@workglow/cli
Command-line interface example for Workglow, demonstrating how to build and run AI task pipelines from the terminal.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@sroussey/transformers | AI (dependencies): Publisher's own scoped fork, pinned version, consistent across releases. | ai | |
| phantom-deps | phantom-dep:@sroussey/transformers | AI (phantom-deps): Config-referenced, not a real risk. | ai | |
| dependencies | unvetted-dep:retuink | AI (dependencies): Pinned niche dep used by CLI, no malicious indicators. | ai | |
| dependencies | unvetted-dep:@workglow/test | AI (dependencies): Same-org sibling package pinned to matching version. | ai | |
| phantom-deps | phantom-dep:@google/genai | AI (phantom-deps): Provider SDK referenced via config for multi-provider AI CLI, expected pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is an in-house sibling package, not a third-party addition. | ai | |
| dependencies | unvetted-dep:@workglow/xai | AI (dependencies): First-party sibling package, same version-locked monorepo as other @workglow deps. | ai | |
| phantom-deps | phantom-dep:@types/react | AI (phantom-deps): Type-only package; framework-scoped, loaded by convention. | ai | |
| phantom-deps | phantom-dep:react-reconciler | AI (phantom-deps): React ecosystem dep used by ink CLI framework; stable pattern. | ai | |
| phantom-deps | phantom-dep:@mediapipe/tasks-vision | AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. | ai | |
| phantom-deps | phantom-dep:is-unicode-supported | AI (phantom-deps): Utility dep referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@mediapipe/tasks-text | AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. | ai | |
| phantom-deps | phantom-dep:react-devtools-core | AI (phantom-deps): React dev tooling dep; loaded by convention in React CLI apps. | ai | |
| phantom-deps | phantom-dep:@mediapipe/tasks-genai | AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. | ai | |
| phantom-deps | phantom-dep:@mediapipe/tasks-audio | AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Monorepo CLI with externalized deps; declared in package.json, used via bundler config. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Ink-based CLI uses React; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@inkjs/ui | AI (phantom-deps): Ink UI dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): CLI framework dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:smol-toml | AI (phantom-deps): Config parsing dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@workglow/ai | AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@workglow/util | AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@workglow/tasks | AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@napi-rs/keyring | AI (phantom-deps): Native keyring dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@workglow/storage | AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@workglow/task-graph | AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@workglow/ai-provider | AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. | ai | |
| phantom-deps | phantom-dep:@huggingface/transformers | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:@huggingface/inference | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:@google/generative-ai | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:@anthropic-ai/sdk | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:node-llama-cpp | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:tiktoken | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:openai | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:ollama | AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): AI provider deps are declared for optional/dynamic use in this CLI; phantom-dep heuristic is a stable false positive here. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @workglow/cli is a scoped AI CLI package; Levenshtein match to 'joi' is coincidental and not a typosquat. | ai |
Versions (showing 51 of 91)
| Version | Deps | Published |
|---|---|---|
| 0.3.25 | 32 / 1 | |
| 0.3.24 | 31 / 1 | |
| 0.3.23 | 31 / 1 | |
| 0.3.22 | 31 / 1 | |
| 0.3.21 | 31 / 1 | |
| 0.3.20 | 31 / 1 | |
| 0.3.19 | 31 / 1 | |
| 0.3.18 | 31 / 1 | |
| 0.3.16 | 31 / 1 | |
| 0.3.15 | 31 / 1 | |
| 0.3.14 | 31 / 1 | |
| 0.3.13 | 31 / 1 | |
| 0.3.12 | 31 / 1 | |
| 0.3.11 | 31 / 1 | |
| 0.3.10 | 31 / 1 | |
| 0.3.9 | 31 / 1 | |
| 0.3.7 | 31 / 1 | |
| 0.3.6 | 31 / 1 | |
| 0.3.5 | 31 / 1 | |
| 0.3.4 | 31 / 1 | |
| 0.3.3 | 31 / 1 | |
| 0.3.2 | 31 / 1 | |
| 0.3.1 | 31 / 1 | |
| 0.3.0 | 31 / 1 | |
| 0.2.37 | 31 / 1 | |
| 0.2.36 | 31 / 1 | |
| 0.2.35 | 31 / 1 | |
| 0.2.34 | 31 / 1 | |
| 0.2.33 | 31 / 1 | |
| 0.2.32 | 31 / 1 | |
| 0.2.31 | 30 / 1 | |
| 0.2.30 | 30 / 1 | |
| 0.2.29 | 30 / 1 | |
| 0.2.28 | 30 / 1 | |
| 0.2.27 | 21 / 1 | |
| 0.2.26 | 21 / 1 | |
| 0.2.25 | 21 / 1 | |
| 0.2.24 | 21 / 1 | |
| 0.2.23 | 21 / 1 | |
| 0.2.22 | 21 / 1 | |
| 0.2.21 | 21 / 1 | |
| 0.2.20 | 21 / 1 | |
| 0.2.19 | 21 / 1 | |
| 0.2.18 | 21 / 1 | |
| 0.2.17 | 21 / 1 | |
| 0.2.16 | 21 / 1 | |
| 0.2.15 | 21 / 1 | |
| 0.2.14 | 21 / 1 | |
| 0.2.13 | 21 / 1 | |
| 0.2.12 | 21 / 1 | |
| 0.2.11 | 21 / 1 |
v0.3.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.