backport
A CLI tool that automates the process of backporting commits
5
Versions
Apache-2.0
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
sqren
Keywords
backportbackportingversioningcherry-pickgitgit-cherry-pickcliautomationproductivitybranchesbranching
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:dedent | AI (phantom-deps): dedent is a declared runtime dep used via config/codegen tooling; stable false positive. | ai | |
| phantom-deps | phantom-dep:graphql-tag | AI (phantom-deps): graphql-tag declared as runtime dep, used via codegen config; stable false positive. | ai | |
| phantom-deps | phantom-dep:safe-json-stringify | AI (phantom-deps): safe-json-stringify declared as runtime dep; stable false positive. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Guarded postinstall only runs a local dist script if present; benign pattern stable across versions. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv is a declared runtime dependency used via config files; phantom-dep heuristic is a false positive here. | ai |