caterpillar-human
Turn your [Caterpillar](https://github.com/bevry/caterpillar) logger stream into a beautiful readable format with colors and optional debug information
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-babel | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:eslint-config-prettier | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-prettier | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:@bevry/update-contributors | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Bevry packages routinely duplicate devDependencies into dependencies for tooling. All 20 new deps are confirmed phantom (not imported) and are well-known dev tools (eslint, typescript, prettier, etc.). | ai | |
| phantom-deps | phantom-dep:kava | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:surge | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:valid-module | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:assert-helpers | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:valid-directory | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:@types/ansicolors | AI (phantom-deps): Type definitions package; framework-scoped, not directly imported. Legitimate for TypeScript packages. | ai | |
| phantom-deps | phantom-dep:make-deno-edition | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:eslint-config-bevry | AI (phantom-deps): Dev tooling dep duplicated into dependencies section; not imported at runtime. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Build tool invoked via npm scripts (our:compile:*); legitimate config-referenced dependency for TypeScript project. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Build tool invoked via npm scripts (our:verify:prettier); legitimate config-referenced dependency for this project. | ai | |
| phantom-deps | phantom-dep:typedoc | AI (phantom-deps): Build tool invoked via npm scripts (our:meta:docs:typedoc); legitimate config-referenced dependency for documentation generation. | ai | |
| phantom-deps | phantom-dep:projectz | AI (phantom-deps): Build tool invoked via npm scripts (our:meta:projectz); legitimate config-referenced dependency for metadata compilation. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): Build tool invoked via npm scripts (our:verify:eslint); legitimate config-referenced dependency for this project. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 6.15.0 | 2 / 20 | |
| 6.14.0 | 2 / 20 | |
| 6.13.0 | 2 / 20 | |
| 6.12.0 | 2 / 20 | |
| 6.11.0 | 2 / 20 | |
| 6.10.0 | 2 / 20 | |
| 6.9.0 | 3 / 20 | |
| 6.8.0 | 22 / 20 | |
| 6.7.0 | 22 / 20 | |
| 6.6.0 | 2 / 20 | |
| 6.5.0 | 2 / 20 | |
| 6.4.0 | 2 / 19 | |
| 6.3.0 | 2 / 19 | |
| 6.2.0 | 2 / 19 | |
| 6.1.0 | 2 / 19 | |
| 6.0.0 | 2 / 19 | |
| 5.1.0 | 2 / 19 | |
| 5.0.0 | 2 / 18 | |
| 4.5.0 | 2 / 18 | |
| 4.4.0 | 2 / 18 | |
| 4.3.0 | 2 / 18 | |
| 4.2.0 | 2 / 18 | |
| 4.1.0 | 2 / 18 | |
| 4.0.0 | 2 / 18 | |
| 3.2.0 | 3 / 18 | |
| 3.0.0 | 3 / 11 | |
| 2.1.2 | 2 / 7 | |
| 2.1.1 | 2 / 6 | |
| 2.1.0 | 2 / 6 | |
| 2.0.2 | 1 / 6 | |
| 2.0.1 | 1 / 5 | |
| 2.0.0 | 2 / 5 |
v6.15.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.14.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.9.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.