← Home

@tscircuit/cli

A CLI for developing, managing and publishing tscircuit code (the "npm for tscircuit")

100
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

seveibar

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Established, widely-used CLI; spam signals are metadata noise. ai
semgrep semgrep:child-process-import AI (semgrep): CLI tool legitimately shells out; no hostile target. ai
phantom-deps phantom-dep:@tscircuit/runframe AI (phantom-deps): Same org scope dependency. ai
phantom-deps phantom-dep:circuit-json-to-connectivity-map AI (phantom-deps): Used via config/build scripts, stable false positive. ai
phantom-deps phantom-dep:performance-now AI (phantom-deps): Used via config/build scripts, stable false positive. ai
phantom-deps phantom-dep:circuit-to-svg AI (phantom-deps): Used via config/build scripts, stable false positive. ai
phantom-deps phantom-dep:redaxios AI (phantom-deps): Used via config/build scripts, stable false positive. ai
phantom-deps phantom-dep:tempy AI (phantom-deps): Used via config/build scripts, stable false positive. ai
phantom-deps phantom-dep:@tscircuit/props AI (phantom-deps): Same-org scope dependency, stable false positive. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): 127.0.0.1 dev server log message, not exfil to remote IP. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get used in a benign posthog proxy no-op fallback. ai
phantom-deps phantom-dep:tsup AI (phantom-deps): Build tool referenced via config only. ai
semgrep semgrep:base64-decode AI (semgrep): File-content base64 decode in a documented export API schema, not payload hiding. ai
dependencies unvetted-dep:@tscircuit/builder AI (dependencies): First-party tscircuit dependency. ai
phantom-deps phantom-dep:node-persist AI (phantom-deps): Likely used in bundled/minified CLI code; no evidence of malicious install-time use. ai
dependencies unvetted-dep:@tscircuit/react-fiber AI (dependencies): First-party tscircuit dependency. ai
dependencies unvetted-dep:dax-sh AI (dependencies): Legit shell-scripting lib used by CLI tooling; no malicious behavior. ai
npm-metadata url-dep:@tscircuit/check-shorts AI (npm-metadata): devDependency only (not installed by consumers), points at vendor-owned jscdn.tscircuit.com; stable for this package. ai
npm-metadata url-dep:@tscircuit/ti-parts-engine AI (npm-metadata): SHA-pinned devDep within tscircuit org; consistent pattern across many versions of this package. ai
npm-metadata url-dep:@tscircuit/fake-ul-kicad-proxy AI (npm-metadata): SHA-pinned devDep within tscircuit org; consistent pattern across many versions of this package. ai
npm-metadata url-dep:@tscircuit/circuit-json-schematic-placement-analysis AI (npm-metadata): SHA-pinned devDep pointing to tscircuit's own org repo; devDeps don't ship to consumers. ai
npm-metadata url-dep:circuit-json-trace-length-analysis AI (npm-metadata): SHA-pinned devDep pointing to tscircuit's own org repo; devDeps don't ship to consumers. ai
npm-metadata bundled-binaries AI (npm-metadata): resvgjs native binaries are expected for SVG/image processing in this EDA CLI; stable pattern across versions. ai
source-diff encoded-string-file:dist/cli/main.js AI (source-diff): Encoded strings are undici's llhttp WASM binary (base64); benign and stable across versions of this package. ai
semgrep semgrep:dynamic-require AI (semgrep): The dynamic require loads a local package.json for project discovery — standard CLI entrypoint pattern, not an arbitrary code execution risk. ai
phantom-deps phantom-dep:@rollup/plugin-node-resolve AI (phantom-deps): Rollup plugin loaded via config; phantom-dep is expected for scoped plugins loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-commonjs AI (phantom-deps): Rollup plugin loaded via config; phantom-dep is expected for scoped plugins loaded by convention. ai
phantom-deps phantom-dep:rollup-plugin-dts AI (phantom-deps): Rollup plugin loaded via config; phantom-dep is expected for plugins loaded by convention. ai
phantom-deps phantom-dep:rollup AI (phantom-deps): Rollup is a build tool referenced in config; phantom-dep is expected for build tools loaded by convention. ai
phantom-deps phantom-dep:@rollup/plugin-typescript AI (phantom-deps): Rollup plugin loaded via config; phantom-dep is expected for scoped plugins loaded by convention. ai
source-diff net-exec-file:dist/cli/main.js AI (source-diff): CLI tool that makes API calls and uses dynamic module loading; network+exec pattern is expected in bundled CLI output for tscircuit. ai
publish-pattern dormant-publish AI (publish-pattern): Package has 1659 versions over 772 days; dormancy finding appears to be a false positive given the extremely active publish cadence. ai
source-diff obfuscated-file:dist/cli/main.js AI (source-diff): dist/cli/main.js is a bun-bundled CLI entry point; long lines are standard bundler output, not obfuscation. Stable pattern for this package. ai
source-diff encoded-string-file:dist/lib/index.js AI (source-diff): The long encoded string is the llhttp WebAssembly binary (base64-encoded WASM) bundled from undici — a standard, legitimate pattern. Not malicious. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @tscircuit/cli is a scoped package in the established tscircuit ecosystem with 772 days of history and 1659 versions. The Levenshtein match to 'joi' is purely coincidental — no impersonation. ai

Versions (showing 100 of 1731)

Version Deps Published
0.1.1518 0 / 70
0.1.1517 0 / 70
0.1.1516 0 / 70
0.1.1515 0 / 70
0.1.1514 0 / 71
0.1.1513 0 / 71
0.1.1512 0 / 71
0.1.1511 0 / 71
0.1.1510 0 / 71
0.1.1509 0 / 71
0.1.1508 0 / 71
0.1.1507 0 / 71
0.1.1506 0 / 71
0.1.1505 0 / 71
0.1.1504 0 / 71
0.1.1503 0 / 71
0.1.1502 0 / 71
0.1.1501 0 / 71
0.1.1500 0 / 71
0.1.1499 0 / 71
0.1.1498 0 / 71
0.1.1497 0 / 71
0.1.1496 0 / 71
0.1.1495 0 / 69
0.1.1494 0 / 69
0.1.1493 0 / 69
0.1.1492 0 / 69
0.1.1491 0 / 69
0.1.1490 0 / 69
0.1.1489 0 / 69
0.1.1488 0 / 69
0.1.1487 0 / 69
0.1.1486 0 / 69
0.1.1485 0 / 69
0.1.1484 0 / 69
0.1.1483 0 / 69
0.1.1482 0 / 69
0.1.1481 0 / 69
0.1.1480 0 / 69
0.1.1479 0 / 69
0.1.1478 0 / 69
0.1.1477 0 / 69
0.1.1476 0 / 69
0.1.1474 0 / 69
0.1.1473 0 / 69
0.1.1472 0 / 69
0.1.1471 0 / 69
0.1.1470 0 / 69
0.1.1469 0 / 69
0.1.1468 0 / 68
0.1.1467 0 / 68
0.1.1466 0 / 68
0.1.1465 0 / 68
0.1.1464 0 / 68
0.1.1463 0 / 68
0.1.1462 0 / 68
0.1.1461 0 / 68
0.1.1460 0 / 68
0.1.1459 0 / 68
0.1.1458 0 / 68
0.1.1457 0 / 68
0.1.1456 0 / 68
0.1.1455 0 / 68
0.1.1454 0 / 68
0.1.1453 0 / 68
0.1.1452 0 / 68
0.1.1451 0 / 68
0.1.1450 0 / 68
0.1.1449 0 / 68
0.1.1448 0 / 68
0.1.1447 0 / 68
0.1.1446 0 / 68
0.1.1445 0 / 68
0.1.1444 0 / 68
0.1.1443 0 / 68
0.1.1442 0 / 68
0.1.1441 0 / 68
0.1.1440 0 / 68
0.1.1439 0 / 68
0.1.1438 0 / 68
0.1.1437 0 / 68
0.1.1436 0 / 68
0.1.1435 0 / 68
0.1.1434 0 / 68
0.1.1433 0 / 68
0.1.1432 0 / 68
0.1.1431 0 / 68
0.1.1430 0 / 68
0.1.1429 0 / 68
0.1.1428 0 / 68
0.1.1427 0 / 68
0.1.1426 0 / 68
0.1.1425 0 / 68
0.1.1424 0 / 68
0.1.1423 0 / 68
0.1.1422 0 / 68
0.1.1421 0 / 68
0.1.1420 0 / 68
0.1.1419 0 / 68
0.1.1418 0 / 68
Showing 100 of 1731 Next page →