← Home

liftoff

Launch your command line tool with ease.

3
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

phatedyocontratkellen

Keywords

command line

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
email-domain unclaimed-email:sleekcode.net AI (email-domain): Contributor email, not publisher; contributor listed since early versions. No account-takeover risk to publishing. ai
dependencies unvetted-dep:fined AI (dependencies): fined is a Gulp Team utility and an expected dependency of liftoff; stable false positive for this package. ai
dependencies unvetted-dep:rechoir AI (dependencies): rechoir is a Gulp Team utility for requiring transpilers; expected dependency of liftoff. ai
dependencies unvetted-dep:findup-sync AI (dependencies): findup-sync is a Gulp Team utility for config file discovery; expected dependency of liftoff. ai
dependencies unvetted-dep:flagged-respawn AI (dependencies): flagged-respawn is a Gulp Team utility for process respawning; expected dependency of liftoff. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require is liftoff's core feature: loading user-specified transpiler modules at CLI startup. Intentional and documented behavior, not a security risk. ai

Versions (showing 3 of 3)

Version Deps Published
5.0.1 7 / 9
5.0.0 7 / 9
4.0.0 8 / 9

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.