← Home

@redocly/cli

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

romanhotsiyalawaradamaltmanmarshevskyyvolodymyr-rutskyi

Keywords

linterOpenAPISwaggerOpenAPI linterSwagger linterAsyncAPI linterArazzo linteroas

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/chunks/73MCRGNI.js AI (source-diff): esbuild-bundled ESM chunk; minified build output, not obfuscation. ai
source-diff net-exec-file:lib/chunks/RD4BYLLT.js AI (source-diff): Bundled deps; net+exec library internals, no exfil. ai
source-diff obfuscated-file:lib/chunks/RD4BYLLT.js AI (source-diff): esbuild bundle of core lint/bundle logic; build output. ai
source-diff net-exec-file:lib/chunks/HT6ZGKQQ.js AI (source-diff): Bundled lint/deps; net+exec are library internals. ai
source-diff obfuscated-file:lib/chunks/HT6ZGKQQ.js AI (source-diff): esbuild bundle of pluralize/graphql; build output. ai
source-diff obfuscated-file:lib/chunks/BFQ3EROY.js AI (source-diff): esbuild bundle of opentelemetry exporter; build output. ai
source-diff net-exec-file:lib/chunks/73MCRGNI.js AI (source-diff): Bundled vendor deps; net+exec are library internals, no hostile target. ai
source-diff obfuscated-file:lib/chunks/KYZEVOA2.js AI (source-diff): Bundled vendor code (pluralize etc); minified build artifact. ai
source-diff net-exec-file:lib/chunks/V74PIVJZ.js AI (source-diff): Bundled tool code, benign. ai
source-diff net-exec-file:lib/chunks/OVY6O6WL.js AI (source-diff): Bundled tool code, no hostile destination. ai
source-diff net-exec-file:lib/chunks/KYZEVOA2.js AI (source-diff): Net+exec is the CLI's own bundled functionality. ai
source-diff obfuscated-file:lib/chunks/V74PIVJZ.js AI (source-diff): esbuild bundle output, not obfuscation. ai
source-diff obfuscated-file:lib/chunks/OVY6O6WL.js AI (source-diff): esbuild bundle output, not obfuscation; recurs every release. ai
source-diff obfuscated-file:lib/chunks/G7TNNDDM.js AI (source-diff): Bundled undici/otel output, not obfuscation. ai
source-diff obfuscated-file:lib/chunks/DZ756KUK.js AI (source-diff): esbuild bundle output, not obfuscation; regenerated chunk names each release. ai
source-diff net-exec-file:lib/chunks/Z5JKGONR.js AI (source-diff): Bundled deps net+require; legit CLI. ai
source-diff obfuscated-file:lib/chunks/Z5JKGONR.js AI (source-diff): Bundled lunr/deps output, not obfuscation. ai
source-diff obfuscated-file:lib/chunks/XEVW3SW6.js AI (source-diff): Bundled OpenTelemetry exporter output. ai
source-diff net-exec-file:lib/chunks/RA3UJ5AH.js AI (source-diff): Bundled deps with net+require; legit. ai
source-diff obfuscated-file:lib/chunks/RA3UJ5AH.js AI (source-diff): Bundled pluralize/deps output, not obfuscation. ai
source-diff net-exec-file:lib/chunks/DZ756KUK.js AI (source-diff): Bundled undici/deps HTTP + dynamic require; legit CLI networking. ai
source-diff obfuscated-file:lib/chunks/M5T4PDSH.js AI (source-diff): esbuild bundle output of vendored deps; minified not obfuscated. ai
source-diff obfuscated-file:lib/chunks/MIPR6NCD.js AI (source-diff): esbuild bundle of pluralize/graphql; minified not obfuscated. ai
source-diff net-exec-file:lib/chunks/M5T4PDSH.js AI (source-diff): Bundled undici/otel HTTP libs; no malicious target. ai
source-diff obfuscated-file:lib/chunks/XB6C62FW.js AI (source-diff): esbuild bundle of undici; minified build output. ai
source-diff obfuscated-file:lib/chunks/G76UYYPW.js AI (source-diff): esbuild bundle of opentelemetry exporter; build output. ai
source-diff net-exec-file:lib/chunks/OPV3WWWU.js AI (source-diff): Bundled HTTP client code; benign for CLI fetch. ai
source-diff obfuscated-file:lib/chunks/OPV3WWWU.js AI (source-diff): esbuild bundle of lunr/redoc; minified build output. ai
source-diff net-exec-file:lib/chunks/MIPR6NCD.js AI (source-diff): Bundled vendored libs; expected for a linter CLI. ai
source-diff large-new-source-files AI (source-diff): Reflects legitimate dependency/module refactor by established maintainer with provenance. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are established mainstream packages tied to refactor, not suspicious additions. ai
source-diff net-exec-file:lib/chunks/CPNIO4J3.js AI (source-diff): Bundled undici/telemetry fetch+require in build output, no hostile target. ai
source-diff net-exec-file:lib/chunks/QFYLVVG2.js AI (source-diff): Bundled vendor code; benign. ai
source-diff net-exec-file:lib/chunks/FRVYIHIR.js AI (source-diff): Bundled vendor code; network+require are legitimate deps. ai
source-diff obfuscated-file:lib/chunks/CPNIO4J3.js AI (source-diff): esbuild-bundled vendor deps, not obfuscation; chunk names change per build. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): Transitive/config usage pattern; stable false positive for this package. ai
source-diff obfuscated-file:lib/chunks/ZKG4D7JN.js AI (source-diff): Bundled build output (pluralize etc.); not obfuscation. ai
source-diff obfuscated-file:lib/chunks/TGF4B4QI.js AI (source-diff): Bundled build output (lunr etc.); not obfuscation. ai
source-diff obfuscated-file:lib/chunks/HYYETV7F.js AI (source-diff): Bundled build output (OpenTelemetry); not obfuscation. ai
source-diff obfuscated-file:lib/chunks/FLGNQ4P2.js AI (source-diff): Bundled build output (undici etc.); not obfuscation. ai
source-diff obfuscated-file:lib/chunks/2ACFK2AA.js AI (source-diff): Bundled build output with readable source; not obfuscation. ai
source-diff net-exec-file:lib/chunks/ZKG4D7JN.js AI (source-diff): Bundled CLI tool; network + require is normal for this package. ai
source-diff net-exec-file:lib/chunks/TGF4B4QI.js AI (source-diff): Bundled CLI tool; network + require is normal for this package. ai
source-diff net-exec-file:lib/chunks/2ACFK2AA.js AI (source-diff): Bundled CLI tool; network + require is normal for this package. ai
source-diff obfuscated-file:lib/chunks/OEYVENNB.js AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. ai
source-diff obfuscated-file:lib/chunks/GRMVFQAA.js AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. ai
source-diff obfuscated-file:lib/chunks/FDUPOI4C.js AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. ai
source-diff obfuscated-file:lib/chunks/2ULY6UWW.js AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. ai
source-diff obfuscated-file:lib/chunks/7GOGGHM5.js AI (source-diff): Bundled ESM chunks from esbuild; not obfuscated. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Bundled undici webidl code; standard Reflect.get for iterator protocol. ai
semgrep semgrep:base64-decode AI (semgrep): Bundled undici HTTP handling; standard base64 usage. ai
semgrep semgrep:env-bulk-read AI (semgrep): Standard debug module pattern filtering DEBUG_ env vars. ai
source-diff source-size-tripled AI (source-diff): Deps moved from node_modules to bundled chunks; expected size increase. ai
source-diff net-exec-file:lib/chunks/OEYVENNB.js AI (source-diff): Bundled deps naturally contain net+exec patterns. ai
source-diff net-exec-file:lib/chunks/GRMVFQAA.js AI (source-diff): Bundled deps naturally contain net+exec patterns. ai
source-diff net-exec-file:lib/chunks/7GOGGHM5.js AI (source-diff): Bundled deps (undici, etc.) naturally contain net+exec patterns. ai
semgrep semgrep:child-process-import AI (semgrep): Used in OAuth device flow to open browser; not arbitrary command execution from user input. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads own package.json via __dirname for node version assertion; not user-controlled input. ai
dependencies unvetted-dep:handlebars AI (dependencies): handlebars is used for build-docs HTML templating; legitimate, long-standing use in this CLI. ai
phantom-deps phantom-dep:form-data AI (phantom-deps): form-data is a declared runtime dep for HTTP multipart uploads; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:abort-controller AI (phantom-deps): abort-controller is a declared runtime dep for fetch cancellation; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): chokidar is a declared runtime dep used by the CLI's file-watching feature; phantom-dep heuristic is a false positive here. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package @redocly/cli; Levenshtein match to 'joi' is a false positive with no brand impersonation. ai
phantom-deps phantom-dep:simple-websocket AI (phantom-deps): simple-websocket used in websocket features; stable false positive for this package. ai
phantom-deps phantom-dep:ajv-formats AI (phantom-deps): ajv-formats used alongside aliased ajv; phantom-dep heuristic misfires. ai
phantom-deps phantom-dep:pluralize AI (phantom-deps): pluralize used in generated code or transitive context; stable false positive. ai
phantom-deps phantom-dep:picomatch AI (phantom-deps): picomatch used via glob internals; stable false positive for this package. ai
phantom-deps phantom-dep:mobx AI (phantom-deps): mobx is a peer/transitive dep for redoc rendering; phantom-dep heuristic fires on indirect usage. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): ajv is declared as npm alias (@redocly/ajv) and used via config; phantom-dep heuristic misfires on aliased deps. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decoding is part of AES credential decryption in oauth-client.js — legitimate crypto usage, not obfuscation. ai

Versions (showing 51 of 117)

View all versions
Version Deps Published
2.40.0 0 / 0
2.39.0 0 / 0
2.38.0 0 / 0
2.37.0 0 / 0
2.35.1 0 / 0
2.35.0 0 / 0
2.34.0 0 / 0
2.33.2 28 / 9
2.33.1 28 / 9
2.33.0 28 / 9
2.32.2 28 / 9
2.32.1 28 / 9
2.32.0 28 / 9
2.31.6 28 / 9
2.31.5 28 / 9
2.31.4 28 / 9
2.31.3 28 / 9
2.31.2 28 / 9
2.31.1 28 / 9
2.31.0 28 / 9
2.30.6 28 / 9
2.30.5 28 / 9
2.30.4 28 / 9
2.30.3 28 / 9
2.30.2 28 / 9
2.30.1 28 / 9
2.30.0 29 / 9
2.29.2 29 / 9
2.29.1 29 / 9
2.28.1 29 / 9
2.28.0 29 / 9
2.27.1 29 / 9
2.27.0 29 / 9
2.26.0 29 / 9
2.25.3 29 / 9
2.25.1 29 / 9
2.25.0 29 / 9
2.24.1 28 / 10
2.24.0 28 / 10
2.23.0 28 / 10
2.22.1 28 / 10
2.22.0 28 / 10
2.21.1 28 / 10
2.21.0 28 / 10
2.20.5 28 / 10
2.20.4 28 / 10
2.20.3 28 / 10
2.20.2 28 / 10
2.20.1 28 / 10
2.20.0 28 / 10
2.19.2 28 / 10

v2.40.0

8 findings
HIGH New obfuscated file: lib/chunks/73MCRGNI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/73MCRGNI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/BFQ3EROY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/chunks/HT6ZGKQQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/HT6ZGKQQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/RD4BYLLT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/RD4BYLLT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.39.0

8 findings
HIGH New obfuscated file: lib/chunks/C3PXBQU5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/chunks/KYZEVOA2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/KYZEVOA2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/OVY6O6WL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/OVY6O6WL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/V74PIVJZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/V74PIVJZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.0

9 findings
HIGH New obfuscated file: lib/chunks/G76UYYPW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/chunks/M5T4PDSH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/M5T4PDSH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/MIPR6NCD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/MIPR6NCD.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/OPV3WWWU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/OPV3WWWU.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/XB6C62FW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.37.0

9 findings
HIGH New obfuscated file: lib/chunks/CPNIO4J3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/CPNIO4J3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/FRVYIHIR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/FRVYIHIR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/LJUXYC4S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/chunks/QFYLVVG2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/chunks/QFYLVVG2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: lib/chunks/U3LS66ZD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.33.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.33.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.33.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.31.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.30.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.