@genesislcap/foundation-cli
Genesis Foundation CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | rapid-publish | AI (publish-pattern): High-velocity monorepo with ~2000 versions; rapid sequential publishes are expected CI behavior. | ai | |
| dependencies | unvetted-dep:inquirer-fuzzy-path | AI (dependencies): Inquirer UI plugin for fuzzy path selection; low-risk interactive prompt helper stable for this CLI package. | ai | |
| dependencies | unvetted-dep:inquirer-file-tree-selection-prompt | AI (dependencies): Inquirer UI plugin for file tree selection; low-risk interactive prompt helper stable for this CLI package. | ai | |
| dependencies | unvetted-dep:inquirer-select-directory | AI (dependencies): Inquirer UI plugin for directory selection; low-risk interactive prompt helper stable for this CLI package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established Genesis platform package; sparse README is a style choice, not spam. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Long-lived CLI package; postinstall runs a local node script, consistent with documented setup across many versions. | ai | |
| phantom-deps | phantom-dep:@microsoft/fast-router | AI (phantom-deps): Declared dep used indirectly via config/plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:liftoff | AI (phantom-deps): Declared dep used indirectly via config/plugin pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:open | AI (phantom-deps): Declared dep used indirectly via config/plugin pattern; stable false positive for this package. | ai |
Versions (showing 55 of 155)
| Version | Deps | Published |
|---|---|---|
| 14.334.0 | 29 / 6 | |
| 14.333.1 | 29 / 6 | |
| 14.333.0 | 29 / 6 | |
| 14.332.0 | 29 / 6 | |
| 14.331.0 | 29 / 6 | |
| 14.330.0 | 29 / 6 | |
| 14.327.0 | 29 / 6 | |
| 14.326.0 | 29 / 6 | |
| 14.325.0 | 29 / 6 | |
| 14.324.0 | 29 / 6 | |
| 14.322.0 | 29 / 6 | |
| 14.321.0 | 29 / 6 | |
| 14.317.1 | 29 / 6 | |
| 14.317.0 | 29 / 6 | |
| 14.316.0 | 29 / 6 | |
| 14.314.2 | 29 / 6 | |
| 14.314.0 | 29 / 6 | |
| 14.313.1 | 29 / 6 | |
| 14.313.0 | 29 / 6 | |
| 14.310.1 | 29 / 6 | |
| 14.310.0 | 29 / 6 | |
| 14.309.0 | 29 / 6 | |
| 14.308.0 | 29 / 6 | |
| 14.306.1 | 29 / 6 | |
| 14.304.2 | 29 / 6 | |
| 14.304.1 | 29 / 6 | |
| 14.303.1 | 29 / 6 | |
| 14.299.0 | 29 / 6 | |
| 14.298.1 | 29 / 6 | |
| 14.297.0 | 29 / 6 | |
| 14.295.0 | 29 / 6 | |
| 14.292.0 | 29 / 6 | |
| 14.290.0 | 29 / 6 | |
| 14.289.1 | 29 / 6 | |
| 14.289.0 | 29 / 6 | |
| 14.288.0 | 29 / 6 | |
| 14.287.0 | 29 / 6 | |
| 14.284.5 | 29 / 6 | |
| 14.284.0 | 29 / 6 | |
| 14.283.2 | 29 / 6 | |
| 14.283.1 | 29 / 6 | |
| 14.281.2 | 29 / 6 | |
| 14.281.0 | 29 / 6 | |
| 14.278.2 | 29 / 6 | |
| 14.278.1 | 29 / 6 | |
| 14.278.0 | 29 / 6 | |
| 14.275.3 | 29 / 6 | |
| 14.275.2 | 29 / 6 | |
| 14.275.0 | 29 / 6 | |
| 14.273.0 | 29 / 6 | |
| 14.269.0 | 29 / 6 | |
| 14.268.2 | 29 / 6 | |
| 14.266.1 | 29 / 6 | |
| 14.265.1 | 29 / 6 | |
| 14.264.2 | 29 / 6 |
v14.334.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.333.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.333.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.332.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.331.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.330.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.327.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.326.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.325.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.324.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.322.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.321.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.317.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.317.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.316.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.314.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.314.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.313.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.313.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.310.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.310.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.309.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.308.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.306.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.304.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.304.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.303.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.299.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.298.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.297.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.295.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.292.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.290.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.289.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.289.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.288.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.287.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.284.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.284.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.283.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.283.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.281.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.281.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.278.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.278.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.278.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.275.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.275.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.275.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.273.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.269.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.268.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.266.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.265.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.264.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.