netlify-cli
Netlify command line tool
28
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
netlify-botmikewenyouvalvserhalp-netlifymlgualtieri-gatsby
Keywords
apiclinetlifystatic
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): yauzl is a well-established zip library replacing extract-zip; routine dep swap in a mature, provenance-attested package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Published by official netlify-bot with SLSA provenance; maintainer roster changes are normal for a large org CLI. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same rationale — org-managed package with provenance attestation; removals reflect normal team changes. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Official Netlify CLI with SLSA provenance; high-frequency release history makes dormancy gap a false positive for this package. | ai | |
| dependencies | unvetted-dep:gh-release-fetch | AI (dependencies): Expected dependency for a CLI tool that fetches prebuilt binaries from GitHub releases; consistent with netlify-cli's documented install flow. | ai | |
| dependencies | unvetted-dep:git-repo-info | AI (dependencies): Git metadata utility; stable dep for this package. | ai | |
| dependencies | unvetted-dep:maxstache-stream | AI (dependencies): Streaming templating dep; stable for this package. | ai | |
| dependencies | unvetted-dep:@netlify/build-info | AI (dependencies): First-party Netlify dep; stable for this package. | ai | |
| dependencies | unvetted-dep:@netlify/local-functions-proxy | AI (dependencies): First-party Netlify dep; stable for this package. | ai | |
| dependencies | unvetted-dep:express-logging | AI (dependencies): Logging middleware; stable dep for this package. | ai | |
| dependencies | unvetted-dep:maxstache | AI (dependencies): Legitimate templating dep used by netlify-cli across versions. | ai | |
| dependencies | unvetted-dep:http-proxy | AI (dependencies): Well-known proxy library; stable dep for this package. | ai | |
| dependencies | unvetted-dep:ascii-table | AI (dependencies): Benign table-formatting utility; stable dep for this package. | ai | |
| dependencies | unvetted-dep:folder-walker | AI (dependencies): Filesystem utility; stable dep for this package. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Runs a local bundled script (scripts/postinstall.js), not a remote fetch; stable pattern for netlify-cli. | ai | |
| phantom-deps | phantom-dep:@netlify/edge-functions | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive for netlify-cli. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api | AI (phantom-deps): Listed in dependencies; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:write-file-atomic | AI (phantom-deps): Listed in dependencies; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 27.0.1 | 96 / 63 | |
| 26.2.0 | 96 / 63 | |
| 26.1.0 | 97 / 64 | |
| 26.0.2 | 98 / 63 | |
| 26.0.1 | 98 / 63 | |
| 26.0.0 | 98 / 63 | |
| 25.6.2 | 98 / 63 | |
| 25.6.1 | 98 / 63 | |
| 25.6.0 | 98 / 63 | |
| 25.3.0 | 98 / 62 | |
| 25.1.1 | 98 / 62 | |
| 25.1.0 | 98 / 62 | |
| 25.0.1 | 98 / 62 | |
| 25.0.0 | 98 / 62 | |
| 24.11.3 | 97 / 0 | |
| 24.11.1 | 97 / 0 | |
| 24.11.0 | 97 / 0 | |
| 24.9.0 | 97 / 0 | |
| 24.8.2 | 97 / 0 | |
| 24.5.1 | 97 / 0 | |
| 24.1.0 | 97 / 0 | |
| 23.13.3 | 95 / 0 | |
| 23.13.2 | 95 / 0 | |
| 23.13.1 | 95 / 0 | |
| 23.12.1 | 95 / 0 | |
| 23.12.0 | 95 / 0 | |
| 23.11.0 | 96 / 0 | |
| 23.10.0 | 96 / 0 |
v27.0.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v26.2.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.