← Home

netlify-cli

Netlify command line tool

21
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

seanrobertsbiilmanneduardoboucasnetlify-botsarahettermikewenkathmbeckhrishikeshkvitaliyrberdavyouvalvserhalp-netlifydomitriusanthonyakardettbarnseancdavismlgualtieri-gatsby

Keywords

apiclinetlifystatic

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Published by official netlify-bot with SLSA provenance; maintainer roster changes are normal for a large org CLI. ai
maintainer-change maintainer-removed AI (maintainer-change): Same rationale — org-managed package with provenance attestation; removals reflect normal team changes. ai
publish-pattern dormant-publish AI (publish-pattern): Official Netlify CLI with SLSA provenance; high-frequency release history makes dormancy gap a false positive for this package. ai
dependencies unvetted-dep:gh-release-fetch AI (dependencies): Expected dependency for a CLI tool that fetches prebuilt binaries from GitHub releases; consistent with netlify-cli's documented install flow. ai
dependencies unvetted-dep:folder-walker AI (dependencies): Filesystem utility; stable dep for this package. ai
dependencies unvetted-dep:express-logging AI (dependencies): Logging middleware; stable dep for this package. ai
dependencies unvetted-dep:maxstache-stream AI (dependencies): Streaming templating dep; stable for this package. ai
dependencies unvetted-dep:@netlify/build-info AI (dependencies): First-party Netlify dep; stable for this package. ai
dependencies unvetted-dep:@netlify/local-functions-proxy AI (dependencies): First-party Netlify dep; stable for this package. ai
dependencies unvetted-dep:git-repo-info AI (dependencies): Git metadata utility; stable dep for this package. ai
dependencies unvetted-dep:maxstache AI (dependencies): Legitimate templating dep used by netlify-cli across versions. ai
dependencies unvetted-dep:http-proxy AI (dependencies): Well-known proxy library; stable dep for this package. ai
dependencies unvetted-dep:ascii-table AI (dependencies): Benign table-formatting utility; stable dep for this package. ai
install-scripts install-script:postinstall AI (install-scripts): Runs a local bundled script (scripts/postinstall.js), not a remote fetch; stable pattern for netlify-cli. ai
phantom-deps phantom-dep:@netlify/edge-functions AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive for netlify-cli. ai
phantom-deps phantom-dep:@opentelemetry/api AI (phantom-deps): Listed in dependencies; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:write-file-atomic AI (phantom-deps): Listed in dependencies; phantom-dep heuristic false positive for this package. ai

Versions (showing 21 of 21)

Version Deps Published
26.0.2 98 / 63
26.0.1 98 / 63
26.0.0 98 / 63
25.6.2 98 / 63
25.6.1 98 / 63
25.6.0 98 / 63
25.3.0 98 / 62
25.1.1 98 / 62
25.1.0 98 / 62
25.0.1 98 / 62
25.0.0 98 / 62
24.11.3 97 / 0
24.11.1 97 / 0
24.11.0 97 / 0
24.9.0 97 / 0
24.8.2 97 / 0
24.5.1 97 / 0
24.1.0 97 / 0
23.13.3 95 / 0
23.11.0 96 / 0
23.10.0 96 / 0

v26.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v26.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v26.0.0

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node ./scripts/postinstall.js

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v25.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.11.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.13.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.