@redocly/cli
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:lib/chunks/73MCRGNI.js | AI (source-diff): esbuild-bundled ESM chunk; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:lib/chunks/RD4BYLLT.js | AI (source-diff): Bundled deps; net+exec library internals, no exfil. | ai | |
| source-diff | obfuscated-file:lib/chunks/RD4BYLLT.js | AI (source-diff): esbuild bundle of core lint/bundle logic; build output. | ai | |
| source-diff | net-exec-file:lib/chunks/HT6ZGKQQ.js | AI (source-diff): Bundled lint/deps; net+exec are library internals. | ai | |
| source-diff | obfuscated-file:lib/chunks/HT6ZGKQQ.js | AI (source-diff): esbuild bundle of pluralize/graphql; build output. | ai | |
| source-diff | obfuscated-file:lib/chunks/BFQ3EROY.js | AI (source-diff): esbuild bundle of opentelemetry exporter; build output. | ai | |
| source-diff | net-exec-file:lib/chunks/73MCRGNI.js | AI (source-diff): Bundled vendor deps; net+exec are library internals, no hostile target. | ai | |
| source-diff | obfuscated-file:lib/chunks/KYZEVOA2.js | AI (source-diff): Bundled vendor code (pluralize etc); minified build artifact. | ai | |
| source-diff | net-exec-file:lib/chunks/V74PIVJZ.js | AI (source-diff): Bundled tool code, benign. | ai | |
| source-diff | net-exec-file:lib/chunks/OVY6O6WL.js | AI (source-diff): Bundled tool code, no hostile destination. | ai | |
| source-diff | net-exec-file:lib/chunks/KYZEVOA2.js | AI (source-diff): Net+exec is the CLI's own bundled functionality. | ai | |
| source-diff | obfuscated-file:lib/chunks/V74PIVJZ.js | AI (source-diff): esbuild bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/chunks/OVY6O6WL.js | AI (source-diff): esbuild bundle output, not obfuscation; recurs every release. | ai | |
| source-diff | obfuscated-file:lib/chunks/G7TNNDDM.js | AI (source-diff): Bundled undici/otel output, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/chunks/DZ756KUK.js | AI (source-diff): esbuild bundle output, not obfuscation; regenerated chunk names each release. | ai | |
| source-diff | net-exec-file:lib/chunks/Z5JKGONR.js | AI (source-diff): Bundled deps net+require; legit CLI. | ai | |
| source-diff | obfuscated-file:lib/chunks/Z5JKGONR.js | AI (source-diff): Bundled lunr/deps output, not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/chunks/XEVW3SW6.js | AI (source-diff): Bundled OpenTelemetry exporter output. | ai | |
| source-diff | net-exec-file:lib/chunks/RA3UJ5AH.js | AI (source-diff): Bundled deps with net+require; legit. | ai | |
| source-diff | obfuscated-file:lib/chunks/RA3UJ5AH.js | AI (source-diff): Bundled pluralize/deps output, not obfuscation. | ai | |
| source-diff | net-exec-file:lib/chunks/DZ756KUK.js | AI (source-diff): Bundled undici/deps HTTP + dynamic require; legit CLI networking. | ai | |
| source-diff | obfuscated-file:lib/chunks/M5T4PDSH.js | AI (source-diff): esbuild bundle output of vendored deps; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/chunks/MIPR6NCD.js | AI (source-diff): esbuild bundle of pluralize/graphql; minified not obfuscated. | ai | |
| source-diff | net-exec-file:lib/chunks/M5T4PDSH.js | AI (source-diff): Bundled undici/otel HTTP libs; no malicious target. | ai | |
| source-diff | obfuscated-file:lib/chunks/XB6C62FW.js | AI (source-diff): esbuild bundle of undici; minified build output. | ai | |
| source-diff | obfuscated-file:lib/chunks/G76UYYPW.js | AI (source-diff): esbuild bundle of opentelemetry exporter; build output. | ai | |
| source-diff | net-exec-file:lib/chunks/OPV3WWWU.js | AI (source-diff): Bundled HTTP client code; benign for CLI fetch. | ai | |
| source-diff | obfuscated-file:lib/chunks/OPV3WWWU.js | AI (source-diff): esbuild bundle of lunr/redoc; minified build output. | ai | |
| source-diff | net-exec-file:lib/chunks/MIPR6NCD.js | AI (source-diff): Bundled vendored libs; expected for a linter CLI. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Reflects legitimate dependency/module refactor by established maintainer with provenance. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are established mainstream packages tied to refactor, not suspicious additions. | ai | |
| source-diff | net-exec-file:lib/chunks/CPNIO4J3.js | AI (source-diff): Bundled undici/telemetry fetch+require in build output, no hostile target. | ai | |
| source-diff | net-exec-file:lib/chunks/QFYLVVG2.js | AI (source-diff): Bundled vendor code; benign. | ai | |
| source-diff | net-exec-file:lib/chunks/FRVYIHIR.js | AI (source-diff): Bundled vendor code; network+require are legitimate deps. | ai | |
| source-diff | obfuscated-file:lib/chunks/CPNIO4J3.js | AI (source-diff): esbuild-bundled vendor deps, not obfuscation; chunk names change per build. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): Transitive/config usage pattern; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:lib/chunks/ZKG4D7JN.js | AI (source-diff): Bundled build output (pluralize etc.); not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/chunks/TGF4B4QI.js | AI (source-diff): Bundled build output (lunr etc.); not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/chunks/HYYETV7F.js | AI (source-diff): Bundled build output (OpenTelemetry); not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/chunks/FLGNQ4P2.js | AI (source-diff): Bundled build output (undici etc.); not obfuscation. | ai | |
| source-diff | obfuscated-file:lib/chunks/2ACFK2AA.js | AI (source-diff): Bundled build output with readable source; not obfuscation. | ai | |
| source-diff | net-exec-file:lib/chunks/ZKG4D7JN.js | AI (source-diff): Bundled CLI tool; network + require is normal for this package. | ai | |
| source-diff | net-exec-file:lib/chunks/TGF4B4QI.js | AI (source-diff): Bundled CLI tool; network + require is normal for this package. | ai | |
| source-diff | net-exec-file:lib/chunks/2ACFK2AA.js | AI (source-diff): Bundled CLI tool; network + require is normal for this package. | ai | |
| source-diff | obfuscated-file:lib/chunks/OEYVENNB.js | AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/chunks/GRMVFQAA.js | AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/chunks/FDUPOI4C.js | AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/chunks/2ULY6UWW.js | AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. | ai | |
| source-diff | obfuscated-file:lib/chunks/7GOGGHM5.js | AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Bundled undici webidl code; standard Reflect.get for iterator protocol. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Bundled undici HTTP handling; standard base64 usage. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Standard debug module pattern filtering DEBUG_ env vars. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Deps moved from node_modules to bundled chunks; expected size increase. | ai | |
| source-diff | net-exec-file:lib/chunks/OEYVENNB.js | AI (source-diff): Bundled deps naturally contain net+exec patterns. | ai | |
| source-diff | net-exec-file:lib/chunks/GRMVFQAA.js | AI (source-diff): Bundled deps naturally contain net+exec patterns. | ai | |
| source-diff | net-exec-file:lib/chunks/7GOGGHM5.js | AI (source-diff): Bundled deps (undici, etc.) naturally contain net+exec patterns. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Used in OAuth device flow to open browser; not arbitrary command execution from user input. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads own package.json via __dirname for node version assertion; not user-controlled input. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): handlebars is used for build-docs HTML templating; legitimate, long-standing use in this CLI. | ai | |
| phantom-deps | phantom-dep:form-data | AI (phantom-deps): form-data is a declared runtime dep for HTTP multipart uploads; phantom-dep heuristic is a false positive. | ai | |
| phantom-deps | phantom-dep:abort-controller | AI (phantom-deps): abort-controller is a declared runtime dep for fetch cancellation; phantom-dep heuristic is a false positive. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): chokidar is a declared runtime dep used by the CLI's file-watching feature; phantom-dep heuristic is a false positive here. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @redocly/cli; Levenshtein match to 'joi' is a false positive with no brand impersonation. | ai | |
| phantom-deps | phantom-dep:simple-websocket | AI (phantom-deps): simple-websocket used in websocket features; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): ajv-formats used alongside aliased ajv; phantom-dep heuristic misfires. | ai | |
| phantom-deps | phantom-dep:pluralize | AI (phantom-deps): pluralize used in generated code or transitive context; stable false positive. | ai | |
| phantom-deps | phantom-dep:picomatch | AI (phantom-deps): picomatch used via glob internals; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:mobx | AI (phantom-deps): mobx is a peer/transitive dep for redoc rendering; phantom-dep heuristic fires on indirect usage. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): ajv is declared as npm alias (@redocly/ajv) and used via config; phantom-dep heuristic misfires on aliased deps. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decoding is part of AES credential decryption in oauth-client.js — legitimate crypto usage, not obfuscation. | ai |
Versions (showing 51 of 117)
| Version | Deps | Published |
|---|---|---|
| 2.40.0 | 0 / 0 | |
| 2.39.0 | 0 / 0 | |
| 2.38.0 | 0 / 0 | |
| 2.37.0 | 0 / 0 | |
| 2.35.1 | 0 / 0 | |
| 2.35.0 | 0 / 0 | |
| 2.34.0 | 0 / 0 | |
| 2.33.2 | 28 / 9 | |
| 2.33.1 | 28 / 9 | |
| 2.33.0 | 28 / 9 | |
| 2.32.2 | 28 / 9 | |
| 2.32.1 | 28 / 9 | |
| 2.32.0 | 28 / 9 | |
| 2.31.6 | 28 / 9 | |
| 2.31.5 | 28 / 9 | |
| 2.31.4 | 28 / 9 | |
| 2.31.3 | 28 / 9 | |
| 2.31.2 | 28 / 9 | |
| 2.31.1 | 28 / 9 | |
| 2.31.0 | 28 / 9 | |
| 2.30.6 | 28 / 9 | |
| 2.30.5 | 28 / 9 | |
| 2.30.4 | 28 / 9 | |
| 2.30.3 | 28 / 9 | |
| 2.30.2 | 28 / 9 | |
| 2.30.1 | 28 / 9 | |
| 2.30.0 | 29 / 9 | |
| 2.29.2 | 29 / 9 | |
| 2.29.1 | 29 / 9 | |
| 2.28.1 | 29 / 9 | |
| 2.28.0 | 29 / 9 | |
| 2.27.1 | 29 / 9 | |
| 2.27.0 | 29 / 9 | |
| 2.26.0 | 29 / 9 | |
| 2.25.3 | 29 / 9 | |
| 2.25.1 | 29 / 9 | |
| 2.25.0 | 29 / 9 | |
| 2.24.1 | 28 / 10 | |
| 2.24.0 | 28 / 10 | |
| 2.23.0 | 28 / 10 | |
| 2.22.1 | 28 / 10 | |
| 2.22.0 | 28 / 10 | |
| 2.21.1 | 28 / 10 | |
| 2.21.0 | 28 / 10 | |
| 2.20.5 | 28 / 10 | |
| 2.20.4 | 28 / 10 | |
| 2.20.3 | 28 / 10 | |
| 2.20.2 | 28 / 10 | |
| 2.20.1 | 28 / 10 | |
| 2.20.0 | 28 / 10 | |
| 2.19.2 | 28 / 10 |
v2.40.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.39.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.38.0
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.37.0
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.33.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.33.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.33.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.32.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.32.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.31.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.31.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.31.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.30.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.