← Home

@runtypelabs/cli

Command-line interface for Runtype AI platform

100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

becomevocalabnc

Keywords

runtypecliaiautomationworkflow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@modelcontextprotocol/core AI (dependencies): Official @modelcontextprotocol org package, not unvetted. ai
phantom-deps phantom-dep:@modelcontextprotocol/client AI (phantom-deps): Bundled dist output; official MCP org dep replacing sdk, no scannable imports expected. ai
dependencies unvetted-dep:@modelcontextprotocol/client AI (dependencies): Official @modelcontextprotocol org package, not unvetted. ai
phantom-deps phantom-dep:@modelcontextprotocol/core AI (phantom-deps): Bundled dist output; official MCP org dep replacing sdk, no scannable imports expected. ai
phantom-deps phantom-dep:inquirer AI (phantom-deps): Prompt library used via config, common CLI pattern. ai
provenance no-provenance AI (provenance): Common; not a risk signal on its own. ai
phantom-deps phantom-dep:ora AI (phantom-deps): CLI deps referenced dynamically/in config; stable FP. ai
phantom-deps phantom-dep:marked-terminal AI (phantom-deps): Terminal markdown renderer; declared and functional. ai
phantom-deps phantom-dep:@clerk/backend AI (phantom-deps): Auth backend integration; declared and functional. ai
phantom-deps phantom-dep:keytar AI (phantom-deps): Credential storage library used in CLI; declared and functional. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Markdown rendering for CLI output; declared and functional. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing; benign for this package. ai
dependencies unvetted-dep:add-mcp AI (dependencies): add-mcp is a legitimate MCP-config helper matching the package's AI/CLI purpose. ai
phantom-deps phantom-dep:add-mcp AI (phantom-deps): Config-referenced, consistent with MCP tooling. ai
phantom-deps phantom-dep:@modelcontextprotocol/sdk AI (phantom-deps): Config-referenced, consistent with MCP tooling. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): Config-file usage, common false positive for CLI tooling deps. ai
phantom-deps phantom-dep:@runtypelabs/ink-components AI (phantom-deps): Same org scope; bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:ink AI (phantom-deps): Bundled ESM CLI; phantom-dep heuristic consistently misfires on compiled dist for this package. ai
phantom-deps phantom-dep:conf AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:open AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:react AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:fflate AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:express AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:micromatch AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:rosie-skills AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:ink-text-input AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:@runtypelabs/sdk AI (phantom-deps): Same org scope; bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:ink-select-input AI (phantom-deps): Same bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:@runtypelabs/terminal-animations AI (phantom-deps): Same org scope; bundled ESM pattern; stable false positive. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): uuid is declared as a runtime dep; phantom-dep heuristic false positive for this CLI package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package @runtypelabs/cli is a CLI tool for Runtype AI, not a typosquat of joi; Levenshtein match is coincidental. ai
phantom-deps phantom-dep:oauth4webapi AI (phantom-deps): oauth4webapi is listed as a runtime dep in package.json; likely used indirectly or via dynamic import in the OAuth flow. ai

Versions (showing 100 of 167)

Version Deps Published
2.32.0 21 / 13
2.31.6 20 / 12
2.31.5 20 / 12
2.31.4 20 / 12
2.31.3 20 / 12
2.31.1 20 / 12
2.31.0 20 / 12
2.30.1 20 / 12
2.30.0 20 / 12
2.29.0 20 / 12
2.28.1 20 / 12
2.25.3 18 / 12
2.25.2 18 / 12
2.25.1 18 / 12
2.25.0 18 / 12
2.24.1 18 / 12
2.24.0 18 / 12
2.23.1 18 / 12
2.23.0 18 / 12
2.22.17 18 / 12
2.22.16 18 / 12
2.22.15 18 / 12
2.22.14 18 / 12
2.22.13 18 / 12
2.22.12 18 / 12
2.22.11 18 / 12
2.22.10 18 / 12
2.22.9 18 / 12
2.22.8 18 / 12
2.22.7 18 / 12
2.22.6 18 / 12
2.22.5 18 / 12
2.22.4 18 / 12
2.22.3 18 / 12
2.22.2 18 / 12
2.22.1 18 / 12
2.22.0 18 / 12
2.21.6 18 / 12
2.21.5 18 / 12
2.21.4 18 / 12
2.21.3 18 / 12
2.21.2 18 / 12
2.21.1 18 / 12
2.21.0 18 / 12
2.20.0 18 / 12
2.19.4 18 / 12
2.19.3 18 / 12
2.19.2 18 / 12
2.19.1 18 / 12
2.19.0 18 / 12
2.18.0 17 / 12
2.17.0 16 / 12
2.16.20 16 / 12
2.16.19 16 / 12
2.16.18 16 / 12
2.16.17 16 / 12
2.16.16 16 / 12
2.16.15 16 / 12
2.16.14 16 / 11
2.16.13 16 / 11
2.16.12 16 / 11
2.16.11 16 / 11
2.16.10 16 / 11
2.16.9 16 / 11
2.16.8 16 / 11
2.16.7 16 / 11
2.16.6 16 / 11
2.16.5 16 / 11
2.16.4 16 / 11
2.16.3 16 / 11
2.16.2 16 / 11
2.16.1 16 / 11
2.16.0 16 / 11
2.15.6 15 / 11
2.15.5 15 / 11
2.15.4 15 / 11
2.15.3 15 / 11
2.15.2 15 / 11
2.15.1 15 / 11
2.15.0 15 / 11
2.14.0 15 / 11
2.13.0 15 / 11
2.12.8 15 / 11
2.12.7 15 / 11
2.12.6 15 / 11
2.12.5 15 / 11
2.12.4 15 / 11
2.12.3 15 / 11
2.12.2 16 / 11
2.12.1 16 / 11
2.12.0 16 / 11
2.11.8 16 / 11
2.11.7 16 / 11
2.11.6 16 / 11
2.11.5 16 / 11
2.11.4 16 / 11
2.11.3 16 / 11
2.11.2 16 / 11
2.11.1 17 / 11
2.11.0 17 / 11
Showing 100 of 167 Next page →

v2.32.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.31.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.31.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.31.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.31.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.31.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.31.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.30.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.30.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.29.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.24.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.