← Home

liftoff

Launch your command line tool with ease.

2
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

phatedyocontratkellen

Keywords

command line

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
email-domain unclaimed-email:sleekcode.net AI (email-domain): Contributor email, not publisher; contributor listed since early versions. No account-takeover risk to publishing. ai
dependencies unvetted-dep:fined AI (dependencies): fined is a Gulp Team utility and an expected dependency of liftoff; stable false positive for this package. ai
dependencies unvetted-dep:rechoir AI (dependencies): rechoir is a Gulp Team utility for requiring transpilers; expected dependency of liftoff. ai
dependencies unvetted-dep:findup-sync AI (dependencies): findup-sync is a Gulp Team utility for config file discovery; expected dependency of liftoff. ai
dependencies unvetted-dep:flagged-respawn AI (dependencies): flagged-respawn is a Gulp Team utility for process respawning; expected dependency of liftoff. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require is liftoff's core feature: loading user-specified transpiler modules at CLI startup. Intentional and documented behavior, not a security risk. ai

Versions (showing 2 of 2)

Version Deps Published
5.0.1 7 / 9
4.0.0 8 / 9

v4.0.0

2 findings
HIGH Unclaimed maintainer email domain: sleekcode.net email-domain

Maintainer email '[email protected]' uses domain 'sleekcode.net' which has no DNS records. An attacker could register this domain to hijack the maintainer identity.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.