@secondlayer/cli
CLI for subgraphs and blockchain indexing on Stacks
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are official Biome packages replacing prettier; benign formatter swap. | ai | |
| dependencies | unvetted-dep:@secondlayer/views | AI (dependencies): First-party @secondlayer scoped package; consistent with this CLI's own monorepo. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): CLI tools commonly use execa for subprocess execution; declared in deps and consistent with the tool's purpose even if not directly imported at the module level. | ai | |
| phantom-deps | phantom-dep:@antfu/ni | AI (phantom-deps): CLI tools use @antfu/ni for package manager detection; declared in deps and consistent with scaffolding/codegen CLI use cases. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 64 versions and 330-day history; lack of provenance is common and not a disqualifying signal for this package. | ai | |
| phantom-deps | phantom-dep:@secondlayer/workflows | AI (phantom-deps): Same-org scoped package declared but not directly imported; consistent with monorepo tooling patterns for @secondlayer packages. | ai | |
| dependencies | unvetted-dep:@secondlayer/workflows | AI (dependencies): First-party dependency from the same @secondlayer organization namespace; contextually appropriate for this CLI package. | ai | |
| dependencies | unvetted-dep:@biomejs/js-api | AI (dependencies): @biomejs/js-api is the official programmatic API for Biome, a well-known JS toolchain. This is a legitimate, reputable dependency used for code formatting/linting in the CLI. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @secondlayer/cli is a scoped CLI package with 330 days of history and 64 versions; levenshtein match to 'joi' is a superficial false positive with no impersonation intent. | ai | |
| phantom-deps | phantom-dep:@biomejs/wasm-nodejs | AI (phantom-deps): @biomejs/wasm-nodejs is a known platform-specific optional dep of the Biome toolchain, commonly referenced in config but not directly imported. Stable false positive for any Biome-using package. | ai |
Versions (showing 51 of 104)
| Version | Deps | Published |
|---|---|---|
| 8.6.1 | 11 / 11 | |
| 8.6.0 | 11 / 11 | |
| 8.5.2 | 11 / 11 | |
| 8.5.1 | 11 / 11 | |
| 8.5.0 | 11 / 11 | |
| 8.4.3 | 11 / 11 | |
| 8.4.2 | 11 / 11 | |
| 8.4.1 | 11 / 11 | |
| 8.4.0 | 11 / 11 | |
| 8.3.0 | 11 / 11 | |
| 8.2.0 | 11 / 11 | |
| 8.1.0 | 11 / 11 | |
| 8.0.0 | 11 / 11 | |
| 7.0.1 | 11 / 11 | |
| 7.0.0 | 11 / 11 | |
| 6.0.0 | 11 / 11 | |
| 5.10.1 | 11 / 11 | |
| 5.10.0 | 11 / 11 | |
| 5.9.0 | 11 / 11 | |
| 5.8.0 | 10 / 11 | |
| 5.7.0 | 10 / 11 | |
| 5.6.6 | 10 / 11 | |
| 5.6.5 | 10 / 11 | |
| 5.6.3 | 10 / 11 | |
| 5.6.2 | 10 / 11 | |
| 5.6.1 | 10 / 11 | |
| 5.6.0 | 10 / 11 | |
| 5.5.0 | 10 / 11 | |
| 5.4.10 | 10 / 11 | |
| 5.4.9 | 10 / 11 | |
| 5.4.8 | 10 / 11 | |
| 5.4.7 | 10 / 11 | |
| 5.4.6 | 10 / 11 | |
| 5.4.5 | 10 / 11 | |
| 5.4.4 | 10 / 11 | |
| 5.4.3 | 10 / 11 | |
| 5.4.2 | 10 / 11 | |
| 5.4.1 | 10 / 11 | |
| 5.4.0 | 10 / 11 | |
| 5.3.0 | 10 / 11 | |
| 5.2.1 | 10 / 11 | |
| 5.2.0 | 10 / 11 | |
| 5.1.6 | 10 / 11 | |
| 5.1.5 | 10 / 11 | |
| 5.1.4 | 10 / 11 | |
| 5.1.3 | 10 / 11 | |
| 5.1.2 | 10 / 11 | |
| 5.1.1 | 10 / 11 | |
| 5.1.0 | 10 / 11 | |
| 5.0.1 | 10 / 11 | |
| 5.0.0 | 10 / 11 |
v8.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.