@workflow/cli
Command-line interface for Workflow SDK
13
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
matt.strakavercel-release-bot
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/lib/inspect/vercel-api.test.js | AI (source-diff): Long line is an inline base64 sourcemap on a plain test file, not obfuscation. | ai | |
| phantom-deps | phantom-dep:find-up | AI (phantom-deps): Config file discovery; typical indirect use in CLI tools. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): File watcher used indirectly in dev/watch mode; stable CLI pattern. | ai | |
| phantom-deps | phantom-dep:@swc/core | AI (phantom-deps): Transpiler used indirectly via @workflow/swc-plugin; stable for this package. | ai | |
| phantom-deps | phantom-dep:builtin-modules | AI (phantom-deps): Used indirectly in bundler config; stable pattern. | ai | |
| phantom-deps | phantom-dep:enhanced-resolve | AI (phantom-deps): Module resolution used indirectly in build tooling; stable for this package. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): Declared as oclif plugin in config; loaded dynamically by oclif framework, not directly imported. | ai | |
| phantom-deps | phantom-dep:ora | AI (phantom-deps): CLI spinner; used indirectly via oclif/bundled commands, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Schema validation used indirectly; common in CLI tooling with dynamic imports. | ai | |
| phantom-deps | phantom-dep:mixpart | AI (phantom-deps): Indirect dep; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@workflow/swc-plugin | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. | ai | |
| phantom-deps | phantom-dep:@workflow/world-local | AI (phantom-deps): Same-org sibling dep; phantom-dep heuristic unreliable for monorepo packages. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): Known implicit/binary dependency pattern; stable false positive for build tools. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Package name @workflow/cli is clearly not a typosquat of joi; levenshtein match is spurious. | ai | |
| bogus-package | bogus-package | AI (bogus-package): CLI tool for a SDK; sparse README is expected for internal/org tooling with 451k downloads. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 4.3.1 | 30 / 2 | |
| 4.3.0 | 30 / 2 | |
| 4.2.10 | 30 / 2 | |
| 4.2.9 | 30 / 2 | |
| 4.2.8 | 30 / 2 | |
| 4.2.7 | 30 / 2 | |
| 4.2.6 | 30 / 2 | |
| 4.2.5 | 30 / 2 | |
| 4.2.4 | 30 / 2 | |
| 4.2.3 | 30 / 2 | |
| 4.2.2 | 30 / 2 | |
| 4.2.1 | 30 / 2 | |
| 4.2.0 | 30 / 2 |
v4.3.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
2 findings
HIGH
New obfuscated file: dist/lib/inspect/vercel-api.test.js
source-diff
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.