@xyo-network/xl1-cli
XYO Layer One CLI
27
Versions
LGPL-3.0-only
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
atrouwjoelbcarterrphansen91jordantrouwjonesmac
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): Declared but not directly imported; framework-scoped usage consistent with this CLI package pattern. | ai | |
| phantom-deps | phantom-dep:msgpackr-extract | AI (phantom-deps): Peer/optional native dep for lmdb; not directly imported but legitimately declared for runtime use. | ai | |
| source-diff | encoded-string-file:dist/cli-min.mjs | AI (source-diff): Rollup-minified CLI bundle; long encoded strings are standard bundler output for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-metrics | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/host-metrics | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-trace-base | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/context-async-hooks | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-prometheus | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-http | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build tool and peer dependency; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-express | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-grpc | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/exporter-trace-otlp-http | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/instrumentation-runtime-node | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/semantic-conventions | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/resources | AI (phantom-deps): Instrumentation framework; used dynamically; stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Config-referenced optional instrumentation; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:mongodb | AI (phantom-deps): Config-referenced optional storage backend; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:lmdb | AI (phantom-deps): Config-referenced optional storage backend; stable pattern for this package. | ai |
Versions (showing 27 of 127)
| Version | Deps | Published |
|---|---|---|
| 1.16.2 | 17 / 39 | |
| 1.15.25 | 17 / 39 | |
| 1.15.21 | 17 / 39 | |
| 1.15.20 | 17 / 39 | |
| 1.15.16 | 17 / 39 | |
| 1.15.13 | 17 / 39 | |
| 1.15.12 | 17 / 39 | |
| 1.15.11 | 17 / 39 | |
| 1.15.10 | 17 / 39 | |
| 1.15.9 | 17 / 39 | |
| 1.15.6 | 17 / 39 | |
| 1.15.0 | 17 / 39 | |
| 1.14.2 | 17 / 39 | |
| 1.14.1 | 17 / 39 | |
| 1.14.0 | 2 / 40 | |
| 1.12.6 | 2 / 38 | |
| 1.12.0 | 1 / 48 | |
| 1.11.0 | 1 / 48 | |
| 1.10.0 | 1 / 48 | |
| 1.9.0 | 1 / 48 | |
| 1.8.1 | 1 / 48 | |
| 1.8.0 | 1 / 48 | |
| 1.7.11 | 1 / 48 | |
| 1.7.10 | 1 / 48 | |
| 1.7.9 | 1 / 48 | |
| 1.7.7 | 1 / 48 | |
| 1.7.6 | 1 / 48 |
v1.16.2
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.