lingo.dev
Lingo.dev CLI
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:p-limit | AI (phantom-deps): Declared and used via dynamic plugin loaders; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:remark-disable-tokenizers | AI (phantom-deps): Declared and used via dynamic plugin loaders; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:mdast-util-from-markdown | AI (phantom-deps): Declared and used via dynamic plugin loaders; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:dedent | AI (phantom-deps): Declared and used via dynamic plugin loaders; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:micromark-extension-gfm | AI (phantom-deps): Declared and used via dynamic plugin loaders; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:remark-mdx-frontmatter | AI (phantom-deps): Declared and used via dynamic plugin loaders; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:remark-frontmatter | AI (phantom-deps): Stable false positive; dynamically loaded by this CLI's plugin/format system. | ai | |
| phantom-deps | phantom-dep:@paralleldrive/cuid2 | AI (phantom-deps): Stable false positive; dynamically loaded by this CLI's plugin/format system. | ai | |
| phantom-deps | phantom-dep:remark-stringify | AI (phantom-deps): Stable false positive; dynamically loaded by this CLI's plugin/format system. | ai | |
| phantom-deps | phantom-dep:unist-util-visit | AI (phantom-deps): Stable false positive; dynamically loaded by this CLI's plugin/format system. | ai | |
| phantom-deps | phantom-dep:@biomejs/wasm-nodejs | AI (phantom-deps): Stable false positive; dynamically loaded by this CLI's plugin/format system. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Optional remark plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:remark-mdx | AI (phantom-deps): Optional remark plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:ink-spinner | AI (phantom-deps): Optional CLI UI component loaded by convention. | ai | |
| phantom-deps | phantom-dep:cli-progress | AI (phantom-deps): Optional CLI UI component loaded by convention. | ai | |
| phantom-deps | phantom-dep:remark-parse | AI (phantom-deps): Optional remark plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:remark-rehype | AI (phantom-deps): Optional remark plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:mdast-util-gfm | AI (phantom-deps): Optional mdast utility loaded by convention. | ai | |
| phantom-deps | phantom-dep:ink-progress-bar | AI (phantom-deps): Optional CLI UI component loaded by convention. | ai | |
| phantom-deps | phantom-dep:rehype-stringify | AI (phantom-deps): Optional rehype plugin loaded by convention. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Optional format handler loaded by convention in this large CLI tool. | ai | |
| dependencies | unvetted-dep:@lingo.dev/_sdk | AI (dependencies): First-party scoped package from same org; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lingo.dev/_spec | AI (dependencies): First-party scoped package from same org; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lingo.dev/_react | AI (dependencies): First-party scoped package from same org; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lingo.dev/_locales | AI (dependencies): First-party scoped package from same org; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@lingo.dev/_compiler | AI (dependencies): First-party scoped package from same org; stable pattern across versions. | ai | |
| phantom-deps | phantom-dep:vfile | AI (phantom-deps): Optional format handler loaded by convention in this large CLI tool. | ai | |
| phantom-deps | phantom-dep:xpath | AI (phantom-deps): Optional format handler loaded by convention in this large CLI tool. | ai | |
| phantom-deps | phantom-dep:unified | AI (phantom-deps): Optional format handler loaded by convention in this large CLI tool. | ai | |
| phantom-deps | phantom-dep:@inkjs/ui | AI (phantom-deps): Optional UI component loaded by convention in this CLI tool. | ai | |
| phantom-deps | phantom-dep:@types/ejs | AI (phantom-deps): Type-only package, framework-scoped; stable false positive. | ai | |
| phantom-deps | phantom-dep:ejs | AI (phantom-deps): Bundled CLI; deps loaded dynamically by format handlers, not via direct top-level imports. | ai | |
| phantom-deps | phantom-dep:posthog-node | AI (phantom-deps): Analytics loaded indirectly in bundled CLI. | ai | |
| phantom-deps | phantom-dep:xliff | AI (phantom-deps): Format handler loaded dynamically in bundled CLI. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Bundled CLI with React-based ink UI; loaded indirectly. | ai | |
| phantom-deps | phantom-dep:sax | AI (phantom-deps): Bundled CLI; format-specific parser loaded indirectly. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): Bundled CLI; ink used via compiled output, not direct import. | ai |
Versions (showing 100 of 247)
| Version | Deps | Published |
|---|---|---|
| 0.114.0 | 95 / 23 | |
| 0.113.8 | 95 / 23 | |
| 0.113.7 | 95 / 23 | |
| 0.113.6 | 95 / 23 | |
| 0.113.5 | 94 / 23 | |
| 0.113.4 | 94 / 23 | |
| 0.113.3 | 94 / 23 | |
| 0.113.2 | 94 / 23 | |
| 0.113.1 | 94 / 23 | |
| 0.113.0 | 94 / 23 | |
| 0.112.1 | 94 / 23 | |
| 0.112.0 | 94 / 23 | |
| 0.111.16 | 93 / 23 | |
| 0.111.15 | 93 / 23 | |
| 0.111.14 | 93 / 23 | |
| 0.111.13 | 93 / 23 | |
| 0.111.12 | 93 / 23 | |
| 0.111.11 | 93 / 23 | |
| 0.111.10 | 91 / 23 | |
| 0.111.9 | 91 / 23 | |
| 0.111.8 | 91 / 23 | |
| 0.111.7 | 90 / 23 | |
| 0.111.6 | 90 / 23 | |
| 0.111.5 | 90 / 23 | |
| 0.111.4 | 90 / 23 | |
| 0.111.3 | 90 / 23 | |
| 0.111.2 | 90 / 23 | |
| 0.111.1 | 90 / 23 | |
| 0.111.0 | 90 / 23 | |
| 0.110.5 | 90 / 23 | |
| 0.110.4 | 90 / 23 | |
| 0.110.3 | 90 / 23 | |
| 0.110.2 | 90 / 23 | |
| 0.110.1 | 90 / 23 | |
| 0.110.0 | 90 / 23 | |
| 0.109.2 | 90 / 23 | |
| 0.109.1 | 90 / 23 | |
| 0.109.0 | 90 / 23 | |
| 0.108.0 | 89 / 23 | |
| 0.107.6 | 89 / 23 | |
| 0.107.5 | 89 / 23 | |
| 0.107.4 | 89 / 23 | |
| 0.107.3 | 89 / 23 | |
| 0.107.2 | 89 / 23 | |
| 0.107.1 | 89 / 23 | |
| 0.107.0 | 89 / 23 | |
| 0.106.0 | 89 / 23 | |
| 0.105.4 | 89 / 23 | |
| 0.105.3 | 89 / 23 | |
| 0.105.2 | 89 / 23 | |
| 0.105.1 | 89 / 23 | |
| 0.105.0 | 89 / 23 | |
| 0.104.0 | 89 / 23 | |
| 0.103.0 | 89 / 23 | |
| 0.102.4 | 89 / 23 | |
| 0.102.3 | 89 / 23 | |
| 0.102.2 | 89 / 23 | |
| 0.102.1 | 89 / 23 | |
| 0.102.0 | 89 / 23 | |
| 0.101.0 | 88 / 22 | |
| 0.100.1 | 87 / 22 | |
| 0.100.0 | 87 / 22 | |
| 0.99.8 | 85 / 22 | |
| 0.99.7 | 85 / 22 | |
| 0.99.6 | 85 / 22 | |
| 0.99.5 | 85 / 22 | |
| 0.99.4 | 85 / 22 | |
| 0.99.3 | 85 / 22 | |
| 0.99.2 | 85 / 22 | |
| 0.99.1 | 85 / 22 | |
| 0.99.0 | 85 / 22 | |
| 0.98.0 | 83 / 22 | |
| 0.97.5 | 83 / 22 | |
| 0.97.4 | 83 / 22 | |
| 0.97.3 | 83 / 22 | |
| 0.97.2 | 83 / 22 | |
| 0.97.1 | 83 / 22 | |
| 0.97.0 | 83 / 22 | |
| 0.96.0 | 82 / 22 | |
| 0.95.0 | 82 / 22 | |
| 0.94.6 | 82 / 22 | |
| 0.94.5 | 82 / 22 | |
| 0.94.4 | 82 / 22 | |
| 0.94.3 | 82 / 22 | |
| 0.94.2 | 82 / 22 | |
| 0.94.1 | 82 / 22 | |
| 0.94.0 | 82 / 22 | |
| 0.93.13 | 82 / 22 | |
| 0.93.12 | 82 / 22 | |
| 0.93.11 | 82 / 22 | |
| 0.93.10 | 82 / 22 | |
| 0.93.9 | 82 / 22 | |
| 0.93.8 | 82 / 22 | |
| 0.93.7 | 82 / 22 | |
| 0.93.6 | 82 / 22 | |
| 0.93.5 | 82 / 22 | |
| 0.93.4 | 82 / 22 | |
| 0.93.3 | 82 / 22 | |
| 0.93.2 | 82 / 22 | |
| 0.93.1 | 82 / 22 |
v0.114.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.113.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.112.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.112.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.111.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.110.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.110.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.110.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.110.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.110.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.110.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.109.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.109.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.109.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.108.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.107.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.107.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.107.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.107.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.107.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.107.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.107.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.106.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.105.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.105.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.105.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.105.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.105.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.104.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.103.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.102.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.102.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.102.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.102.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.102.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.101.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.100.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.100.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.99.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.98.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.97.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.97.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.97.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.97.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.97.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.97.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.96.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.95.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.94.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.94.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.94.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.94.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.94.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.94.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.94.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.93.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.