← Home

instant-cli

Instant's CLI

1
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

stopachkanezajdwwdrew-h

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-removed AI (maintainer-change): Maintainer removal is consistent with the transition to automated GitHub Actions publishing; SLSA attestation confirms the official repo is the source. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation from the official instantdb/instant repo — this reflects a legitimate CI/CD migration, not a compromise. ai
publish-pattern dormant-publish AI (publish-pattern): Package has SLSA provenance attestation confirming CI/CD publish; dormancy followed by legitimate feature release is consistent with this project's history. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): dotenv is a declared dependency used via config files; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:commander AI (phantom-deps): commander is a declared dependency; @commander-js/extra-typings wraps it. Phantom detection is a false positive here. ai
phantom-deps phantom-dep:ansi-escapes AI (phantom-deps): ansi-escapes is a declared dependency used indirectly; false positive for this package. ai
provenance slsa-provenance AI (provenance): instant-cli consistently publishes via CI/CD with SLSA provenance; this is a stable supply chain integrity signal for this package. ai
dependencies unvetted-dep:pkg-types AI (dependencies): pkg-types is a well-maintained UnJS package used by Vite, Nuxt, and many major tools. Not a security concern for this package. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding in an auth client module is a normal operation for decoding auth tokens/credentials. No obfuscation or malicious payload hiding evident. ai
semgrep semgrep:env-spread AI (semgrep): Flagged code is in a test helper (__tests__/e2e/helpers.ts) that spreads process.env to pass env vars to a child process — standard CLI test harness pattern, not a runtime risk. ai

Versions (showing 1 of 201)

Version Deps Published
0.22.35 19 / 8