create-done-coding
项目创建命令行工具
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:es/index-890cd24a.js | AI (source-diff): Bundled CLI entrypoint using child_process/fs for its documented scaffolding function, not a loader. | ai | |
| source-diff | net-exec-file:es/index-4a647b16.js | AI (source-diff): Bundled CLI entrypoint; network+exec used for legit template-fetch/git workflow, not exfil. | ai | |
| source-diff | net-exec-file:es/index-cb50bb18.js | AI (source-diff): Bundled CLI entrypoint using git/http utils for stated scaffolding function, not a loader. | ai | |
| source-diff | net-exec-file:es/index-4bae0d72.js | AI (source-diff): Bundled CLI code using child_process/git for scaffolding, not a loader/dropper. | ai | |
| source-diff | net-exec-file:es/index-17803ba6.js | AI (source-diff): Bundled CLI entrypoint for a scaffolding tool; network+exec is its stated function, not exfil. | ai | |
| source-diff | net-exec-file:es/index-49fe32cc.js | AI (source-diff): Bundled CLI entrypoint using own git/fs deps for stated scaffolding function, not a loader/dropper. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are all @done-coding/* first-party packages from same repo, not external attack surface. | ai | |
| dependencies | unvetted-dep:@done-coding/node-tools | AI (dependencies): First-party monorepo sibling package from same publisher, not an external unvetted dep. | ai | |
| source-diff | net-exec-file:es/index-899813ab.js | AI (source-diff): Bundled CLI output; network+exec is the package's documented template-fetching function, not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-021ee1d9.js | AI (source-diff): Bundled CLI chunk; network+exec is git-clone/template-fetch for scaffolding, not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-7117a7fe.js | AI (source-diff): Bundled CLI chunk; network+exec pattern is first-party scaffolding logic, not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-8c566507.js | AI (source-diff): Bundled CLI chunk; network+exec pattern is legitimate scaffolding/template operations within the done-coding ecosystem. | ai | |
| source-diff | net-exec-file:es/index-1bee1c57.js | AI (source-diff): Bundled CLI scaffold tool; network+exec is core functionality (template fetching), not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-16ca177d.js | AI (source-diff): Bundled CLI output; network+exec is core to a git-based project scaffolding tool, not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-47ef88b7.js | AI (source-diff): Bundled CLI artifact; network calls and execSync are part of documented CLI scaffolding, not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-35579987.js | AI (source-diff): Bundled CLI entry; network calls fetch user-configured template lists, execSync runs git ops — all within stated CLI function. | ai | |
| source-diff | net-exec-file:es/index-697ce8a4.js | AI (source-diff): Bundled vite CLI artifact; network+exec pattern is legitimate CLI scaffolding (git clone, template ops), not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-84747a83.js | AI (source-diff): Bundled CLI artifact; network+exec pattern is the package's documented template-fetching and git workflow, not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-9dd6b9c3.js | AI (source-diff): Network calls target publisher's own gitee repo for template fetching; execSync used for git clone — consistent with CLI scaffolding tool function. | ai | |
| source-diff | net-exec-file:es/index-3d1ed6a9.js | AI (source-diff): Bundled CLI output; network+exec is the package's stated function (git clone, hook execution), not dropper behavior. | ai | |
| source-diff | net-exec-file:es/index-1ef18b8f.js | AI (source-diff): Bundled CLI tool; network+exec patterns are from @done-coding/cli-* workspace deps for scaffolding/git ops, not dropper behavior. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Chinese-language CLI tool with minimal README; low-value signals don't indicate spam or malice for this package. | ai | |
| phantom-deps | phantom-dep:@done-coding/cli-inject | AI (phantom-deps): Scoped internal dep referenced in config but bundled at build time; stable false positive for this package. | ai |
Versions (showing 51 of 56)
| Version | Deps | Published |
|---|---|---|
| 0.15.1 | 3 / 8 | |
| 0.15.0 | 3 / 8 | |
| 0.14.0 | 3 / 7 | |
| 0.13.0 | 3 / 6 | |
| 0.12.2 | 3 / 6 | |
| 0.12.1 | 3 / 6 | |
| 0.12.0 | 3 / 6 | |
| 0.11.26 | 3 / 6 | |
| 0.11.25 | 3 / 6 | |
| 0.11.24 | 3 / 6 | |
| 0.11.22 | 4 / 6 | |
| 0.11.21 | 4 / 6 | |
| 0.11.20 | 4 / 6 | |
| 0.11.19 | 4 / 6 | |
| 0.11.18 | 4 / 6 | |
| 0.11.17 | 4 / 6 | |
| 0.11.16 | 4 / 6 | |
| 0.11.14 | 4 / 6 | |
| 0.11.13 | 4 / 6 | |
| 0.11.12 | 4 / 6 | |
| 0.11.10 | 4 / 6 | |
| 0.11.9 | 4 / 6 | |
| 0.11.7 | 4 / 6 | |
| 0.11.4 | 4 / 6 | |
| 0.11.3 | 4 / 6 | |
| 0.11.2 | 4 / 6 | |
| 0.11.1 | 4 / 6 | |
| 0.10.3 | 4 / 6 | |
| 0.9.0 | 6 / 8 | |
| 0.8.0 | 6 / 8 | |
| 0.7.0 | 6 / 8 | |
| 0.6.0 | 5 / 8 | |
| 0.5.2 | 5 / 8 | |
| 0.5.1 | 5 / 8 | |
| 0.5.0 | 5 / 8 | |
| 0.4.8 | 3 / 8 | |
| 0.4.7 | 3 / 8 | |
| 0.4.6 | 3 / 8 | |
| 0.4.5 | 3 / 8 | |
| 0.4.3 | 3 / 8 | |
| 0.4.2 | 3 / 8 | |
| 0.4.1 | 3 / 8 | |
| 0.4.0 | 3 / 7 | |
| 0.3.1 | 3 / 18 | |
| 0.2.13 | 2 / 17 | |
| 0.2.12 | 2 / 17 | |
| 0.2.11 | 2 / 17 | |
| 0.2.9 | 2 / 16 | |
| 0.2.8 | 2 / 16 | |
| 0.2.7 | 2 / 16 | |
| 0.2.6 | 2 / 16 |
v0.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.