@walkeros/cli
46
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
alexanderkirtzel
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a declared runtime dep in package.json; phantom-dep heuristic misfires here. | ai | |
| source-diff | net-exec-file:examples/web-serve.js | AI (source-diff): Network+exec pattern is from bundled framework code (Zod, template engine), not a dropper payload. | ai | |
| source-diff | obfuscated-file:examples/web-serve.js | AI (source-diff): Content appears to be a bundled Zod/framework library, not malware — but file should not be in the published package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase fully explained by two new bundled example .mjs files added in this version. | ai | |
| source-diff | net-exec-file:examples/web-serve.mjs | AI (source-diff): Network+exec pattern in bundled example; new Function() is a capability-detection guard, not a dropper. | ai | |
| source-diff | obfuscated-file:examples/web-serve.mjs | AI (source-diff): File is an esbuild-bundled example artifact; minification is expected, not obfuscation. | ai | |
| dependencies | unvetted-dep:@walkeros/docker | AI (dependencies): Internal scoped package from the same elbwalker/walkerOS org; consistent with the package's ecosystem. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Handlebars is a well-known templating library; stable dependency for this CLI package. | ai | |
| phantom-deps | phantom-dep:p-limit | AI (phantom-deps): p-limit is a declared dep used indirectly via config; stable false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; consistent with org-level CI/CD adoption. | ai | |
| phantom-deps | phantom-dep:jsdom | AI (phantom-deps): jsdom is listed as a runtime dependency in package.json; phantom-dep heuristic misfires here. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): express is a declared runtime dependency; phantom-dep heuristic false positive. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @walkeros/cli is the official walkerOS CLI; no resemblance to joi. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function('') used only as a feature-detection check in bundled example file. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get used in a lazy-init proxy pattern in bundled examples; standard JS idiom. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decodes a 1x1 GIF pixel constant in bundled example file; not a payload. | ai | |
| phantom-deps | phantom-dep:cors | AI (phantom-deps): cors is a declared runtime dependency used via express middleware; phantom-dep heuristic false positive. | ai |
Versions (showing 46 of 46)
| Version | Deps | Published |
|---|---|---|
| 4.3.2 | 23 / 12 | |
| 4.3.1 | 23 / 12 | |
| 4.3.0 | 23 / 12 | |
| 4.2.1 | 23 / 12 | |
| 4.2.0 | 23 / 12 | |
| 4.1.2 | 21 / 12 | |
| 4.1.1 | 21 / 12 | |
| 4.1.0 | 21 / 12 | |
| 4.0.2 | 21 / 12 | |
| 4.0.1 | 21 / 12 | |
| 4.0.0 | 18 / 11 | |
| 3.4.2 | 14 / 11 | |
| 3.4.1 | 14 / 11 | |
| 3.4.0 | 14 / 11 | |
| 3.3.1 | 14 / 11 | |
| 3.3.0 | 14 / 11 | |
| 3.2.0 | 14 / 11 | |
| 3.1.1 | 14 / 11 | |
| 3.1.0 | 14 / 11 | |
| 3.0.2 | 14 / 11 | |
| 3.0.1 | 14 / 11 | |
| 3.0.0 | 14 / 11 | |
| 2.1.1 | 13 / 10 | |
| 2.1.0 | 13 / 10 | |
| 2.0.1 | 13 / 10 | |
| 2.0.0 | 12 / 10 | |
| 1.3.0 | 10 / 7 | |
| 1.2.0 | 10 / 7 | |
| 1.1.3 | 10 / 7 | |
| 1.1.2 | 10 / 7 | |
| 1.1.1 | 10 / 7 | |
| 1.1.0 | 10 / 7 | |
| 1.0.2 | 10 / 7 | |
| 1.0.1 | 10 / 7 | |
| 1.0.0 | 10 / 7 | |
| 0.8.0 | 10 / 7 | |
| 0.6.2 | 10 / 7 | |
| 0.6.1 | 10 / 7 | |
| 0.6.0 | 10 / 7 | |
| 0.4.1 | 10 / 5 | |
| 0.3.6 | 9 / 5 | |
| 0.3.5 | 9 / 5 | |
| 0.3.4 | 9 / 5 | |
| 0.3.3 | 9 / 5 | |
| 0.3.2 | 9 / 5 | |
| 0.3.1 | 10 / 5 |
v4.3.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.