@red-hat-developer-hub/cli
CLI for developing Backstage plugins and apps
9
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
nickboldtbethany.griggskashish_mittaltomaskralrhdh-botschultzp2020
Keywords
rhdhcli
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:eslint-config-prettier | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:react-refresh | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:esbuild-loader | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:gitconfiglocal | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:@changesets/cli | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:@backstage/types | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:html-webpack-plugin | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:bfj | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:codeowners | AI (phantom-deps): CLI build tool; deps referenced via config/build tooling, not direct imports. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): esbuild is a known implicit runtime/binary dependency for build tools; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): eslint is referenced in config files as expected for a CLI build tool; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): typescript referenced in config/scripts as expected for a build CLI; stable false positive. | ai | |
| phantom-deps | phantom-dep:webpack-dev-server | AI (phantom-deps): webpack-dev-server used via config in build CLI context; stable false positive. | ai | |
| phantom-deps | phantom-dep:@backstage/cli | AI (phantom-deps): Referenced in config files as expected for a Backstage-based CLI; stable false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @red-hat-developer-hub/cli bears no resemblance to 'joi'; levenshtein match is a false positive. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 1.11.3 | 54 / 34 | |
| 1.11.2 | 54 / 34 | |
| 1.10.8 | 54 / 33 | |
| 1.10.6 | 52 / 35 | |
| 1.10.5 | 52 / 35 | |
| 1.10.4 | 51 / 35 | |
| 1.10.0 | 49 / 23 | |
| 1.9.2 | 49 / 23 | |
| 1.9.0 | 49 / 23 |
v1.11.3
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.11.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.8
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.