oclif
oclif: create your own CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:env-spread | AI (semgrep): Standard pattern passing env to child process with NODE_ENV override; benign for this CLI tool. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads resolved @oclif/plugin-legacy path; stable plugin-compat pattern across versions. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): Referenced as oclif plugin in config, not a direct import; expected pattern. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-not-found | AI (phantom-deps): Referenced as oclif plugin in config, not a direct import; expected pattern. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-warn-if-update-available | AI (phantom-deps): Referenced as oclif plugin in config, not a direct import; expected pattern. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-perfectionist | AI (phantom-deps): ESLint plugin referenced in config files; standard pattern for linting deps. | ai |
Versions (showing 51 of 384)
| Version | Deps | Published |
|---|---|---|
| 4.23.29 | 23 / 36 | |
| 4.23.28 | 23 / 36 | |
| 4.23.27 | 23 / 36 | |
| 4.23.26 | 23 / 36 | |
| 4.23.25 | 23 / 36 | |
| 4.23.24 | 23 / 36 | |
| 4.23.23 | 23 / 36 | |
| 4.23.22 | 23 / 36 | |
| 4.23.21 | 23 / 36 | |
| 4.23.20 | 23 / 36 | |
| 4.23.19 | 22 / 35 | |
| 4.23.18 | 22 / 35 | |
| 4.23.17 | 22 / 35 | |
| 4.23.16 | 22 / 35 | |
| 4.23.15 | 22 / 35 | |
| 4.23.14 | 22 / 35 | |
| 4.23.13 | 22 / 35 | |
| 4.23.12 | 22 / 35 | |
| 4.23.11 | 22 / 35 | |
| 4.23.10 | 24 / 34 | |
| 4.23.9 | 24 / 34 | |
| 4.23.8 | 24 / 34 | |
| 4.23.7 | 24 / 34 | |
| 4.23.6 | 24 / 34 | |
| 4.23.5 | 24 / 34 | |
| 4.23.4 | 24 / 34 | |
| 4.23.3 | 24 / 34 | |
| 4.23.2 | 24 / 34 | |
| 4.23.1 | 24 / 34 | |
| 4.22.98 | 24 / 34 | |
| 4.22.97 | 24 / 34 | |
| 4.22.96 | 24 / 34 | |
| 4.22.95 | 24 / 34 | |
| 4.22.94 | 24 / 34 | |
| 4.22.93 | 24 / 34 | |
| 4.22.92 | 24 / 34 | |
| 4.22.91 | 24 / 34 | |
| 4.22.90 | 24 / 34 | |
| 4.22.89 | 24 / 34 | |
| 4.22.88 | 24 / 34 | |
| 4.22.87 | 24 / 34 | |
| 4.22.86 | 24 / 34 | |
| 4.22.85 | 24 / 34 | |
| 4.22.84 | 24 / 34 | |
| 4.22.83 | 24 / 34 | |
| 4.22.82 | 24 / 34 | |
| 4.22.81 | 24 / 34 | |
| 4.22.80 | 24 / 34 | |
| 4.22.79 | 24 / 34 | |
| 4.22.78 | 24 / 34 | |
| 4.22.77 | 24 / 34 |
v4.23.29
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.28
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.26
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.25
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.24
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.23
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.22
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.23.21
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.