@zintrust/core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decode used for AES-256-GCM IV and auth tag parsing — legitimate crypto pattern. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall is a no-op process.exit(0); stable false positive for this package. | ai | |
| semgrep | semgrep:silent-process-exec | AI (semgrep): Detached spawn in VersionChecker is a self-restart pattern for CLI version upgrades, not a reverse shell. | ai | |
| semgrep | semgrep:silent-process-exec-var | AI (semgrep): Same VersionChecker self-restart context; benign for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get inside a Proxy get trap is idiomatic JS; not obfuscation. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding JWT/auth token bodies in ServiceAuthMiddleware is standard auth middleware practice. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @zintrust/core is a framework, not a typosquat of cors; name collision is coincidental. | ai | |
| phantom-deps | phantom-dep:@zintrust/workers | AI (phantom-deps): Same-org sibling package loaded by framework convention. | ai | |
| phantom-deps | phantom-dep:@cloudflare/containers | AI (phantom-deps): Framework-scoped Cloudflare package loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:bullmq | AI (phantom-deps): bullmq is a declared dependency used via config/convention in this framework. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): env-spread passes process.env to a child process spawn — standard CLI framework pattern, not exfiltration. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All raw-IP references are localhost (127.0.0.1) log messages, not external network calls. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads process.env to build worker dev-vars config file — expected framework behavior. | ai |
Versions (showing 100 of 229)
| Version | Deps | Published |
|---|---|---|
| 0.4.80 | 9 / 0 | |
| 0.4.79 | 9 / 0 | |
| 0.4.77 | 9 / 0 | |
| 0.4.76 | 9 / 0 | |
| 0.4.75 | 9 / 0 | |
| 0.4.74 | 9 / 0 | |
| 0.4.72 | 9 / 0 | |
| 0.4.71 | 9 / 0 | |
| 0.4.70 | 9 / 0 | |
| 0.4.68 | 9 / 0 | |
| 0.4.67 | 9 / 0 | |
| 0.4.66 | 9 / 0 | |
| 0.4.65 | 9 / 0 | |
| 0.4.64 | 9 / 0 | |
| 0.4.63 | 9 / 0 | |
| 0.4.62 | 9 / 0 | |
| 0.4.61 | 10 / 0 | |
| 0.4.60 | 10 / 0 | |
| 0.4.59 | 10 / 0 | |
| 0.4.58 | 10 / 0 | |
| 0.4.57 | 10 / 0 | |
| 0.4.56 | 10 / 0 | |
| 0.4.55 | 8 / 0 | |
| 0.4.54 | 8 / 0 | |
| 0.4.53 | 8 / 0 | |
| 0.4.52 | 8 / 0 | |
| 0.4.51 | 8 / 0 | |
| 0.4.50 | 10 / 0 | |
| 0.4.49 | 10 / 0 | |
| 0.4.43 | 10 / 0 | |
| 0.4.42 | 10 / 0 | |
| 0.4.41 | 10 / 0 | |
| 0.4.40 | 10 / 0 | |
| 0.4.39 | 10 / 0 | |
| 0.4.38 | 10 / 0 | |
| 0.4.36 | 10 / 0 | |
| 0.4.34 | 10 / 0 | |
| 0.4.33 | 10 / 0 | |
| 0.4.32 | 10 / 0 | |
| 0.4.31 | 10 / 0 | |
| 0.4.30 | 10 / 0 | |
| 0.4.29 | 10 / 0 | |
| 0.4.27 | 10 / 0 | |
| 0.4.26 | 10 / 0 | |
| 0.4.24 | 10 / 0 | |
| 0.4.22 | 10 / 0 | |
| 0.4.21 | 10 / 0 | |
| 0.4.20 | 10 / 0 | |
| 0.4.19 | 10 / 0 | |
| 0.4.18 | 10 / 0 | |
| 0.4.17 | 10 / 35 | |
| 0.4.16 | 10 / 0 | |
| 0.4.15 | 10 / 0 | |
| 0.4.14 | 10 / 0 | |
| 0.4.13 | 10 / 0 | |
| 0.4.12 | 10 / 0 | |
| 0.4.11 | 10 / 0 | |
| 0.4.10 | 10 / 0 | |
| 0.4.9 | 10 / 0 | |
| 0.4.8 | 10 / 0 | |
| 0.4.7 | 10 / 0 | |
| 0.4.6 | 10 / 0 | |
| 0.4.5 | 10 / 0 | |
| 0.4.4 | 10 / 0 | |
| 0.4.3 | 10 / 0 | |
| 0.4.2 | 10 / 0 | |
| 0.4.1 | 10 / 0 | |
| 0.4.0 | 10 / 0 | |
| 0.1.54 | 10 / 0 | |
| 0.1.53 | 10 / 0 | |
| 0.1.52 | 10 / 0 | |
| 0.1.51 | 10 / 0 | |
| 0.1.50 | 10 / 0 | |
| 0.1.49 | 10 / 0 | |
| 0.1.48 | 10 / 0 | |
| 0.1.46 | 10 / 0 | |
| 0.1.44 | 9 / 0 | |
| 0.1.43 | 9 / 0 | |
| 0.1.42 | 9 / 0 | |
| 0.1.41 | 9 / 0 | |
| 0.1.40 | 5 / 0 | |
| 0.1.39 | 5 / 0 | |
| 0.1.38 | 5 / 0 | |
| 0.1.37 | 5 / 0 | |
| 0.1.36 | 5 / 0 | |
| 0.1.35 | 5 / 0 | |
| 0.1.34 | 5 / 0 | |
| 0.1.33 | 5 / 0 | |
| 0.1.32 | 5 / 0 | |
| 0.1.31 | 5 / 0 | |
| 0.1.30 | 5 / 0 | |
| 0.1.29 | 5 / 0 | |
| 0.1.28 | 5 / 31 | |
| 0.1.27 | 5 / 0 | |
| 0.1.26 | 5 / 0 | |
| 0.1.25 | 5 / 0 | |
| 0.1.24 | 5 / 0 | |
| 0.1.23 | 5 / 0 | |
| 0.1.20 | 5 / 0 | |
| 0.1.19 | 5 / 0 |
v0.4.80
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9d4407acf4ed3fd1d60b6d42986b567be49e8fae/bin/zintrust-main.js#L78 76 | const child = spawn(process.execPath, [target.binPath, ...rawArgs], { 77 | stdio: 'inherit', > 78 | env: { 79 | ...process.env, 80 | [CLI_HANDOFF_ENV_KEY]: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9d4407acf4ed3fd1d60b6d42986b567be49e8fae/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9d4407acf4ed3fd1d60b6d42986b567be49e8fae/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9d4407acf4ed3fd1d60b6d42986b567be49e8fae/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9d4407acf4ed3fd1d60b6d42986b567be49e8fae/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.79
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f39a51a5fb324f867d0e7bb247989564a16913e7/bin/zintrust-main.js#L71 69 | const result = spawnSync(process.execPath, [target.binPath, ...rawArgs], { 70 | stdio: 'inherit', > 71 | env: { 72 | ...process.env, 73 | [CLI_HANDOFF_ENV_KEY]: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f39a51a5fb324f867d0e7bb247989564a16913e7/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f39a51a5fb324f867d0e7bb247989564a16913e7/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f39a51a5fb324f867d0e7bb247989564a16913e7/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f39a51a5fb324f867d0e7bb247989564a16913e7/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.77
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f37a0c05b1ac7aa7da1e38ec7bf0c778486f6187/bin/zintrust-main.js#L71 69 | const result = spawnSync(process.execPath, [target.binPath, ...rawArgs], { 70 | stdio: 'inherit', > 71 | env: { 72 | ...process.env, 73 | [CLI_HANDOFF_ENV_KEY]: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f37a0c05b1ac7aa7da1e38ec7bf0c778486f6187/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f37a0c05b1ac7aa7da1e38ec7bf0c778486f6187/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f37a0c05b1ac7aa7da1e38ec7bf0c778486f6187/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f37a0c05b1ac7aa7da1e38ec7bf0c778486f6187/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.76
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/29c16e362b97a3d9dc827fdd238f0df6f6c8d52c/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/29c16e362b97a3d9dc827fdd238f0df6f6c8d52c/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/29c16e362b97a3d9dc827fdd238f0df6f6c8d52c/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/29c16e362b97a3d9dc827fdd238f0df6f6c8d52c/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.75
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f910e7ecb3034331dcea8d06f38a588c8ad4708f/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f910e7ecb3034331dcea8d06f38a588c8ad4708f/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f910e7ecb3034331dcea8d06f38a588c8ad4708f/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f910e7ecb3034331dcea8d06f38a588c8ad4708f/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.74
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9bdfc570310619465dabebff579fd77d3e3ce5ad/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9bdfc570310619465dabebff579fd77d3e3ce5ad/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9bdfc570310619465dabebff579fd77d3e3ce5ad/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9bdfc570310619465dabebff579fd77d3e3ce5ad/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.72
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.71
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/996fb4dcc000059c9e456acb6d125fdba5c872d5/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.70
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b92b2b05efd6341b64aa9151b8ab9ffec74b8b57/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b92b2b05efd6341b64aa9151b8ab9ffec74b8b57/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b92b2b05efd6341b64aa9151b8ab9ffec74b8b57/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b92b2b05efd6341b64aa9151b8ab9ffec74b8b57/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.68
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.67
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f5a9d786805ba4b86575f54c51ff82372e4a783a/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.66
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/27ba2c052b5cf1079d6be49cf1cb960d62d0ca4a/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/27ba2c052b5cf1079d6be49cf1cb960d62d0ca4a/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/27ba2c052b5cf1079d6be49cf1cb960d62d0ca4a/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/27ba2c052b5cf1079d6be49cf1cb960d62d0ca4a/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.65
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/018dcfe5dfa23dfb59bcd010a32ac9fd01ba0dcc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/018dcfe5dfa23dfb59bcd010a32ac9fd01ba0dcc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/018dcfe5dfa23dfb59bcd010a32ac9fd01ba0dcc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/018dcfe5dfa23dfb59bcd010a32ac9fd01ba0dcc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.64
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/ca40f4760248225054a1586281fa688df3c8c1dc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/ca40f4760248225054a1586281fa688df3c8c1dc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/ca40f4760248225054a1586281fa688df3c8c1dc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/ca40f4760248225054a1586281fa688df3c8c1dc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.63
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/533afc24e8d29716860ea13d6e7346dab71e065b/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/533afc24e8d29716860ea13d6e7346dab71e065b/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/533afc24e8d29716860ea13d6e7346dab71e065b/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/533afc24e8d29716860ea13d6e7346dab71e065b/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.62
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9405f5ded9ec6d627706fca4d3e9c71a31e951d9/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9405f5ded9ec6d627706fca4d3e9c71a31e951d9/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9405f5ded9ec6d627706fca4d3e9c71a31e951d9/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9405f5ded9ec6d627706fca4d3e9c71a31e951d9/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.61
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b4dbe529010cf49021ced0145ab9580fee46a046/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b4dbe529010cf49021ced0145ab9580fee46a046/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b4dbe529010cf49021ced0145ab9580fee46a046/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b4dbe529010cf49021ced0145ab9580fee46a046/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.60
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/be058c1d3ff6ccedc14c0818851762c5dc5fe662/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/be058c1d3ff6ccedc14c0818851762c5dc5fe662/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/be058c1d3ff6ccedc14c0818851762c5dc5fe662/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/be058c1d3ff6ccedc14c0818851762c5dc5fe662/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.59
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.58
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.57
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.56
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/99e4d331e8b3f526a8bbceeec7d9269eb1072b81/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.55
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.54
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.53
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.52
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.51
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8b60bc094277e6d952d6252f231e7f3a9232b1bc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.49
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/85c26a1c8b57e454756103e71c09c72ddfc4876e/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/85c26a1c8b57e454756103e71c09c72ddfc4876e/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/85c26a1c8b57e454756103e71c09c72ddfc4876e/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/85c26a1c8b57e454756103e71c09c72ddfc4876e/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.43
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/57e4d1b5e1980814b1db07b9227db48133adac65/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/57e4d1b5e1980814b1db07b9227db48133adac65/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/57e4d1b5e1980814b1db07b9227db48133adac65/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/57e4d1b5e1980814b1db07b9227db48133adac65/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.42
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/72821e8d432a28dfd59846c3c543f47bfbbe3bfb/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/72821e8d432a28dfd59846c3c543f47bfbbe3bfb/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/72821e8d432a28dfd59846c3c543f47bfbbe3bfb/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/72821e8d432a28dfd59846c3c543f47bfbbe3bfb/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.41
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4c539a14bbf17128dcc1d4da6aea29904c4c1ddc/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4c539a14bbf17128dcc1d4da6aea29904c4c1ddc/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4c539a14bbf17128dcc1d4da6aea29904c4c1ddc/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4c539a14bbf17128dcc1d4da6aea29904c4c1ddc/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.40
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02a830c9f71aaef2eb3ce7b46c32c7ba5ddc6795/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02a830c9f71aaef2eb3ce7b46c32c7ba5ddc6795/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02a830c9f71aaef2eb3ce7b46c32c7ba5ddc6795/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02a830c9f71aaef2eb3ce7b46c32c7ba5ddc6795/src/cli/commands/StartCommand.js#L336 334 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 335 | }; > 336 | const buildStartEnv = (projectRoot) => ({ 337 | ...process.env, 338 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.39
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/0d093bc60d186159627a46a3543feb88500238e2/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/0d093bc60d186159627a46a3543feb88500238e2/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/0d093bc60d186159627a46a3543feb88500238e2/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/0d093bc60d186159627a46a3543feb88500238e2/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.38
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b929eccf77497892f6b07693b8eece3336f74b52/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b929eccf77497892f6b07693b8eece3336f74b52/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b929eccf77497892f6b07693b8eece3336f74b52/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b929eccf77497892f6b07693b8eece3336f74b52/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.36
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/a45b4628325862f693392334e50c1d750379a6fd/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/a45b4628325862f693392334e50c1d750379a6fd/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/a45b4628325862f693392334e50c1d750379a6fd/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/a45b4628325862f693392334e50c1d750379a6fd/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.34
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4abfecc68af8ced9c8d19d9dfea3e60b3e8d44d4/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4abfecc68af8ced9c8d19d9dfea3e60b3e8d44d4/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4abfecc68af8ced9c8d19d9dfea3e60b3e8d44d4/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4abfecc68af8ced9c8d19d9dfea3e60b3e8d44d4/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.33
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0155de9f5fd164a7fc93bf9b23e0a009a772e00/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0155de9f5fd164a7fc93bf9b23e0a009a772e00/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0155de9f5fd164a7fc93bf9b23e0a009a772e00/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0155de9f5fd164a7fc93bf9b23e0a009a772e00/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.32
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/aeab3f04f0614c20916b08f47b7325a264e054a8/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/aeab3f04f0614c20916b08f47b7325a264e054a8/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/aeab3f04f0614c20916b08f47b7325a264e054a8/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/aeab3f04f0614c20916b08f47b7325a264e054a8/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.31
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.30
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.29
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/ProxyCommand.js#L51 49 | command: 'tsx', 50 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 51 | env: { 52 | ...process.env, 53 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8e198e73ee7d12e0febe32aecd0fe2252d7c3cf6/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.27
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/abcaf9aeadf269637a61b104891ee0e9c3473f83/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/abcaf9aeadf269637a61b104891ee0e9c3473f83/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/abcaf9aeadf269637a61b104891ee0e9c3473f83/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/abcaf9aeadf269637a61b104891ee0e9c3473f83/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.26
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/69efc09452e6230c6e96d0141f0d291e5199707b/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/69efc09452e6230c6e96d0141f0d291e5199707b/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/69efc09452e6230c6e96d0141f0d291e5199707b/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/69efc09452e6230c6e96d0141f0d291e5199707b/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.24
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/3a24c13e5a96ff8aee4b1e35d1823a5d0bedc19b/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/3a24c13e5a96ff8aee4b1e35d1823a5d0bedc19b/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/3a24c13e5a96ff8aee4b1e35d1823a5d0bedc19b/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/3a24c13e5a96ff8aee4b1e35d1823a5d0bedc19b/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.22
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/94caf69e2c6b7a4d89e80dd47743ef742c886572/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/94caf69e2c6b7a4d89e80dd47743ef742c886572/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/94caf69e2c6b7a4d89e80dd47743ef742c886572/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/94caf69e2c6b7a4d89e80dd47743ef742c886572/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.21
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4923f4c2bc901a2156976a5eb3f76f548427ece1/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4923f4c2bc901a2156976a5eb3f76f548427ece1/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4923f4c2bc901a2156976a5eb3f76f548427ece1/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4923f4c2bc901a2156976a5eb3f76f548427ece1/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.20
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/597f453f88968045ba10b7dc986177663a923ca2/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/597f453f88968045ba10b7dc986177663a923ca2/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/597f453f88968045ba10b7dc986177663a923ca2/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/597f453f88968045ba10b7dc986177663a923ca2/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.19
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/eb3dbc5b32699ffd587df085e3ee9b68a1fd936c/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/eb3dbc5b32699ffd587df085e3ee9b68a1fd936c/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/eb3dbc5b32699ffd587df085e3ee9b68a1fd936c/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/eb3dbc5b32699ffd587df085e3ee9b68a1fd936c/src/cli/commands/StartCommand.js#L335 333 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 334 | }; > 335 | const buildStartEnv = (projectRoot) => ({ 336 | ...process.env, 337 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.18
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0142a174359ecfbcae1e90eba4afb52b74d2062/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0142a174359ecfbcae1e90eba4afb52b74d2062/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0142a174359ecfbcae1e90eba4afb52b74d2062/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f0142a174359ecfbcae1e90eba4afb52b74d2062/src/cli/commands/StartCommand.js#L267 265 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 266 | }; > 267 | const buildStartEnv = (projectRoot) => ({ 268 | ...process.env, 269 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.17
7 findingsScript: node -e "process.exit(0)"
Package name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4a261f18c97f0988501622bc851750f936bf596a/src/cli/commands/D1LearnCommand.ts#L77 75 | const child = spawn(cmd, args, { 76 | stdio: 'inherit', > 77 | env: { 78 | ...process.env, 79 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4a261f18c97f0988501622bc851750f936bf596a/src/cli/commands/ProxyCommand.ts#L60 58 | command: 'tsx', 59 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 60 | env: { 61 | ...process.env, 62 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4a261f18c97f0988501622bc851750f936bf596a/src/cli/commands/ProxyCommandUtils.ts#L45 43 | command: 'tsx', 44 | args, > 45 | env: { 46 | ...process.env, 47 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/4a261f18c97f0988501622bc851750f936bf596a/src/cli/commands/StartCommand.ts#L350 348 | }; 349 | > 350 | const buildStartEnv = (projectRoot: string): NodeJS.ProcessEnv => ({ 351 | ...process.env, 352 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.16
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8a816541e7f7dc39c2d491a6b3801a7175f33946/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8a816541e7f7dc39c2d491a6b3801a7175f33946/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8a816541e7f7dc39c2d491a6b3801a7175f33946/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8a816541e7f7dc39c2d491a6b3801a7175f33946/src/cli/commands/StartCommand.js#L234 232 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 233 | }; > 234 | const buildStartEnv = (projectRoot) => ({ 235 | ...process.env, 236 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.15
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/793b17b50b67fd64522924a44407eff57fc5b82b/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/793b17b50b67fd64522924a44407eff57fc5b82b/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/793b17b50b67fd64522924a44407eff57fc5b82b/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/793b17b50b67fd64522924a44407eff57fc5b82b/src/cli/commands/StartCommand.js#L234 232 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 233 | }; > 234 | const buildStartEnv = (projectRoot) => ({ 235 | ...process.env, 236 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.14
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/StartCommand.js#L234 232 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 233 | }; > 234 | const buildStartEnv = (projectRoot) => ({ 235 | ...process.env, 236 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.13
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8ce464f533976f3a652c77136db95c4789d10b4c/src/cli/commands/StartCommand.js#L230 228 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 229 | }; > 230 | const buildStartEnv = (projectRoot) => ({ 231 | ...process.env, 232 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.12
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c46357e2e6b0367085ed0ca75f3221eb6132111a/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c46357e2e6b0367085ed0ca75f3221eb6132111a/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c46357e2e6b0367085ed0ca75f3221eb6132111a/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c46357e2e6b0367085ed0ca75f3221eb6132111a/src/cli/commands/StartCommand.js#L209 207 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 208 | }; > 209 | const buildStartEnv = (projectRoot) => ({ 210 | ...process.env, 211 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.11
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/StartCommand.js#L209 207 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 208 | }; > 209 | const buildStartEnv = (projectRoot) => ({ 210 | ...process.env, 211 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.10
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/afdd465b64fd11621915b3abb94a4ed62f70937d/src/cli/commands/StartCommand.js#L209 207 | throw ErrorFactory.createCliError("Error: No ZinTrust app found. Run 'zin new <project>' or ensure package.json exis 208 | }; > 209 | const buildStartEnv = (projectRoot) => ({ 210 | ...process.env, 211 | ZINTRUST_PROJECT_ROOT: projectRoot,
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.9
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b5307c7e81a9ab38f3d77c695ebbf0af7a4a168d/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b5307c7e81a9ab38f3d77c695ebbf0af7a4a168d/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b5307c7e81a9ab38f3d77c695ebbf0af7a4a168d/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b5307c7e81a9ab38f3d77c695ebbf0af7a4a168d/src/cli/commands/StartCommand.js#L401 399 | const webDev = resolveNodeDevCommand(cwd, packageJson); 400 | // Producer Environment > 401 | const producerEnv = { 402 | ...process.env, 403 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/b5307c7e81a9ab38f3d77c695ebbf0af7a4a168d/src/cli/commands/StartCommand.js#L408 406 | }; 407 | // Consumer Environment > 408 | const consumerEnv = { 409 | ...process.env, 410 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.8
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/366640e7cf3bcba2f8c9c7cb8e32781e4cf9967e/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/366640e7cf3bcba2f8c9c7cb8e32781e4cf9967e/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/366640e7cf3bcba2f8c9c7cb8e32781e4cf9967e/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/366640e7cf3bcba2f8c9c7cb8e32781e4cf9967e/src/cli/commands/StartCommand.js#L401 399 | const webDev = resolveNodeDevCommand(cwd, packageJson); 400 | // Producer Environment > 401 | const producerEnv = { 402 | ...process.env, 403 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/366640e7cf3bcba2f8c9c7cb8e32781e4cf9967e/src/cli/commands/StartCommand.js#L408 406 | }; 407 | // Consumer Environment > 408 | const consumerEnv = { 409 | ...process.env, 410 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.7
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9a1e439f428ddb89987c8c7e54e925b2c0b2fc65/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9a1e439f428ddb89987c8c7e54e925b2c0b2fc65/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9a1e439f428ddb89987c8c7e54e925b2c0b2fc65/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9a1e439f428ddb89987c8c7e54e925b2c0b2fc65/src/cli/commands/StartCommand.js#L401 399 | const webDev = resolveNodeDevCommand(cwd, packageJson); 400 | // Producer Environment > 401 | const producerEnv = { 402 | ...process.env, 403 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9a1e439f428ddb89987c8c7e54e925b2c0b2fc65/src/cli/commands/StartCommand.js#L408 406 | }; 407 | // Consumer Environment > 408 | const consumerEnv = { 409 | ...process.env, 410 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.6
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6e8f8339f894d7d598bcadea883c8edb8633b9ec/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6e8f8339f894d7d598bcadea883c8edb8633b9ec/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6e8f8339f894d7d598bcadea883c8edb8633b9ec/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6e8f8339f894d7d598bcadea883c8edb8633b9ec/src/cli/commands/StartCommand.js#L401 399 | const webDev = resolveNodeDevCommand(cwd, packageJson); 400 | // Producer Environment > 401 | const producerEnv = { 402 | ...process.env, 403 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6e8f8339f894d7d598bcadea883c8edb8633b9ec/src/cli/commands/StartCommand.js#L408 406 | }; 407 | // Consumer Environment > 408 | const consumerEnv = { 409 | ...process.env, 410 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.5
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c3c63c0306fcbe12534b07dae89dad28b1693a41/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c3c63c0306fcbe12534b07dae89dad28b1693a41/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c3c63c0306fcbe12534b07dae89dad28b1693a41/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c3c63c0306fcbe12534b07dae89dad28b1693a41/src/cli/commands/StartCommand.js#L401 399 | const webDev = resolveNodeDevCommand(cwd, packageJson); 400 | // Producer Environment > 401 | const producerEnv = { 402 | ...process.env, 403 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/c3c63c0306fcbe12534b07dae89dad28b1693a41/src/cli/commands/StartCommand.js#L408 406 | }; 407 | // Consumer Environment > 408 | const consumerEnv = { 409 | ...process.env, 410 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.4
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9c3d19bc5bc4a957a94fb8948f67bb401afa4f67/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9c3d19bc5bc4a957a94fb8948f67bb401afa4f67/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9c3d19bc5bc4a957a94fb8948f67bb401afa4f67/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9c3d19bc5bc4a957a94fb8948f67bb401afa4f67/src/cli/commands/StartCommand.js#L401 399 | const webDev = resolveNodeDevCommand(cwd, packageJson); 400 | // Producer Environment > 401 | const producerEnv = { 402 | ...process.env, 403 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/9c3d19bc5bc4a957a94fb8948f67bb401afa4f67/src/cli/commands/StartCommand.js#L408 406 | }; 407 | // Consumer Environment > 408 | const consumerEnv = { 409 | ...process.env, 410 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.3
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6c6cef390ccae6b7af514016939ffd83e8d15928/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6c6cef390ccae6b7af514016939ffd83e8d15928/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6c6cef390ccae6b7af514016939ffd83e8d15928/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6c6cef390ccae6b7af514016939ffd83e8d15928/src/cli/commands/StartCommand.js#L401 399 | const webDev = resolveNodeDevCommand(cwd, packageJson); 400 | // Producer Environment > 401 | const producerEnv = { 402 | ...process.env, 403 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/6c6cef390ccae6b7af514016939ffd83e8d15928/src/cli/commands/StartCommand.js#L408 406 | }; 407 | // Consumer Environment > 408 | const consumerEnv = { 409 | ...process.env, 410 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.2
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/23f120f2fa46226dce91a5f2f595c61d4991256d/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/23f120f2fa46226dce91a5f2f595c61d4991256d/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/23f120f2fa46226dce91a5f2f595c61d4991256d/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/23f120f2fa46226dce91a5f2f595c61d4991256d/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/23f120f2fa46226dce91a5f2f595c61d4991256d/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.1
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/1e3be65be19ed0411c34ef098aaae846977d508b/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/1e3be65be19ed0411c34ef098aaae846977d508b/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/1e3be65be19ed0411c34ef098aaae846977d508b/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/1e3be65be19ed0411c34ef098aaae846977d508b/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/1e3be65be19ed0411c34ef098aaae846977d508b/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.0
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f113bd58f204b4e302e915fb7a8ed13de1454b1d/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f113bd58f204b4e302e915fb7a8ed13de1454b1d/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f113bd58f204b4e302e915fb7a8ed13de1454b1d/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f113bd58f204b4e302e915fb7a8ed13de1454b1d/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/f113bd58f204b4e302e915fb7a8ed13de1454b1d/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.54
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02193c0596f2b096f3da14528fc63d8fb17cc039/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02193c0596f2b096f3da14528fc63d8fb17cc039/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02193c0596f2b096f3da14528fc63d8fb17cc039/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02193c0596f2b096f3da14528fc63d8fb17cc039/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/02193c0596f2b096f3da14528fc63d8fb17cc039/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.53
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/40cc568fce7a6201e5b6adaf2d43f3e939025ea7/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/40cc568fce7a6201e5b6adaf2d43f3e939025ea7/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/40cc568fce7a6201e5b6adaf2d43f3e939025ea7/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/40cc568fce7a6201e5b6adaf2d43f3e939025ea7/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/40cc568fce7a6201e5b6adaf2d43f3e939025ea7/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.52
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d3a269d8ce4f3cea00e17c19f370a004dc8553b5/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d3a269d8ce4f3cea00e17c19f370a004dc8553b5/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d3a269d8ce4f3cea00e17c19f370a004dc8553b5/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d3a269d8ce4f3cea00e17c19f370a004dc8553b5/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d3a269d8ce4f3cea00e17c19f370a004dc8553b5/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.51
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/694da0193fb45461da06fed73f6fdea60f1644e8/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/694da0193fb45461da06fed73f6fdea60f1644e8/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/694da0193fb45461da06fed73f6fdea60f1644e8/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/694da0193fb45461da06fed73f6fdea60f1644e8/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/694da0193fb45461da06fed73f6fdea60f1644e8/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.50
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/788b10aab93fedb1374a4e952e7a198d64b36536/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/788b10aab93fedb1374a4e952e7a198d64b36536/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/788b10aab93fedb1374a4e952e7a198d64b36536/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/788b10aab93fedb1374a4e952e7a198d64b36536/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/788b10aab93fedb1374a4e952e7a198d64b36536/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.49
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/16b342c67403f6e82b1a8a532c458c91027f2916/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/16b342c67403f6e82b1a8a532c458c91027f2916/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/16b342c67403f6e82b1a8a532c458c91027f2916/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/16b342c67403f6e82b1a8a532c458c91027f2916/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/16b342c67403f6e82b1a8a532c458c91027f2916/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.48
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/892ac0eddc746ce623804d491d5dd38142d117b9/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/892ac0eddc746ce623804d491d5dd38142d117b9/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/892ac0eddc746ce623804d491d5dd38142d117b9/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/892ac0eddc746ce623804d491d5dd38142d117b9/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/892ac0eddc746ce623804d491d5dd38142d117b9/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.46
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/71775b2e4315da66abf4377ed8acf586ddf4c1ae/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/71775b2e4315da66abf4377ed8acf586ddf4c1ae/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/71775b2e4315da66abf4377ed8acf586ddf4c1ae/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/71775b2e4315da66abf4377ed8acf586ddf4c1ae/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/71775b2e4315da66abf4377ed8acf586ddf4c1ae/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.44
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d42fc0ec9951e29470b710c84b9df4e1acf1898b/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d42fc0ec9951e29470b710c84b9df4e1acf1898b/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d42fc0ec9951e29470b710c84b9df4e1acf1898b/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d42fc0ec9951e29470b710c84b9df4e1acf1898b/src/cli/commands/StartCommand.js#L379 377 | const webDev = resolveNodeDevCommand(cwd, packageJson); 378 | // Producer Environment > 379 | const producerEnv = { 380 | ...process.env, 381 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/d42fc0ec9951e29470b710c84b9df4e1acf1898b/src/cli/commands/StartCommand.js#L386 384 | }; 385 | // Consumer Environment > 386 | const consumerEnv = { 387 | ...process.env, 388 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.43
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8d344e91f2908667cc8db5167787ce95bc6bf0d8/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8d344e91f2908667cc8db5167787ce95bc6bf0d8/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8d344e91f2908667cc8db5167787ce95bc6bf0d8/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8d344e91f2908667cc8db5167787ce95bc6bf0d8/src/cli/commands/StartCommand.js#L366 364 | const webDev = resolveNodeDevCommand(cwd, packageJson); 365 | // Producer Environment > 366 | const producerEnv = { 367 | ...process.env, 368 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/8d344e91f2908667cc8db5167787ce95bc6bf0d8/src/cli/commands/StartCommand.js#L373 371 | }; 372 | // Consumer Environment > 373 | const consumerEnv = { 374 | ...process.env, 375 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.42
7 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/88afa3bf6ccee72de1fcb9401bfe58accddf6ee7/src/cli/commands/D1LearnCommand.js#L64 62 | const child = spawn(cmd, args, { 63 | stdio: 'inherit', > 64 | env: { 65 | ...process.env, 66 | ZT_D1_LEARN_FILE: LEARN_FILE,
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/88afa3bf6ccee72de1fcb9401bfe58accddf6ee7/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/88afa3bf6ccee72de1fcb9401bfe58accddf6ee7/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/88afa3bf6ccee72de1fcb9401bfe58accddf6ee7/src/cli/commands/StartCommand.js#L352 350 | const webDev = resolveNodeDevCommand(cwd, packageJson); 351 | // Producer Environment > 352 | const producerEnv = { 353 | ...process.env, 354 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/88afa3bf6ccee72de1fcb9401bfe58accddf6ee7/src/cli/commands/StartCommand.js#L359 357 | }; 358 | // Consumer Environment > 359 | const consumerEnv = { 360 | ...process.env, 361 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.41
6 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/33b681d1db679ea1c61cd6fbf058132747fad9ff/src/cli/commands/ProxyCommand.js#L49 47 | command: 'tsx', 48 | args: [path.join('bin', 'zin.ts'), mapped, ...extra], > 49 | env: { 50 | ...process.env, 51 | },
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/33b681d1db679ea1c61cd6fbf058132747fad9ff/src/cli/commands/ProxyCommandUtils.js#L31 29 | command: 'tsx', 30 | args, > 31 | env: { 32 | ...process.env, 33 | ZINTRUST_PROXY_WATCH_CHILD: '1',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/33b681d1db679ea1c61cd6fbf058132747fad9ff/src/cli/commands/StartCommand.js#L352 350 | const webDev = resolveNodeDevCommand(cwd, packageJson); 351 | // Producer Environment > 352 | const producerEnv = { 353 | ...process.env, 354 | WORKER_ENABLED: 'false',
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/ZinTrust/ZinTrust/blob/33b681d1db679ea1c61cd6fbf058132747fad9ff/src/cli/commands/StartCommand.js#L359 357 | }; 358 | // Consumer Environment > 359 | const consumerEnv = { 360 | ...process.env, 361 | WORKER_ENABLED: 'true',
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.40
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.39
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.38
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.37
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.36
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.35
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.34
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.33
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.32
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.31
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.30
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.29
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.28
3 findingsScript: node -e "process.exit(0)"
Package name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.27
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.26
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.25
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.24
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.23
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.20
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.19
2 findingsPackage name '@zintrust/core' is 1 edit(s) away from popular package 'cors'.
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.