@runtypelabs/cli
Command-line interface for Runtype AI platform
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:inquirer | AI (phantom-deps): Prompt library used via config, common CLI pattern. | ai | |
| provenance | no-provenance | AI (provenance): Common; not a risk signal on its own. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): CLI deps referenced dynamically/in config; stable FP. | ai | |
| phantom-deps | phantom-dep:@clerk/backend | AI (phantom-deps): Auth backend integration; declared and functional. | ai | |
| phantom-deps | phantom-dep:keytar | AI (phantom-deps): Credential storage library used in CLI; declared and functional. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Markdown rendering for CLI output; declared and functional. | ai | |
| phantom-deps | phantom-dep:marked-terminal | AI (phantom-deps): Terminal markdown renderer; declared and functional. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing; benign for this package. | ai | |
| dependencies | unvetted-dep:add-mcp | AI (dependencies): add-mcp is a legitimate MCP-config helper matching the package's AI/CLI purpose. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Config-file usage, common false positive for CLI tooling deps. | ai | |
| phantom-deps | phantom-dep:add-mcp | AI (phantom-deps): Config-referenced, consistent with MCP tooling. | ai | |
| phantom-deps | phantom-dep:@modelcontextprotocol/sdk | AI (phantom-deps): Config-referenced, consistent with MCP tooling. | ai | |
| phantom-deps | phantom-dep:ink-text-input | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ink-select-input | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@runtypelabs/ink-components | AI (phantom-deps): Same org scope; bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@runtypelabs/terminal-animations | AI (phantom-deps): Same org scope; bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@runtypelabs/sdk | AI (phantom-deps): Same org scope; bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Bundled ESM CLI; phantom-dep heuristic consistently misfires on compiled dist for this package. | ai | |
| phantom-deps | phantom-dep:conf | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:open | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:fflate | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:micromatch | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:rosie-skills | AI (phantom-deps): Same bundled ESM pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): uuid is declared as a runtime dep; phantom-dep heuristic false positive for this CLI package. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @runtypelabs/cli is a CLI tool for Runtype AI, not a typosquat of joi; Levenshtein match is coincidental. | ai | |
| phantom-deps | phantom-dep:oauth4webapi | AI (phantom-deps): oauth4webapi is listed as a runtime dep in package.json; likely used indirectly or via dynamic import in the OAuth flow. | ai |
Versions (showing 51 of 165)
| Version | Deps | Published |
|---|---|---|
| 2.31.5 | 20 / 12 | |
| 2.31.4 | 20 / 12 | |
| 2.31.3 | 20 / 12 | |
| 2.31.1 | 20 / 12 | |
| 2.31.0 | 20 / 12 | |
| 2.30.1 | 20 / 12 | |
| 2.30.0 | 20 / 12 | |
| 2.29.0 | 20 / 12 | |
| 2.28.1 | 20 / 12 | |
| 2.25.3 | 18 / 12 | |
| 2.25.2 | 18 / 12 | |
| 2.25.1 | 18 / 12 | |
| 2.25.0 | 18 / 12 | |
| 2.24.1 | 18 / 12 | |
| 2.24.0 | 18 / 12 | |
| 2.23.1 | 18 / 12 | |
| 2.23.0 | 18 / 12 | |
| 2.22.17 | 18 / 12 | |
| 2.22.16 | 18 / 12 | |
| 2.22.15 | 18 / 12 | |
| 2.22.14 | 18 / 12 | |
| 2.22.13 | 18 / 12 | |
| 2.22.12 | 18 / 12 | |
| 2.22.11 | 18 / 12 | |
| 2.22.10 | 18 / 12 | |
| 2.22.9 | 18 / 12 | |
| 2.22.8 | 18 / 12 | |
| 2.22.7 | 18 / 12 | |
| 2.22.6 | 18 / 12 | |
| 2.22.5 | 18 / 12 | |
| 2.22.4 | 18 / 12 | |
| 2.22.3 | 18 / 12 | |
| 2.22.2 | 18 / 12 | |
| 2.22.1 | 18 / 12 | |
| 2.22.0 | 18 / 12 | |
| 2.21.6 | 18 / 12 | |
| 2.21.5 | 18 / 12 | |
| 2.21.4 | 18 / 12 | |
| 2.21.3 | 18 / 12 | |
| 2.21.2 | 18 / 12 | |
| 2.21.1 | 18 / 12 | |
| 2.21.0 | 18 / 12 | |
| 2.20.0 | 18 / 12 | |
| 2.19.4 | 18 / 12 | |
| 2.19.3 | 18 / 12 | |
| 2.19.2 | 18 / 12 | |
| 2.19.1 | 18 / 12 | |
| 2.19.0 | 18 / 12 | |
| 2.18.0 | 17 / 12 | |
| 2.17.0 | 16 / 12 | |
| 2.16.20 | 16 / 12 |
v2.31.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.