@xyo-network/xl1-cli
XYO Layer One CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): Declared but not directly imported; framework-scoped usage consistent with this CLI package pattern. | ai | |
| phantom-deps | phantom-dep:msgpackr-extract | AI (phantom-deps): Peer/optional native dep for lmdb; not directly imported but legitimately declared for runtime use. | ai | |
| source-diff | encoded-string-file:dist/cli-min.mjs | AI (source-diff): Rollup-minified CLI bundle; long encoded strings are standard bundler output for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-metrics | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/host-metrics | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-trace-base | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/context-async-hooks | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-prometheus | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-http | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build tool and peer dependency; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-express | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-grpc | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-http | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-runtime-node | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/semantic-conventions | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/resources | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Config-referenced optional instrumentation; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:mongodb | AI (phantom-deps): Config-referenced optional storage backend; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:lmdb | AI (phantom-deps): Config-referenced optional storage backend; stable pattern for this package. | ai |
Versions (showing 51 of 127)
| Version | Deps | Published |
|---|---|---|
| 4.5.4 | 19 / 24 | |
| 4.5.3 | 19 / 22 | |
| 4.5.2 | 19 / 22 | |
| 4.5.1 | 19 / 22 | |
| 4.5.0 | 19 / 22 | |
| 4.4.0 | 19 / 22 | |
| 4.3.2 | 19 / 22 | |
| 4.3.1 | 19 / 23 | |
| 4.3.0 | 19 / 23 | |
| 4.2.1 | 19 / 23 | |
| 4.1.0 | 19 / 25 | |
| 4.0.6 | 19 / 37 | |
| 4.0.5 | 19 / 37 | |
| 4.0.4 | 19 / 67 | |
| 4.0.3 | 19 / 67 | |
| 4.0.2 | 19 / 66 | |
| 4.0.1 | 19 / 66 | |
| 4.0.0 | 19 / 93 | |
| 3.0.2 | 19 / 93 | |
| 3.0.1 | 19 / 93 | |
| 3.0.0 | 19 / 95 | |
| 2.0.18 | 19 / 93 | |
| 2.0.17 | 19 / 93 | |
| 2.0.16 | 19 / 93 | |
| 2.0.13 | 19 / 93 | |
| 2.0.9 | 18 / 112 | |
| 2.0.7 | 18 / 112 | |
| 2.0.5 | 18 / 112 | |
| 2.0.4 | 18 / 111 | |
| 2.0.3 | 18 / 111 | |
| 1.23.0 | 19 / 116 | |
| 1.22.0 | 20 / 120 | |
| 1.20.15 | 22 / 64 | |
| 1.20.14 | 22 / 64 | |
| 1.20.13 | 22 / 64 | |
| 1.20.12 | 22 / 64 | |
| 1.20.11 | 22 / 64 | |
| 1.20.10 | 22 / 63 | |
| 1.20.9 | 22 / 63 | |
| 1.20.8 | 21 / 65 | |
| 1.20.5 | 17 / 23 | |
| 1.20.4 | 17 / 23 | |
| 1.20.3 | 17 / 23 | |
| 1.20.2 | 17 / 23 | |
| 1.20.1 | 17 / 23 | |
| 1.20.0 | 17 / 23 | |
| 1.19.18 | 17 / 23 | |
| 1.19.17 | 17 / 25 | |
| 1.19.16 | 17 / 26 | |
| 1.19.15 | 16 / 29 | |
| 1.19.14 | 17 / 27 |
v4.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.5.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-21, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.4.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-18, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-17, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-15, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.2.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-15, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.5
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (atrouw) than the most recent previously approved version (jonesmac) on 2026-07-08, but atrouw is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (atrouw) on 2026-07-02, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v4.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.10
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2026-03-26, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.20.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2026-03-24, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.20.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jonesmac) than the most recent previously approved version (xyo) on 2026-03-09, but jonesmac is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.20.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (xyo) than the most recent previously approved version (jonesmac) on 2026-03-04, but xyo is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.19.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.