← Home

@sanity/cli

82
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sanity-svc.npmsanity-io

Keywords

clicmscontentheadlessrealtimesanitytool

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:env-spread AI (semgrep): process.env passed to worker thread for dynamic import flag; standard CLI behavior. ai
phantom-deps phantom-dep:get-it AI (phantom-deps): Referenced via config, first-party http client. ai
phantom-deps phantom-dep:@sanity/template-validator AI (phantom-deps): Same-org scoped dep. ai
phantom-deps phantom-dep:@babel/traverse AI (phantom-deps): Loaded by convention within CLI codegen. ai
phantom-deps phantom-dep:@babel/parser AI (phantom-deps): Loaded by convention within CLI codegen. ai
phantom-deps phantom-dep:esbuild AI (phantom-deps): Implicit binary dependency for CLI bundling. ai
semgrep semgrep:base64-decode AI (semgrep): Ciphertext decode in local env decrypt routine. ai
semgrep semgrep:hex-decode AI (semgrep): Local .env decrypt helper, no exfil destination. ai
phantom-deps phantom-dep:skills AI (phantom-deps): Listed as runtime dep in package.json; phantom-dep heuristic false positive for this CLI package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is a declared runtime dep used in build tooling context; stable false positive for this package. ai
dependencies unvetted-dep:@sanity/cli-build AI (dependencies): @sanity/cli-build is a same-org Sanity monorepo build helper; stable false positive for this package. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is same-org @sanity/cli-build; consistent with internal refactor, not a supply-chain injection. ai
phantom-deps phantom-dep:@oclif/plugin-not-found AI (phantom-deps): oclif plugin declared as dep and referenced in oclif config; not directly imported by code but legitimately used by the framework. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): Referenced in oclif config files; stable false positive for this CLI package. ai
phantom-deps phantom-dep:@sanity/migrate AI (phantom-deps): Same-org dep used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): tsx is a build/script tool referenced in config files; stable false positive for this package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Edit-distance match of '@sanity/cli' to 'joi' is a false positive; completely different namespace and purpose. ai
phantom-deps phantom-dep:@sanity/runtime-cli AI (phantom-deps): Same-org dep; stable false positive for this package. ai
phantom-deps phantom-dep:@sanity/descriptors AI (phantom-deps): Same-org dep; stable false positive for this package. ai

Versions (showing 82 of 82)

Version Deps Published
7.13.0 66 / 34
7.12.1 66 / 34
7.12.0 66 / 34
7.11.0 66 / 34
7.10.0 66 / 34
7.9.0 66 / 34
7.8.0 66 / 34
7.7.1 66 / 35
7.7.0 66 / 35
7.6.0 66 / 35
7.5.0 66 / 35
7.4.2 66 / 35
7.4.1 66 / 35
7.4.0 67 / 35
7.3.0 67 / 35
7.2.3 65 / 35
7.2.2 65 / 35
7.2.1 65 / 34
7.2.0 65 / 34
7.1.0 65 / 34
7.0.2 65 / 34
7.0.1 65 / 34
7.0.0 65 / 34
6.7.2 65 / 35
6.7.1 65 / 35
6.7.0 65 / 35
6.6.0 67 / 34
6.5.3 67 / 34
6.5.2 67 / 34
6.5.1 67 / 34
6.5.0 67 / 34
6.4.0 68 / 32
6.3.2 68 / 32
6.3.1 67 / 32
6.3.0 67 / 32
6.2.1 68 / 32
6.2.0 68 / 32
6.1.8 68 / 32
6.1.7 68 / 32
6.1.6 68 / 32
6.1.5 68 / 32
6.1.4 68 / 32
6.1.3 68 / 32
6.1.2 68 / 32
6.1.1 70 / 33
6.1.0 70 / 33
6.0.0 72 / 33
5.14.1 19 / 57
5.14.0 19 / 57
5.13.0 19 / 57
5.12.0 19 / 57
5.11.0 18 / 57
5.10.0 18 / 57
5.9.0 18 / 57
5.8.1 18 / 57
5.8.0 18 / 57
5.7.0 18 / 57
5.6.0 18 / 57
5.5.0 18 / 56
5.4.0 18 / 56
5.3.1 18 / 56
5.3.0 18 / 56
5.2.0 17 / 56
5.1.0 17 / 56
5.0.1 17 / 56
5.0.0 17 / 56
4.22.0 17 / 56
4.21.1 17 / 56
4.21.0 17 / 56
4.20.3 17 / 56
4.20.2 17 / 56
4.20.1 17 / 56
4.20.0 17 / 56
4.19.0 16 / 57
4.18.0 16 / 57
4.17.0 16 / 57
4.16.0 16 / 57
4.15.0 16 / 57
4.14.2 17 / 57
4.14.1 16 / 57
4.14.0 16 / 57
4.13.0 15 / 57

v7.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.14.1

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.14.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.13.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.12.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.11.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.10.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.9.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.1

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.7.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.6.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.5.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.1

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.1

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.22.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.21.1

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.21.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.20.3

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.20.2

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.20.1

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.20.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.19.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.18.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.17.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.16.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.15.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.14.2

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.14.1

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.14.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.13.0

2 findings
HIGH env-spread: lib/_chunks-cjs/journeyConfig.js:26 semgrep

Spreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.