← Home

create-done-coding

项目创建命令行工具

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

justsosu

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:es/index-890cd24a.js AI (source-diff): Bundled CLI entrypoint using child_process/fs for its documented scaffolding function, not a loader. ai
source-diff net-exec-file:es/index-4a647b16.js AI (source-diff): Bundled CLI entrypoint; network+exec used for legit template-fetch/git workflow, not exfil. ai
source-diff net-exec-file:es/index-cb50bb18.js AI (source-diff): Bundled CLI entrypoint using git/http utils for stated scaffolding function, not a loader. ai
source-diff net-exec-file:es/index-4bae0d72.js AI (source-diff): Bundled CLI code using child_process/git for scaffolding, not a loader/dropper. ai
source-diff net-exec-file:es/index-17803ba6.js AI (source-diff): Bundled CLI entrypoint for a scaffolding tool; network+exec is its stated function, not exfil. ai
source-diff net-exec-file:es/index-49fe32cc.js AI (source-diff): Bundled CLI entrypoint using own git/fs deps for stated scaffolding function, not a loader/dropper. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are all @done-coding/* first-party packages from same repo, not external attack surface. ai
dependencies unvetted-dep:@done-coding/node-tools AI (dependencies): First-party monorepo sibling package from same publisher, not an external unvetted dep. ai
source-diff net-exec-file:es/index-899813ab.js AI (source-diff): Bundled CLI output; network+exec is the package's documented template-fetching function, not dropper behavior. ai
source-diff net-exec-file:es/index-021ee1d9.js AI (source-diff): Bundled CLI chunk; network+exec is git-clone/template-fetch for scaffolding, not dropper behavior. ai
source-diff net-exec-file:es/index-7117a7fe.js AI (source-diff): Bundled CLI chunk; network+exec pattern is first-party scaffolding logic, not dropper behavior. ai
source-diff net-exec-file:es/index-8c566507.js AI (source-diff): Bundled CLI chunk; network+exec pattern is legitimate scaffolding/template operations within the done-coding ecosystem. ai
source-diff net-exec-file:es/index-1bee1c57.js AI (source-diff): Bundled CLI scaffold tool; network+exec is core functionality (template fetching), not dropper behavior. ai
source-diff net-exec-file:es/index-16ca177d.js AI (source-diff): Bundled CLI output; network+exec is core to a git-based project scaffolding tool, not dropper behavior. ai
source-diff net-exec-file:es/index-47ef88b7.js AI (source-diff): Bundled CLI artifact; network calls and execSync are part of documented CLI scaffolding, not dropper behavior. ai
source-diff net-exec-file:es/index-35579987.js AI (source-diff): Bundled CLI entry; network calls fetch user-configured template lists, execSync runs git ops — all within stated CLI function. ai
source-diff net-exec-file:es/index-697ce8a4.js AI (source-diff): Bundled vite CLI artifact; network+exec pattern is legitimate CLI scaffolding (git clone, template ops), not dropper behavior. ai
source-diff net-exec-file:es/index-84747a83.js AI (source-diff): Bundled CLI artifact; network+exec pattern is the package's documented template-fetching and git workflow, not dropper behavior. ai
source-diff net-exec-file:es/index-9dd6b9c3.js AI (source-diff): Network calls target publisher's own gitee repo for template fetching; execSync used for git clone — consistent with CLI scaffolding tool function. ai
source-diff net-exec-file:es/index-3d1ed6a9.js AI (source-diff): Bundled CLI output; network+exec is the package's stated function (git clone, hook execution), not dropper behavior. ai
source-diff net-exec-file:es/index-1ef18b8f.js AI (source-diff): Bundled CLI tool; network+exec patterns are from @done-coding/cli-* workspace deps for scaffolding/git ops, not dropper behavior. ai
bogus-package bogus-package AI (bogus-package): Chinese-language CLI tool with minimal README; low-value signals don't indicate spam or malice for this package. ai
phantom-deps phantom-dep:@done-coding/cli-inject AI (phantom-deps): Scoped internal dep referenced in config but bundled at build time; stable false positive for this package. ai

Versions (showing 51 of 56)

View all versions
Version Deps Published
0.15.1 3 / 8
0.15.0 3 / 8
0.14.0 3 / 7
0.13.0 3 / 6
0.12.2 3 / 6
0.12.1 3 / 6
0.12.0 3 / 6
0.11.26 3 / 6
0.11.25 3 / 6
0.11.24 3 / 6
0.11.22 4 / 6
0.11.21 4 / 6
0.11.20 4 / 6
0.11.19 4 / 6
0.11.18 4 / 6
0.11.17 4 / 6
0.11.16 4 / 6
0.11.14 4 / 6
0.11.13 4 / 6
0.11.12 4 / 6
0.11.10 4 / 6
0.11.9 4 / 6
0.11.7 4 / 6
0.11.4 4 / 6
0.11.3 4 / 6
0.11.2 4 / 6
0.11.1 4 / 6
0.10.3 4 / 6
0.9.0 6 / 8
0.8.0 6 / 8
0.7.0 6 / 8
0.6.0 5 / 8
0.5.2 5 / 8
0.5.1 5 / 8
0.5.0 5 / 8
0.4.8 3 / 8
0.4.7 3 / 8
0.4.6 3 / 8
0.4.5 3 / 8
0.4.3 3 / 8
0.4.2 3 / 8
0.4.1 3 / 8
0.4.0 3 / 7
0.3.1 3 / 18
0.2.13 2 / 17
0.2.12 2 / 17
0.2.11 2 / 17
0.2.9 2 / 16
0.2.8 2 / 16
0.2.7 2 / 16
0.2.6 2 / 16

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.