← Home

forest-cli

3
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

vincentmolinieforestforestbotarnaudbesnier

Keywords

forestadmin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:pg AI (phantom-deps): DB driver declared as optional dep for SQL scaffolding CLI; not directly imported by design. ai
phantom-deps phantom-dep:mysql2 AI (phantom-deps): DB driver declared as optional dep for SQL scaffolding CLI; not directly imported by design. ai
phantom-deps phantom-dep:tedious AI (phantom-deps): DB driver declared as optional dep for SQL scaffolding CLI; not directly imported by design. ai
phantom-deps phantom-dep:saslprep AI (phantom-deps): MongoDB auth helper; declared dep, not directly imported by design. ai
phantom-deps phantom-dep:commander AI (phantom-deps): CLI framework dep; stable false positive for this package. ai
phantom-deps phantom-dep:jsonwebtoken AI (phantom-deps): Auth utility; declared dep, not directly imported by design. ai
phantom-deps phantom-dep:app-root-path AI (phantom-deps): Utility dep; stable false positive for this package. ai
phantom-deps phantom-dep:stdout-stderr AI (phantom-deps): Test utility dep; stable false positive for this package. ai
phantom-deps phantom-dep:atob AI (phantom-deps): Utility dep; stable false positive for this package. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): oclif plugin declared in oclif config, not directly imported; stable false positive. ai
phantom-deps phantom-dep:@oclif/plugin-not-found AI (phantom-deps): oclif plugin declared in oclif config, not directly imported; stable false positive. ai
phantom-deps phantom-dep:@oclif/plugin-warn-if-update-available AI (phantom-deps): oclif plugin declared in oclif config, not directly imported; stable false positive. ai
phantom-deps phantom-dep:@paralleldrive/cuid2 AI (phantom-deps): Utility dep; stable false positive for this package. ai

Versions (showing 3 of 3)

Version Deps Published
5.3.9 39 / 33
5.3.8 39 / 33
5.3.6 39 / 33

v5.3.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.