@tradejs/cli
Official CLI for the TradeJS open-source framework: infra setup, backtests, signals, bots, and ML workflows.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/scripts/signalsDaemon.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/lib/runEnvironment.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/lib/runFormatting.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/scripts/aiPocketSearch.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/scripts/replay.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/scripts/replayRunner.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/lib/marketContextPrepare.js | AI (source-diff): tsup/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/scripts/aiTrain.js | AI (source-diff): esbuild/tsup bundle output with node_modules path comments; not obfuscated. | ai | |
| phantom-deps | phantom-dep:@tradejs/base | AI (phantom-deps): Same-org scoped dep; CLI may re-export or use at runtime without direct top-level import. | ai | |
| phantom-deps | phantom-dep:@tradejs/types | AI (phantom-deps): Same-org types package; likely used transitively or via type-only imports not detected by heuristic. | ai | |
| phantom-deps | phantom-dep:@tradejs/indicators | AI (phantom-deps): Same-org scoped dep; CLI orchestrates multiple packages and may use at runtime without direct import. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @tradejs/cli is a scoped CLI package in its own org; Levenshtein proximity to 'joi' is coincidental. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 2.0.6 | 17 / 7 | |
| 2.0.5 | 17 / 7 | |
| 2.0.4 | 17 / 7 | |
| 2.0.3 | 17 / 7 | |
| 2.0.2 | 17 / 7 | |
| 2.0.1 | 17 / 7 | |
| 2.0.0 | 17 / 7 | |
| 1.0.12 | 17 / 7 | |
| 1.0.11 | 17 / 7 | |
| 1.0.10 | 17 / 7 | |
| 1.0.9 | 16 / 6 | |
| 1.0.8 | 16 / 6 | |
| 1.0.6 | 16 / 6 | |
| 1.0.5 | 16 / 6 | |
| 1.0.4 | 16 / 6 | |
| 1.0.3 | 16 / 6 | |
| 1.0.2 | 16 / 6 | |
| 1.0.1 | 16 / 6 | |
| 1.0.0 | 16 / 6 |
v2.0.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.10
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.