@saltcorn/cli
Command-line interface for Saltcorn, open-source no-code platform
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Intentional pattern: spreads process.env to inject PGPASSWORD for pg backup utilities — expected CLI behavior. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI tool legitimately uses child_process for backup/restore commands; stable pattern across all versions. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require resolves a package.json path for plugin localization — not arbitrary user input. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @saltcorn/cli is a scoped package in the saltcorn org; not a typosquat of joi. | ai | |
| phantom-deps | phantom-dep:node-watch | AI (phantom-deps): Referenced in oclif config/runtime; false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): Loaded via oclif bootstrap, not direct import; stable false positive. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-plugins | AI (phantom-deps): Declared as oclif plugin in config; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@saltcorn/common-code | AI (phantom-deps): Same-org dependency; may be transitively loaded; stable false positive. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 1.6.1 | 20 / 3 | |
| 1.6.0 | 20 / 3 | |
| 1.5.8 | 20 / 3 | |
| 1.5.6 | 20 / 3 | |
| 1.5.3 | 20 / 3 | |
| 1.5.0 | 20 / 3 | |
| 1.4.3 | 20 / 3 | |
| 1.1.4 | 20 / 3 | |
| 1.1.3 | 20 / 3 | |
| 1.1.2 | 20 / 3 | |
| 1.1.1 | 20 / 3 | |
| 1.1.0 | 20 / 3 | |
| 1.0.0 | 20 / 3 |
v1.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.