@sanity/cli
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): process.env passed to worker thread for dynamic import flag; standard CLI behavior. | ai | |
| phantom-deps | phantom-dep:get-it | AI (phantom-deps): Referenced via config, first-party http client. | ai | |
| phantom-deps | phantom-dep:@sanity/template-validator | AI (phantom-deps): Same-org scoped dep. | ai | |
| phantom-deps | phantom-dep:@babel/traverse | AI (phantom-deps): Loaded by convention within CLI codegen. | ai | |
| phantom-deps | phantom-dep:@babel/parser | AI (phantom-deps): Loaded by convention within CLI codegen. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): Implicit binary dependency for CLI bundling. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Ciphertext decode in local env decrypt routine. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Local .env decrypt helper, no exfil destination. | ai | |
| phantom-deps | phantom-dep:skills | AI (phantom-deps): Listed as runtime dep in package.json; phantom-dep heuristic false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is a declared runtime dep used in build tooling context; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@sanity/cli-build | AI (dependencies): @sanity/cli-build is a same-org Sanity monorepo build helper; stable false positive for this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is same-org @sanity/cli-build; consistent with internal refactor, not a supply-chain injection. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-not-found | AI (phantom-deps): oclif plugin declared as dep and referenced in oclif config; not directly imported by code but legitimately used by the framework. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): Referenced in oclif config files; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:@sanity/migrate | AI (phantom-deps): Same-org dep used indirectly; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tsx | AI (phantom-deps): tsx is a build/script tool referenced in config files; stable false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Edit-distance match of '@sanity/cli' to 'joi' is a false positive; completely different namespace and purpose. | ai | |
| phantom-deps | phantom-dep:@sanity/runtime-cli | AI (phantom-deps): Same-org dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@sanity/descriptors | AI (phantom-deps): Same-org dep; stable false positive for this package. | ai |
Versions (showing 82 of 82)
| Version | Deps | Published |
|---|---|---|
| 7.13.0 | 66 / 34 | |
| 7.12.1 | 66 / 34 | |
| 7.12.0 | 66 / 34 | |
| 7.11.0 | 66 / 34 | |
| 7.10.0 | 66 / 34 | |
| 7.9.0 | 66 / 34 | |
| 7.8.0 | 66 / 34 | |
| 7.7.1 | 66 / 35 | |
| 7.7.0 | 66 / 35 | |
| 7.6.0 | 66 / 35 | |
| 7.5.0 | 66 / 35 | |
| 7.4.2 | 66 / 35 | |
| 7.4.1 | 66 / 35 | |
| 7.4.0 | 67 / 35 | |
| 7.3.0 | 67 / 35 | |
| 7.2.3 | 65 / 35 | |
| 7.2.2 | 65 / 35 | |
| 7.2.1 | 65 / 34 | |
| 7.2.0 | 65 / 34 | |
| 7.1.0 | 65 / 34 | |
| 7.0.2 | 65 / 34 | |
| 7.0.1 | 65 / 34 | |
| 7.0.0 | 65 / 34 | |
| 6.7.2 | 65 / 35 | |
| 6.7.1 | 65 / 35 | |
| 6.7.0 | 65 / 35 | |
| 6.6.0 | 67 / 34 | |
| 6.5.3 | 67 / 34 | |
| 6.5.2 | 67 / 34 | |
| 6.5.1 | 67 / 34 | |
| 6.5.0 | 67 / 34 | |
| 6.4.0 | 68 / 32 | |
| 6.3.2 | 68 / 32 | |
| 6.3.1 | 67 / 32 | |
| 6.3.0 | 67 / 32 | |
| 6.2.1 | 68 / 32 | |
| 6.2.0 | 68 / 32 | |
| 6.1.8 | 68 / 32 | |
| 6.1.7 | 68 / 32 | |
| 6.1.6 | 68 / 32 | |
| 6.1.5 | 68 / 32 | |
| 6.1.4 | 68 / 32 | |
| 6.1.3 | 68 / 32 | |
| 6.1.2 | 68 / 32 | |
| 6.1.1 | 70 / 33 | |
| 6.1.0 | 70 / 33 | |
| 6.0.0 | 72 / 33 | |
| 5.14.1 | 19 / 57 | |
| 5.14.0 | 19 / 57 | |
| 5.13.0 | 19 / 57 | |
| 5.12.0 | 19 / 57 | |
| 5.11.0 | 18 / 57 | |
| 5.10.0 | 18 / 57 | |
| 5.9.0 | 18 / 57 | |
| 5.8.1 | 18 / 57 | |
| 5.8.0 | 18 / 57 | |
| 5.7.0 | 18 / 57 | |
| 5.6.0 | 18 / 57 | |
| 5.5.0 | 18 / 56 | |
| 5.4.0 | 18 / 56 | |
| 5.3.1 | 18 / 56 | |
| 5.3.0 | 18 / 56 | |
| 5.2.0 | 17 / 56 | |
| 5.1.0 | 17 / 56 | |
| 5.0.1 | 17 / 56 | |
| 5.0.0 | 17 / 56 | |
| 4.22.0 | 17 / 56 | |
| 4.21.1 | 17 / 56 | |
| 4.21.0 | 17 / 56 | |
| 4.20.3 | 17 / 56 | |
| 4.20.2 | 17 / 56 | |
| 4.20.1 | 17 / 56 | |
| 4.20.0 | 17 / 56 | |
| 4.19.0 | 16 / 57 | |
| 4.18.0 | 16 / 57 | |
| 4.17.0 | 16 / 57 | |
| 4.16.0 | 16 / 57 | |
| 4.15.0 | 16 / 57 | |
| 4.14.2 | 17 / 57 | |
| 4.14.1 | 16 / 57 | |
| 4.14.0 | 16 / 57 | |
| 4.13.0 | 15 / 57 |
v7.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.12.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.9.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.14.1
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.14.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.13.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.12.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.11.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.9.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.1
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.7.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.6.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.4.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.1
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.1
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.22.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.21.1
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.21.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.20.3
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.20.2
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.20.1
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.20.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.19.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.18.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.17.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.16.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.15.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.14.2
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.14.1
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.14.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.0
2 findingsSpreading entire process.env into an object — may capture all secrets 24 | const worker = new node_worker_threads.Worker(workerPath, { 25 | workerData, > 26 | env: { 27 | ...process.env, 28 | // Dynamic HTTPS imports are currently behind a Node flag
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.