inngest-cli
The leading workflow orchestration platform. Run stateful step functions and AI workflows on serverless, servers, or the edge.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): Documented binary-fetch postinstall for CLI tool; stable pattern across all versions of this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): CLI wrapper package; README link dump and missing keywords are expected for this type of package. | ai |
v1.17.8
2 findingsScript: node postinstall.js
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.3
2 findingsScript: node postinstall.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.13
2 findingsScript: node postinstall.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.11
2 findingsScript: node postinstall.js
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.