← Home

@workglow/cli

Command-line interface example for Workglow, demonstrating how to build and run AI task pipelines from the terminal.

91
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

sroussey

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@sroussey/transformers AI (dependencies): Publisher's own scoped fork, pinned version, consistent across releases. ai
phantom-deps phantom-dep:@sroussey/transformers AI (phantom-deps): Config-referenced, not a real risk. ai
dependencies unvetted-dep:retuink AI (dependencies): Pinned niche dep used by CLI, no malicious indicators. ai
dependencies unvetted-dep:@workglow/test AI (dependencies): Same-org sibling package pinned to matching version. ai
phantom-deps phantom-dep:@google/genai AI (phantom-deps): Provider SDK referenced via config for multi-provider AI CLI, expected pattern. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is an in-house sibling package, not a third-party addition. ai
dependencies unvetted-dep:@workglow/xai AI (dependencies): First-party sibling package, same version-locked monorepo as other @workglow deps. ai
phantom-deps phantom-dep:@types/react AI (phantom-deps): Type-only package; framework-scoped, loaded by convention. ai
phantom-deps phantom-dep:react-reconciler AI (phantom-deps): React ecosystem dep used by ink CLI framework; stable pattern. ai
phantom-deps phantom-dep:@mediapipe/tasks-vision AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. ai
phantom-deps phantom-dep:is-unicode-supported AI (phantom-deps): Utility dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:@mediapipe/tasks-text AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. ai
phantom-deps phantom-dep:react-devtools-core AI (phantom-deps): React dev tooling dep; loaded by convention in React CLI apps. ai
phantom-deps phantom-dep:@mediapipe/tasks-genai AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. ai
phantom-deps phantom-dep:@mediapipe/tasks-audio AI (phantom-deps): Optional mediapipe dep; conditionally loaded by plugin pattern. ai
phantom-deps phantom-dep:ink AI (phantom-deps): Monorepo CLI with externalized deps; declared in package.json, used via bundler config. ai
phantom-deps phantom-dep:react AI (phantom-deps): Ink-based CLI uses React; externalized in bundler config. ai
phantom-deps phantom-dep:@inkjs/ui AI (phantom-deps): Ink UI dep; externalized in bundler config. ai
phantom-deps phantom-dep:commander AI (phantom-deps): CLI framework dep; externalized in bundler config. ai
phantom-deps phantom-dep:smol-toml AI (phantom-deps): Config parsing dep; externalized in bundler config. ai
phantom-deps phantom-dep:@workglow/ai AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. ai
phantom-deps phantom-dep:@workglow/util AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. ai
phantom-deps phantom-dep:@workglow/tasks AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. ai
phantom-deps phantom-dep:@napi-rs/keyring AI (phantom-deps): Native keyring dep; externalized in bundler config. ai
phantom-deps phantom-dep:@workglow/storage AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. ai
phantom-deps phantom-dep:@workglow/task-graph AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. ai
phantom-deps phantom-dep:@workglow/ai-provider AI (phantom-deps): Same-org monorepo dep; externalized in bundler config. ai
phantom-deps phantom-dep:@huggingface/transformers AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:@huggingface/inference AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:@google/generative-ai AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:@anthropic-ai/sdk AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:node-llama-cpp AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:tiktoken AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:openai AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:ollama AI (phantom-deps): Optional AI provider dependency; dynamically loaded pattern expected for this CLI. ai
phantom-deps phantom-dep:chalk AI (phantom-deps): AI provider deps are declared for optional/dynamic use in this CLI; phantom-dep heuristic is a stable false positive here. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @workglow/cli is a scoped AI CLI package; Levenshtein match to 'joi' is coincidental and not a typosquat. ai

Versions (showing 91 of 91)

Version Deps Published
0.3.25 32 / 1
0.3.24 31 / 1
0.3.23 31 / 1
0.3.22 31 / 1
0.3.21 31 / 1
0.3.20 31 / 1
0.3.19 31 / 1
0.3.18 31 / 1
0.3.16 31 / 1
0.3.15 31 / 1
0.3.14 31 / 1
0.3.13 31 / 1
0.3.12 31 / 1
0.3.11 31 / 1
0.3.10 31 / 1
0.3.9 31 / 1
0.3.7 31 / 1
0.3.6 31 / 1
0.3.5 31 / 1
0.3.4 31 / 1
0.3.3 31 / 1
0.3.2 31 / 1
0.3.1 31 / 1
0.3.0 31 / 1
0.2.37 31 / 1
0.2.36 31 / 1
0.2.35 31 / 1
0.2.34 31 / 1
0.2.33 31 / 1
0.2.32 31 / 1
0.2.31 30 / 1
0.2.30 30 / 1
0.2.29 30 / 1
0.2.28 30 / 1
0.2.27 21 / 1
0.2.26 21 / 1
0.2.25 21 / 1
0.2.24 21 / 1
0.2.23 21 / 1
0.2.22 21 / 1
0.2.21 21 / 1
0.2.20 21 / 1
0.2.19 21 / 1
0.2.18 21 / 1
0.2.17 21 / 1
0.2.16 21 / 1
0.2.15 21 / 1
0.2.14 21 / 1
0.2.13 21 / 1
0.2.12 21 / 1
0.2.11 21 / 1
0.2.10 21 / 1
0.2.9 21 / 1
0.2.8 21 / 1
0.2.7 21 / 1
0.2.6 21 / 1
0.2.5 21 / 1
0.2.4 21 / 1
0.2.3 21 / 1
0.2.2 21 / 1
0.2.1 21 / 1
0.2.0 21 / 1
0.1.2 20 / 1
0.1.1 20 / 1
0.1.0 20 / 1
0.0.126 20 / 1
0.0.125 20 / 1
0.0.124 20 / 1
0.0.123 20 / 1
0.0.122 20 / 1
0.0.121 26 / 0
0.0.120 26 / 0
0.0.119 26 / 0
0.0.118 26 / 0
0.0.117 26 / 0
0.0.116 26 / 0
0.0.115 26 / 0
0.0.114 26 / 0
0.0.113 26 / 0
0.0.110 26 / 0
0.0.109 26 / 0
0.0.102 26 / 0
0.0.101 26 / 0
0.0.100 26 / 0
0.0.73 20 / 0
0.0.64 17 / 0
0.0.58 17 / 0
0.0.57 17 / 0
0.0.55 17 / 0
0.0.53 17 / 0
0.0.52 17 / 0

v0.3.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.73

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.64

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.