 1 / 0
1.0.13 0 / 0
1.0.12 0 / 0
1.0.11 0 / 0
1.0.10 0 / 0
1.0.7 0 / 0
1.0.4 0 / 0
1.0.3 0 / 0
1.0.1 0 / 0
0.2.17 0 / 0
0.2.16 0 / 0
0.2.15 0 / 0
0.2.6 2 / 0
0.2.5 2 / 0
0.2.4 2 / 0
0.1.38 2 / 0
0.1.22 2 / 0
0.1.5 2 / 0
0.1.4 2 / 0
0.1.3 2 / 0
0.1.2 2 / 0
0.1.1 2 / 0
0.0.16 0 / 0

v1.0.37

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.36

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.35

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.34

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.33

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.32

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.31

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • bundle/vendor/ripgrep/arm64-darwin/rg

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.