@willbooster/wb
CLI tool for WillBooster projects
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): Bundled CLI output; consistent with other accepted phantom deps. | ai | |
| phantom-deps | phantom-dep:fast-glob | AI (phantom-deps): Bundled CLI output; consistent with other accepted phantom deps for this package. | ai | |
| phantom-deps | phantom-dep:smol-toml | AI (phantom-deps): New minor dep for TOML parsing, likely used in bundled dist. | ai | |
| phantom-deps | phantom-dep:fastest-levenshtein | AI (phantom-deps): Bundled CLI output; consistent with other accepted phantom deps. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Used in config files; well-known utility dep. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): dotenv CLI legitimately builds env context for its export command; no external exfil target. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Config-library env enumeration, expected for a dotenv tool. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from manual publish (exkazuu) to GitHub Actions CI/CD is confirmed by SLSA provenance attestation; stable for this package going forward. | ai | |
| phantom-deps | phantom-dep:minimal-promise-pool | AI (phantom-deps): Runtime dep declared in package.json; stable false positive for this CLI tool. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Runtime dep declared in package.json; CLI tool may use it indirectly via config/build patterns. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): Runtime dep declared in package.json; CLI tool uses yargs for argument parsing. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): Runtime dep declared in package.json; stable false positive for this CLI tool. | ai | |
| phantom-deps | phantom-dep:globby | AI (phantom-deps): Runtime dep declared in package.json; stable false positive for this CLI tool. | ai | |
| phantom-deps | phantom-dep:kill-port | AI (phantom-deps): Runtime dep declared in package.json; stable false positive for this CLI tool. | ai | |
| phantom-deps | phantom-dep:dotenv-expand | AI (phantom-deps): Runtime dep declared in package.json; stable false positive for this CLI tool. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @willbooster/wb; Levenshtein match to 'pg' is a false positive with no impersonation intent. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @willbooster/wb; Levenshtein match to 'qs' is a false positive with no impersonation intent. | ai |
Versions (showing 51 of 204)
| Version | Deps | Published |
|---|---|---|
| 19.5.1 | 12 / 24 | |
| 19.5.0 | 12 / 24 | |
| 19.4.0 | 12 / 24 | |
| 19.3.1 | 12 / 24 | |
| 19.3.0 | 12 / 24 | |
| 19.2.1 | 12 / 24 | |
| 19.2.0 | 12 / 24 | |
| 19.1.0 | 12 / 24 | |
| 19.0.2 | 12 / 24 | |
| 19.0.1 | 12 / 24 | |
| 19.0.0 | 12 / 24 | |
| 18.0.1 | 12 / 24 | |
| 18.0.0 | 11 / 24 | |
| 17.0.0 | 11 / 24 | |
| 16.1.1 | 11 / 24 | |
| 16.1.0 | 11 / 24 | |
| 16.0.1 | 11 / 24 | |
| 16.0.0 | 11 / 24 | |
| 15.4.0 | 11 / 24 | |
| 15.3.0 | 11 / 24 | |
| 15.2.2 | 11 / 24 | |
| 15.2.1 | 11 / 24 | |
| 15.2.0 | 11 / 24 | |
| 15.1.1 | 11 / 24 | |
| 15.1.0 | 11 / 24 | |
| 15.0.4 | 11 / 24 | |
| 15.0.3 | 11 / 24 | |
| 15.0.2 | 11 / 24 | |
| 15.0.1 | 10 / 24 | |
| 15.0.0 | 9 / 23 | |
| 14.2.0 | 9 / 23 | |
| 14.1.0 | 9 / 23 | |
| 14.0.0 | 9 / 21 | |
| 13.28.8 | 9 / 21 | |
| 13.28.7 | 9 / 21 | |
| 13.28.6 | 9 / 21 | |
| 13.28.5 | 9 / 21 | |
| 13.28.4 | 9 / 21 | |
| 13.28.3 | 9 / 21 | |
| 13.28.2 | 9 / 21 | |
| 13.28.1 | 9 / 21 | |
| 13.28.0 | 9 / 21 | |
| 13.27.0 | 8 / 21 | |
| 13.26.2 | 8 / 21 | |
| 13.26.1 | 8 / 21 | |
| 13.26.0 | 8 / 21 | |
| 13.25.3 | 8 / 21 | |
| 13.25.2 | 8 / 21 | |
| 13.25.1 | 8 / 21 | |
| 13.25.0 | 8 / 21 | |
| 13.24.0 | 8 / 21 |
v19.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v19.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v18.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v18.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v17.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v16.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.0.1
2 findingsSpreading entire process.env into an object — may capture all secrets Source: https://github.com/WillBooster/shared/blob/3e8fe5dc0c5eb5c90a33a72d8f7eed7940c3854a/bin/dotenv.js#L193 191 | // `--non-interactive`: prompts or browser auth flows would hang forever because stdin is ignored. 192 | const args = ['export', '--format', 'json', '--no-color', '--if-missing', 'error', '--non-interactive']; > 193 | const env = { ...process.env }; 194 | if (cascade) { 195 | args.push('--profile', cascade);
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v15.0.0
2 findingsSpreading entire process.env into an object — may capture all secrets Source: https://github.com/WillBooster/shared/blob/90c991875037f0bfc8965a093c7f951141a43ff2/bin/dotenv.js#L193 191 | // `--non-interactive`: prompts or browser auth flows would hang forever because stdin is ignored. 192 | const args = ['export', '--format', 'json', '--no-color', '--if-missing', 'error', '--non-interactive']; > 193 | const env = { ...process.env }; 194 | if (cascade) { 195 | args.push('--profile', cascade);
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.2.0
2 findingsSpreading entire process.env into an object — may capture all secrets Source: https://github.com/WillBooster/shared/blob/f055f274c099ea36fd05a15cbd76452fabbc3a4a/bin/dotenv.js#L156 154 | // `--non-interactive`: prompts or browser auth flows would hang forever because stdin is ignored. 155 | const args = ['export', '--format', 'json', '--no-color', '--if-missing', 'error', '--non-interactive']; > 156 | const env = { ...process.env }; 157 | if (cascade) { 158 | args.push('--profile', cascade);
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v14.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.28.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.27.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.26.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.26.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.25.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.25.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.25.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v13.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.