← Home

loop-things

loop through commands in fun and amazing ways!

24
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

mateodelnorte

Keywords

loopcommandcommands

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata suspicious-initial-version AI (npm-metadata): Package is 9+ years old with 24 versions and a trusted publisher (mateodelnorte, 115 approved). The 0.0.0 version is the original release, not a throwaway. ai
phantom-deps phantom-dep:mocha AI (phantom-deps): mocha is a test runner declared as a runtime dep by mistake; not imported in production code, no security risk. ai
phantom-deps phantom-dep:should AI (phantom-deps): should is a test assertion library declared as runtime dep; not imported in production code, no security risk. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): yargs is a CLI arg parser used indirectly via bin scripts; phantom-dep finding is a false positive for this CLI package. ai
phantom-deps phantom-dep:cross-env AI (phantom-deps): cross-env is a CLI utility used in scripts context; phantom-dep finding is a false positive for this CLI package. ai
phantom-deps phantom-dep:concurrently AI (phantom-deps): concurrently is a CLI utility used in scripts context; phantom-dep finding is a false positive for this CLI package. ai
phantom-deps phantom-dep:global-paths AI (phantom-deps): global-paths is used indirectly in the CLI toolchain; phantom-dep finding is a false positive for this CLI package. ai
semgrep semgrep:child-process-import AI (semgrep): loop-things is a CLI command runner; child_process usage in expandCommand.js is core to its documented purpose of executing and looping commands. ai

Versions (showing 24 of 24)

Version Deps Published
0.0.23 8 / 0
0.0.22 12 / 0
0.0.21 12 / 0
0.0.20 10 / 0
0.0.19 9 / 0
0.0.18 9 / 0
0.0.17 9 / 0
0.0.16 8 / 0
0.0.15 8 / 0
0.0.14 8 / 0
0.0.13 7 / 0
0.0.12 6 / 0
0.0.11 6 / 0
0.0.10 6 / 0
0.0.9 6 / 0
0.0.8 6 / 0
0.0.7 6 / 0
0.0.6 6 / 0
0.0.5 6 / 0
0.0.4 6 / 0
0.0.3 6 / 0
0.0.2 6 / 0
0.0.1 5 / 0
0.0.0 5 / 0

v0.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.