Skip to content

v1.0.0 — the whole engine, offline

Latest

Choose a tag to compare

@Nizoka Nizoka released this 08 Oct 20:05
954bb5d

pkinative-cli v1.0.0

Released 2026-10-08 · engine: pkinative ^1.0.0

The first release of the official command line for pkinative. Every one of the engine's 294 exports is reached by one of 18 commands, and a test holds that claim to the engine's frozen API.
The CLI is offline, has pkinative as its only runtime dependency, and exposes one process contract to people, scripts and AI agents: the artefact or report on stdout, one JSON envelope on stderr, exit 0/1/2.

Highlights

  • Read and judge everything the engine reads: certificates, PKCS#10 requests, CRLs, OCSP responses, CMS SignedData, RFC 3161 tokens, PKCS#8 and PKCS#12; ASN.1, PEM and OIDs at the byte level.
  • One-call verdicts: chain verify builds the path, verifies every signature, validates it under RFC 5280, checks the host name and purposes, and judges revocation from the CRLs and OCSP answers you supply.
  • Create what the engine creates: certificates and requests from JSON specs, CMS signatures (attached, detached or from a digest) with time-stamps, OCSP and time-stamp requests. Keys stay yours: imported non-extractable, never generated, never exported.
  • Built for automation: pkinative's PKI_* codes verbatim beside 13 stable CLI classes, explain for every code, schema for every report, --fields and --summary to keep agent transcripts short.

Security

  • feat(security): no secret on argv (CWE-214): passwords come from a file, stdin or PKINATIVE_PASSWORD.
  • feat(security): no key material in any key or p12 report (CWE-312), checked over every PKCS#12 reader; the byte-level tools (asn1 decode, pem decode) print what you give them.
  • feat(security): exclusive writes refuse an existing path, a symbolic link included; --overwrite replaces it through a temporary file and a rename, never through the link; a half-written file is removed on a signal (CWE-59, CWE-367).
  • feat(security): --strict escalates the first engine warning on every command, a verify or check report included (the engine escalates only while parsing).
  • feat(security): cms add-timestamp checks that the token stamps the signer's signature value before it writes anything; a token over the content is E_INPUT with PKI_REASON_TSP_IMPRINT_MISMATCH and the recipe as remedy (the cms-add-timestamp sample demonstrates the refusal, exit 1, and the completion sample is re-pinned for the --label flag registered wherever --encoding pem is advertised).
  • feat(security): every engine bound behind a --max-* flag, every input capped before it is read (CWE-400, CWE-770).
  • feat(security): .pkinativerc.json is presentation only (ADR 0007): nine allowed keys, every other key refused, and the applied file named in the envelope — a planted file can never change what is read, trusted, when it is judged, a bound, or where output goes; it may choose a report format or an artefact encoding, and strict only tightens.
  • feat(security): the parser holds every invocation to the registry: an alias is its flag, a flag or switch given twice, an extra argument and a misspelt spec member are refused, so no verdict depends on the order or spelling of the flags.
  • feat(security): the engine's refusals kept: no network, no key generation, no key or PKCS#12 writer, no legacy PKCS#12 scheme, no default RSA scheme, no SHA-1 without --allow-sha1.

Added

  • feat(encodings): pem, oid, fingerprint, asn1.
  • feat(cert): cert (inspect, create, encode, decode-extension, verify-signature, check-name, match-name, check-purpose) and csr (inspect, create, verify).
  • feat(chain): chain (verify, build, validate).
  • feat(revocation): crl (inspect, find, verify-signature, check) and ocsp (request, cert-id, inspect, verify-signature, check).
  • feat(signatures): cms (sign, verify, inspect, verify-signer, add-attribute, add-timestamp) and tsp (request, inspect, verify).
  • feat(keys): key (inspect, check) and p12 (inspect, verify-mac, bags, open).
  • feat(meta): doctor, limits, explain, schema, completion (its pinned sample re-pinned before release: aliases complete like their flags, file names after a path flag, shell names after completion).

Engine

pkinative ^1.0.0. All 117 runtime exports and, through their signatures, all 177 types are reached (docs/data/core-exports.json); the 55 bullets of the engine's 1.0.0 CHANGELOG are each mapped to a CLI test or a typed waiver (tests/regression/engine-surface.json).

Install

npm install --global pkinative-cli@1.0.0 --ignore-scripts
pkinative doctor

The repository is held to pdfnative-cli's norms by npm run verify:docs (13 rules: generated files, commands, samples, figures, versions, links, PR template, agent settings and hook, context budgets, package files, ADRs, English prose, LF line endings) and the deliberate divergences are listed in CONTRIBUTING.md §Conformity with pdfnative-cli. The package ships a bin and no main: require('pkinative-cli') fails instead of running the CLI; every install uses --ignore-scripts (the package has no install-time script).

To check the registry signatures and the provenance, install it once in an empty project and run npm audit signatures there (it audits the project it runs in); SECURITY.md §Release integrity gives the full recipe.

Node.js ^22.22.2 || ^24.14.1 || >=25.8.2 (CVE-2026-21713). The tarball on this Release is the registry's, with its SBOMs and a Sigstore attestation; SECURITY.md §Release integrity has the verification commands.

Links