carlin
CLI tool for deploying AWS cloud resources using CloudFormation templates.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:import-sync | AI (phantom-deps): Config-file reference pattern; stable for this package. | ai | |
| dependencies | unvetted-dep:@ttoss/config | AI (dependencies): Same-org monorepo dependency (ttoss/ttoss); stable across versions. | ai | |
| dependencies | unvetted-dep:@ttoss/cloudformation | AI (dependencies): Same-org monorepo dependency (ttoss/ttoss); stable across versions. | ai | |
| dependencies | unvetted-dep:@ttoss/read-config-file | AI (dependencies): Same-org monorepo dependency (ttoss/ttoss); stable across versions. | ai | |
| dependencies | unvetted-dep:vercel | AI (dependencies): vercel is a well-known, widely-used deployment CLI; low risk for this package. | ai | |
| dependencies | unvetted-dep:import-sync | AI (dependencies): Utility dep with no malware indicators; stable usage pattern for this package. | ai | |
| phantom-deps | phantom-dep:vercel | AI (phantom-deps): CLI tool; vercel invoked as a subprocess/config dependency, not a direct import. | ai | |
| phantom-deps | phantom-dep:@ttoss/read-config-file | AI (phantom-deps): Internal monorepo package; referenced via config, stable false positive. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Commonly referenced in config/scripts without direct import in CLI packages. | ai | |
| phantom-deps | phantom-dep:ts-node | AI (phantom-deps): Used as a runtime executor via config, not a direct import. | ai | |
| phantom-deps | phantom-dep:@slack/webhook | AI (phantom-deps): Referenced in config files; CLI dispatch pattern for this package. | ai | |
| phantom-deps | phantom-dep:@octokit/webhooks | AI (phantom-deps): Referenced in config files; CLI dispatch pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ttoss/cloudformation | AI (phantom-deps): Internal monorepo package; referenced via config, stable false positive. | ai |
Versions (showing 51 of 74)
| Version | Deps | Published |
|---|---|---|
| 1.49.21 | 27 / 18 | |
| 1.49.20 | 27 / 18 | |
| 1.49.14 | 28 / 18 | |
| 1.49.13 | 28 / 18 | |
| 1.49.12 | 28 / 18 | |
| 1.49.11 | 28 / 18 | |
| 1.49.10 | 28 / 18 | |
| 1.49.9 | 28 / 18 | |
| 1.49.8 | 28 / 18 | |
| 1.49.7 | 28 / 18 | |
| 1.49.6 | 28 / 18 | |
| 1.49.5 | 28 / 18 | |
| 1.49.4 | 28 / 18 | |
| 1.49.3 | 28 / 18 | |
| 1.49.2 | 28 / 18 | |
| 1.49.1 | 28 / 18 | |
| 1.49.0 | 28 / 18 | |
| 1.48.4 | 28 / 18 | |
| 1.48.3 | 28 / 18 | |
| 1.48.2 | 28 / 18 | |
| 1.39.12 | 26 / 17 | |
| 1.39.11 | 26 / 17 | |
| 1.39.10 | 26 / 17 | |
| 1.39.9 | 26 / 17 | |
| 1.39.8 | 26 / 17 | |
| 1.39.7 | 26 / 17 | |
| 1.39.6 | 26 / 17 | |
| 1.39.5 | 26 / 17 | |
| 1.39.4 | 26 / 17 | |
| 1.39.3 | 26 / 17 | |
| 1.39.2 | 26 / 17 | |
| 1.39.1 | 26 / 17 | |
| 1.39.0 | 26 / 17 | |
| 1.38.7 | 26 / 17 | |
| 1.38.6 | 26 / 17 | |
| 1.38.5 | 26 / 17 | |
| 1.38.4 | 26 / 17 | |
| 1.38.3 | 26 / 17 | |
| 1.38.2 | 26 / 17 | |
| 1.38.1 | 26 / 17 | |
| 1.38.0 | 26 / 17 | |
| 1.37.1 | 26 / 17 | |
| 1.37.0 | 26 / 17 | |
| 1.36.21 | 26 / 17 | |
| 1.36.20 | 26 / 17 | |
| 1.36.19 | 26 / 17 | |
| 1.36.18 | 26 / 17 | |
| 1.36.17 | 26 / 17 | |
| 1.36.16 | 26 / 17 | |
| 1.36.15 | 26 / 17 | |
| 1.36.14 | 26 / 17 |
v1.38.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.38.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.38.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.38.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.20
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.