@quatrain/core-cli
Quatrain Core CLI for generating configurations and migrations
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Decodes stored config credentials (STUDIO_AUTH_PASS/USER) from a local file — not a payload obfuscation pattern. | ai | |
| phantom-deps | phantom-dep:@quatrain/log | AI (phantom-deps): Same-org monorepo dep; CLI tool likely re-exports rather than directly imports it. | ai | |
| phantom-deps | phantom-dep:@quatrain/core | AI (phantom-deps): Same-org monorepo dep; CLI tool likely re-exports rather than directly imports it. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 1.1.7 | 5 / 4 | |
| 1.1.6 | 5 / 4 | |
| 1.1.5 | 5 / 4 | |
| 1.1.4 | 5 / 4 | |
| 1.1.3 | 4 / 4 | |
| 1.1.2 | 4 / 4 | |
| 1.1.1 | 4 / 4 |
v1.1.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.