@styleframe/cli
14
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
alexgrozav
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/export-BMneJTdq.cjs | AI (source-diff): Bundled CLI output using node:fs/promises for file I/O; no network fetch or dynamic eval — false positive for this package. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Size drop explained by extraction of code into @styleframe/dtcg dependency; not a stub/redirect. | ai | |
| source-diff | net-exec-file:dist/export-Cx6awh55.js | AI (source-diff): ESM counterpart of the same bundled CLI output; same false-positive reasoning applies. | ai | |
| source-diff | obfuscated-file:dist/index-BX6dI2z2.js | AI (source-diff): Standard webpack/rollup bundle output (jiti/mlly bundled); minification is expected for this CLI package. | ai | |
| source-diff | obfuscated-file:dist/build-aC0xw4RW.js | AI (source-diff): Bundled build artifact (webpack/rollup output of jiti+deps); long lines are minification, not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:@styleframe/loader | AI (phantom-deps): Same-org runtime dep; CLI tools commonly invoke dependencies without static top-level imports. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @styleframe/cli vs 'joi' is not a credible typosquat; edit-distance match is coincidental. | ai | |
| phantom-deps | phantom-dep:@styleframe/figma | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for monorepo packages that may be used indirectly. | ai |