← Home

@semiont/cli

Semiont CLI - Unified environment management tool

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

adamaialliance

Keywords

semiontdeprecated

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@testcontainers/postgresql AI (phantom-deps): Test/integration dep referenced in config; phantom-dep heuristic misses config-scoped usage. ai
phantom-deps phantom-dep:openai AI (phantom-deps): AI SDK dep used in bundled dist output; phantom-dep heuristic misses bundled imports. ai
phantom-deps phantom-dep:simple-git AI (phantom-deps): Git utility dep likely used in bundled dist; phantom-dep heuristic misses bundled imports. ai
phantom-deps phantom-dep:is-ci AI (phantom-deps): CI detection dep likely used in bundled dist; phantom-dep heuristic misses bundled imports. ai
phantom-deps phantom-dep:is-upper-case AI (phantom-deps): Utility dep likely used in bundled dist; phantom-dep heuristic misses bundled imports. ai
phantom-deps phantom-dep:commander AI (phantom-deps): CLI tool; commander is a standard CLI dep likely used in bundled dist output. ai
phantom-deps phantom-dep:react AI (phantom-deps): Required peer for ink; loaded by convention. ai
phantom-deps phantom-dep:smol-toml AI (phantom-deps): TOML config parsing; same pattern as js-yaml — bundled usage. ai
phantom-deps phantom-dep:@vitest/ui AI (phantom-deps): Test framework UI package; framework-scoped, not directly imported. ai
phantom-deps phantom-dep:ink AI (phantom-deps): ink is a React-based CLI rendering lib; loaded by convention in this CLI tool. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): YAML parsing dep; likely used in config handling within bundled output. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @semiont/cli is a scoped CLI tool unrelated to joi; Levenshtein match is coincidental. ai
phantom-deps phantom-dep:@anthropic-ai/sdk AI (phantom-deps): AI SDK likely loaded via config/plugin convention in bundled output. ai
phantom-deps phantom-dep:@semiont/graph AI (phantom-deps): Same-org scoped package; phantom-dep heuristic unreliable for intra-monorepo deps. ai
phantom-deps phantom-dep:@aws-sdk/client-ecr AI (phantom-deps): Package.json comment explicitly notes AWS SDK deps are loaded by platform convention, not direct import. ai
phantom-deps phantom-dep:@aws-sdk/client-sts AI (phantom-deps): AWS SDK loaded by platform convention per package.json comment. ai
phantom-deps phantom-dep:@aws-sdk/client-wafv2 AI (phantom-deps): AWS SDK loaded by platform convention per package.json comment. ai
phantom-deps phantom-dep:@aws-sdk/client-route-53 AI (phantom-deps): AWS SDK loaded by platform convention per package.json comment. ai
phantom-deps phantom-dep:@aws-sdk/client-cloudwatch AI (phantom-deps): AWS SDK loaded by platform convention per package.json comment. ai
phantom-deps phantom-dep:@aws-sdk/client-cost-explorer AI (phantom-deps): AWS SDK loaded by platform convention per package.json comment. ai
phantom-deps phantom-dep:@aws-sdk/client-secrets-manager AI (phantom-deps): AWS SDK loaded by platform convention per package.json comment. ai
phantom-deps phantom-dep:arg AI (phantom-deps): CLI arg-parsing dep; likely used in bundled dist output not directly traced by static analysis. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Schema validation dep; likely used in bundled/config code not directly imported. ai

Versions (showing 51 of 76)

View all versions
Version Deps Published
0.5.21 0 / 2
0.5.7 17 / 8
0.5.2 17 / 7
0.5.1 17 / 7
0.5.0 17 / 7
0.4.22 17 / 7
0.4.21 16 / 7
0.4.20 16 / 7
0.4.19 16 / 7
0.4.18 16 / 7
0.4.17 16 / 7
0.4.16 16 / 7
0.4.15 32 / 7
0.4.14 32 / 7
0.4.13 32 / 7
0.4.12 32 / 7
0.4.11 32 / 7
0.4.9 32 / 7
0.4.7 32 / 7
0.4.6 32 / 7
0.4.5 32 / 7
0.4.4 32 / 7
0.4.3 32 / 7
0.4.2 33 / 8
0.4.1 33 / 8
0.4.0 33 / 8
0.3.8 33 / 8
0.3.7 33 / 8
0.3.6 33 / 8
0.3.5 33 / 8
0.3.4 31 / 8
0.3.3 31 / 8
0.3.2 31 / 8
0.3.1 31 / 8
0.3.0 31 / 8
0.2.46 33 / 11
0.2.45 33 / 11
0.2.43 33 / 11
0.2.42 33 / 11
0.2.41 33 / 11
0.2.40 33 / 11
0.2.39 34 / 10
0.2.38 34 / 10
0.2.37 34 / 10
0.2.36 34 / 10
0.2.35 34 / 10
0.2.34 34 / 10
0.2.33 34 / 10
0.2.32 34 / 10
0.2.31 34 / 10
0.2.30 34 / 10

v0.5.21

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.