← Home

inngest-cli

The leading workflow orchestration platform. Run stateful step functions and AI workflows on serverless, servers, or the edge.

4
Versions
SEE LICENSE IN LICENSE.md
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

djfarrellyjpwilliamsinngest-release-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): Documented binary-fetch postinstall for CLI tool; stable pattern across all versions of this package. ai
bogus-package bogus-package AI (bogus-package): CLI wrapper package; README link dump and missing keywords are expected for this type of package. ai

Versions (showing 4 of 4)

Version Deps Published
1.17.8 4 / 5
1.6.3 4 / 6
1.5.13 4 / 6
1.5.11 4 / 6

v1.17.8

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.js

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.3

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.js

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.13

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.js

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.11

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.js

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.