@zowe/imperative
framework for building configurable CLIs
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:web-help | AI (npm-metadata): web-help is a local file: dev dependency bundled within the monorepo; not a remote URL risk. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large file count reflects cross-major-version diff artifact, not injected code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Cross-major-version diff; new deps are benign utilities consistent with Zowe CLI framework evolution. | ai | |
| dependencies | unvetted-dep:lodash-deep | AI (dependencies): lodash-deep is a legitimate utility library; its use in a CLI framework is expected and benign across all versions. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a well-known markdown parser; its use in Zowe Imperative for web help rendering is expected and benign. | ai | |
| dependencies | unvetted-dep:dataobject-parser | AI (dependencies): dataobject-parser is a legitimate utility; its use in a CLI config framework is expected and benign. | ai | |
| phantom-deps | phantom-dep:jsonschema | AI (phantom-deps): Phantom dep in a large monorepo framework; declared for config validation tooling, not a security concern. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding is used to parse HTTP Basic Auth headers — standard authentication handling, not payload obfuscation. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() in EnvQuery.js evaluates internal semver probe expressions for diagnostics; input is from internal config, not arbitrary user input. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require of handlerPath is the core plugin/handler loading mechanism of this CLI framework — expected and documented behavior across all versions. | ai | |
| phantom-deps | phantom-dep:@types/yargs | AI (phantom-deps): @types/* packages are TypeScript type definitions loaded by convention; phantom-dep warnings are expected false positives for this package type. | ai | |
| phantom-deps | phantom-dep:@types/semver | AI (phantom-deps): @types/* packages are TypeScript type definitions loaded by convention; phantom-dep warnings are expected false positives for this package type. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Iterating process.env to delete CLI-prefixed vars during daemon context cleanup is standard CLI framework behavior in Zowe Imperative; not exfiltration. | ai |
Versions (showing 51 of 62)
| Version | Deps | Published |
|---|---|---|
| 8.34.0 | 40 / 21 | |
| 8.33.3 | 40 / 21 | |
| 8.33.2 | 40 / 21 | |
| 8.33.1 | 40 / 21 | |
| 8.33.0 | 39 / 20 | |
| 8.32.2 | 39 / 20 | |
| 8.32.0 | 39 / 20 | |
| 8.31.5 | 38 / 21 | |
| 8.31.3 | 38 / 21 | |
| 8.31.2 | 38 / 21 | |
| 8.31.1 | 38 / 21 | |
| 8.30.1 | 38 / 21 | |
| 8.29.11 | 37 / 21 | |
| 8.29.10 | 37 / 21 | |
| 8.29.8 | 38 / 22 | |
| 8.29.6 | 38 / 22 | |
| 8.29.4 | 38 / 22 | |
| 8.29.1 | 38 / 22 | |
| 8.24.2 | 38 / 22 | |
| 8.24.1 | 38 / 22 | |
| 8.23.1 | 38 / 22 | |
| 8.22.0 | 38 / 22 | |
| 8.21.0 | 38 / 22 | |
| 8.19.0 | 36 / 22 | |
| 8.18.3 | 36 / 22 | |
| 8.18.0 | 36 / 22 | |
| 8.17.0 | 36 / 22 | |
| 8.16.0 | 36 / 22 | |
| 8.15.1 | 36 / 22 | |
| 8.14.1 | 36 / 22 | |
| 8.14.0 | 36 / 22 | |
| 8.13.0 | 36 / 22 | |
| 8.12.0 | 36 / 22 | |
| 8.11.0 | 36 / 22 | |
| 8.10.4 | 36 / 22 | |
| 8.10.3 | 36 / 22 | |
| 8.10.1 | 36 / 22 | |
| 8.10.0 | 36 / 22 | |
| 8.8.3 | 36 / 22 | |
| 8.8.2 | 36 / 22 | |
| 8.8.1 | 36 / 22 | |
| 8.8.0 | 36 / 22 | |
| 8.7.1 | 36 / 22 | |
| 8.7.0 | 36 / 22 | |
| 8.6.2 | 36 / 22 | |
| 8.6.1 | 36 / 22 | |
| 8.6.0 | 36 / 22 | |
| 8.3.1 | 36 / 22 | |
| 8.2.0 | 36 / 22 | |
| 8.1.0 | 36 / 22 | |
| 8.0.1 | 36 / 22 |
v8.34.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.33.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.33.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.33.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.18.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.15.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.10.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.10.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.8.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.8.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.