@tangle-network/sandbox-cli
CLI for Tangle Sandbox operations
21
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
vutuanlinh2k2drewstonetjemmmictin-tangle-tools
Keywords
tanglesandboxcliai-agents
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from individual maintainer to GitHub Actions CI/CD publish is an improvement, consistent with org automation. | ai | |
| dependencies | unvetted-dep:@tangle-network/sdk-core | AI (dependencies): Same org scope as this package; no malicious behavior detected in this version. | ai | |
| phantom-deps | phantom-dep:@tangle-network/agent-eval | AI (phantom-deps): Same org scope; likely used transitively or via dynamic import in CLI tooling. | ai | |
| phantom-deps | phantom-dep:@tangle-network/hub-sdk | AI (phantom-deps): Same org scope; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:@tangle-network/agent-runtime | AI (phantom-deps): Same org scope; likely used transitively or via dynamic import in CLI tooling. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a transitive/config-referenced dep in this CLI package; stable false positive. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): CLI tool with bundled ESM output; indirect imports expected. | ai | |
| phantom-deps | phantom-dep:@tangle-network/sandbox | AI (phantom-deps): Same-org dependency; indirect usage in bundled CLI is expected. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): CLI tool with bundled ESM output; indirect imports expected. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): CLI tool with bundled ESM output; indirect imports expected. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): CLI tool with bundled ESM output; indirect imports expected. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 0.5.0 | 11 / 7 | |
| 0.4.1 | 11 / 7 | |
| 0.4.0 | 11 / 7 | |
| 0.3.3 | 10 / 7 | |
| 0.3.2 | 10 / 7 | |
| 0.3.1 | 10 / 7 | |
| 0.3.0 | 9 / 7 | |
| 0.2.14 | 7 / 7 | |
| 0.2.13 | 7 / 7 | |
| 0.2.11 | 7 / 7 | |
| 0.2.10 | 7 / 7 | |
| 0.2.9 | 7 / 7 | |
| 0.2.8 | 7 / 7 | |
| 0.2.7 | 7 / 7 | |
| 0.2.6 | 7 / 7 | |
| 0.2.5 | 6 / 7 | |
| 0.2.4 | 6 / 7 | |
| 0.2.2 | 5 / 5 | |
| 0.2.1 | 5 / 5 | |
| 0.2.0 | 5 / 5 | |
| 0.1.0 | 5 / 5 |
v0.5.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.