← Home

@ridit/milo

Tiny cat. Big code.

48
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ridit-jangra

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-spread AI (semgrep): env spread into child shell with GIT_EDITOR override; no exfil, normal for CLI process spawning. ai
phantom-deps phantom-dep:@ai-sdk/openai-compatible AI (phantom-deps): Bundler-external/config-referenced; expected for this ink/bun-built CLI. ai
dependencies unvetted-dep:@ridit/ai AI (dependencies): Same-org scope dep for this org's own AI CLI; consistent across versions. ai
provenance missing-githead AI (provenance): No malicious behavior; consistent with normal CI variance for this maintainer's other approved packages. ai
phantom-deps phantom-dep:@openrouter/ai-sdk-provider AI (phantom-deps): Used via TS source/config, not statically detected; benign for this CLI tool. ai
provenance no-provenance AI (provenance): Manual publish is common; not a risk signal for this CLI. ai
semgrep semgrep:child-process-execsync AI (semgrep): Used for cwd tracking within the tool's own persistent shell utility. ai
publish-pattern new-deps-added AI (publish-pattern): commander is a standard, well-known CLI arg-parsing library. ai
semgrep semgrep:child-process-import AI (semgrep): Core shell-management feature of this CLI tool, not arbitrary exec of untrusted input. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Bundled via bun build --external commander; phantom-dep heuristic inapplicable. ai
phantom-deps phantom-dep:lodash-es AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:ink-spinner AI (phantom-deps): Bundled via bun build --external ink-spinner; phantom-dep heuristic inapplicable. ai
phantom-deps phantom-dep:@ai-sdk/groq AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:cli-truncate AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
typosquat typosquat.levenshtein:pino AI (typosquat): Scoped CLI package @ridit/milo is unrelated to pino logger; Levenshtein match is coincidental. ai
phantom-deps phantom-dep:cli-highlight AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:@ai-sdk/google AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:@ai-sdk/openai AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:@vscode/ripgrep AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:@ai-sdk/anthropic AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:ai-sdk-ollama AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:ai AI (phantom-deps): Deps are bundled via bun build; phantom-dep heuristic doesn't account for bundled output. ai
phantom-deps phantom-dep:ink AI (phantom-deps): Bundled via bun build --external ink; not directly imported in dist. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:glob AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Bundled via bun build --external chalk; phantom-dep heuristic inapplicable. ai
phantom-deps phantom-dep:react AI (phantom-deps): Bundled via bun build --external react; phantom-dep heuristic inapplicable. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Bundled dependency; phantom-dep heuristic inapplicable to bundled packages. ai
phantom-deps phantom-dep:figures AI (phantom-deps): Bundled via bun build --external figures; phantom-dep heuristic inapplicable. ai

Versions (showing 48 of 48)

Version Deps Published
0.7.9 23 / 11
0.7.7 21 / 10
0.7.6 21 / 10
0.6.9 21 / 10
0.6.8 21 / 10
0.6.7 21 / 10
0.6.6 21 / 10
0.6.5 21 / 10
0.6.4 21 / 10
0.6.3 21 / 10
0.6.2 21 / 10
0.6.0 20 / 10
0.5.9 20 / 5
0.5.8 20 / 5
0.5.7 20 / 5
0.5.6 19 / 5
0.5.5 19 / 5
0.5.4 19 / 5
0.5.3 19 / 5
0.5.2 19 / 5
0.5.1 19 / 5
0.5.0 19 / 5
0.4.11 19 / 5
0.4.10 19 / 5
0.4.9 19 / 5
0.4.8 19 / 5
0.4.7 19 / 5
0.4.6 19 / 5
0.4.5 19 / 5
0.4.4 19 / 5
0.4.3 19 / 5
0.4.2 19 / 5
0.4.1 19 / 5
0.4.0 19 / 5
0.3.5 18 / 5
0.3.4 18 / 5
0.3.3 18 / 5
0.3.2 18 / 5
0.3.1 17 / 5
0.3.0 17 / 5
0.2.2 17 / 5
0.2.1 17 / 5
0.2.0 17 / 5
0.1.4 17 / 5
0.1.3 17 / 5
0.1.2 17 / 5
0.1.1 23 / 4
0.1.0 29 / 4

v0.6.7

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.9

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ridit-jangra.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

2 findings
HIGH env-spread: src/utils/PersistentShell.ts:62 semgrep

Spreading entire process.env into an object — may capture all secrets 60 | stdio: ["pipe", "pipe", "pipe"], 61 | cwd, > 62 | env: { ...process.env, GIT_EDITOR: "true" }, 63 | }, 64 | );

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.