@rootplatform/cli
Root Platform CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:cli-diff | AI (dependencies): Small utility dep, longstanding usage, no malicious behavior. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established package with real repo/history; README heuristic false positive. | ai | |
| dependencies | unvetted-dep:joi-to-json | AI (dependencies): Used for schema generation, matches stated CLI purpose. | ai | |
| provenance | publisher-changed | AI (provenance): Change is to GitHub Actions CI publisher, consistent with normal CI/CD automation. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Used in config/build tooling, not directly imported; stable pattern for this CLI package. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): ESLint config reference only; not directly imported at runtime. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): ESLint config reference only; not directly imported at runtime. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads mocha from a user-configured modulesPath; expected CLI test-runner behavior. | ai | |
| phantom-deps | phantom-dep:mocha | AI (phantom-deps): Mocha is loaded dynamically via modulesPath in the test runner script, not via static import. | ai | |
| phantom-deps | phantom-dep:npm | AI (phantom-deps): npm is a CLI tool dependency used by convention, not via direct import. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Config-file loaded dependency; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/adm-zip | AI (phantom-deps): Type package; stable false positive for this package. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP (127.0.0.1) appears only in test files testing localhost URL handling — not a runtime network call. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Package is @rootplatform/cli — a scoped CLI tool, not a typosquat of joi. Levenshtein match is spurious. | ai | |
| phantom-deps | phantom-dep:snakecase-keys | AI (phantom-deps): Config-referenced; stable false positive. | ai | |
| phantom-deps | phantom-dep:camelcase-keys | AI (phantom-deps): Config-referenced; stable false positive. | ai | |
| phantom-deps | phantom-dep:dayjs | AI (phantom-deps): Dev/config-referenced; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Dev/config-referenced; stable false positive for this CLI package. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Used in schema-generator to compile Joi schema descriptions; input is internally generated, not user-supplied arbitrary code. | ai | |
| phantom-deps | phantom-dep:sinon | AI (phantom-deps): Test utility referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): Linting tool referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): Config-referenced; stable false positive. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Formatter referenced in config; stable false positive. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 2.1.5 | 30 / 20 | |
| 2.0.5 | 29 / 20 | |
| 2.0.4 | 29 / 20 | |
| 2.0.0 | 29 / 20 | |
| 1.4.30 | 30 / 34 | |
| 1.4.28 | 30 / 34 | |
| 1.4.26 | 30 / 34 | |
| 1.4.25 | 30 / 34 | |
| 1.4.24 | 30 / 34 | |
| 1.4.23 | 33 / 31 | |
| 1.4.20 | 30 / 34 | |
| 1.4.18 | 30 / 34 |
v2.1.5
2 findingsThis version was published by a different npm account than previous versions on 2026-07-08. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.30
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.