Repository navigation
pkinative-cli v1.0.0
Released 2026-10-08 · engine: pkinative ^1.0.0
The first release of the official command line for pkinative. Every one of the engine's 294 exports is reached by one of 18 commands, and a test holds that claim to the engine's frozen API.
The CLI is offline, has pkinative as its only runtime dependency, and exposes one process contract to people, scripts and AI agents: the artefact or report on stdout, one JSON envelope on stderr, exit 0/1/2.
Highlights
- Read and judge everything the engine reads: certificates, PKCS#10 requests, CRLs, OCSP responses, CMS SignedData, RFC 3161 tokens, PKCS#8 and PKCS#12; ASN.1, PEM and OIDs at the byte level.
- One-call verdicts:
chain verifybuilds the path, verifies every signature, validates it under RFC 5280, checks the host name and purposes, and judges revocation from the CRLs and OCSP answers you supply. - Create what the engine creates: certificates and requests from JSON specs, CMS signatures (attached, detached or from a digest) with time-stamps, OCSP and time-stamp requests. Keys stay yours: imported non-extractable, never generated, never exported.
- Built for automation: pkinative's
PKI_*codes verbatim beside 13 stable CLI classes,explainfor every code,schemafor every report,--fieldsand--summaryto keep agent transcripts short.
Security
- feat(security): no secret on argv (CWE-214): passwords come from a file, stdin or
PKINATIVE_PASSWORD. - feat(security): no key material in any
keyorp12report (CWE-312), checked over every PKCS#12 reader; the byte-level tools (asn1 decode,pem decode) print what you give them. - feat(security): exclusive writes refuse an existing path, a symbolic link included;
--overwritereplaces it through a temporary file and a rename, never through the link; a half-written file is removed on a signal (CWE-59, CWE-367). - feat(security):
--strictescalates the first engine warning on every command, a verify or check report included (the engine escalates only while parsing). - feat(security):
cms add-timestampchecks that the token stamps the signer's signature value before it writes anything; a token over the content isE_INPUTwithPKI_REASON_TSP_IMPRINT_MISMATCHand the recipe asremedy(thecms-add-timestampsample demonstrates the refusal, exit 1, and thecompletionsample is re-pinned for the--labelflag registered wherever--encoding pemis advertised). - feat(security): every engine bound behind a
--max-*flag, every input capped before it is read (CWE-400, CWE-770). - feat(security):
.pkinativerc.jsonis presentation only (ADR 0007): nine allowed keys, every other key refused, and the applied file named in the envelope — a planted file can never change what is read, trusted, when it is judged, a bound, or where output goes; it may choose a report format or an artefact encoding, andstrictonly tightens. - feat(security): the parser holds every invocation to the registry: an alias is its flag, a flag or switch given twice, an extra argument and a misspelt spec member are refused, so no verdict depends on the order or spelling of the flags.
- feat(security): the engine's refusals kept: no network, no key generation, no key or PKCS#12 writer, no legacy PKCS#12 scheme, no default RSA scheme, no SHA-1 without
--allow-sha1.
Added
- feat(encodings):
pem,oid,fingerprint,asn1. - feat(cert):
cert(inspect, create, encode, decode-extension, verify-signature, check-name, match-name, check-purpose) andcsr(inspect, create, verify). - feat(chain):
chain(verify, build, validate). - feat(revocation):
crl(inspect, find, verify-signature, check) andocsp(request, cert-id, inspect, verify-signature, check). - feat(signatures):
cms(sign, verify, inspect, verify-signer, add-attribute, add-timestamp) andtsp(request, inspect, verify). - feat(keys):
key(inspect, check) andp12(inspect, verify-mac, bags, open). - feat(meta):
doctor,limits,explain,schema,completion(its pinned sample re-pinned before release: aliases complete like their flags, file names after a path flag, shell names aftercompletion).
Engine
pkinative ^1.0.0. All 117 runtime exports and, through their signatures, all 177 types are reached (docs/data/core-exports.json); the 55 bullets of the engine's 1.0.0 CHANGELOG are each mapped to a CLI test or a typed waiver (tests/regression/engine-surface.json).
Install
npm install --global pkinative-cli@1.0.0 --ignore-scripts
pkinative doctorThe repository is held to pdfnative-cli's norms by npm run verify:docs (13 rules: generated files, commands, samples, figures, versions, links, PR template, agent settings and hook, context budgets, package files, ADRs, English prose, LF line endings) and the deliberate divergences are listed in CONTRIBUTING.md §Conformity with pdfnative-cli. The package ships a bin and no main: require('pkinative-cli') fails instead of running the CLI; every install uses --ignore-scripts (the package has no install-time script).
To check the registry signatures and the provenance, install it once in an empty project and run npm audit signatures there (it audits the project it runs in); SECURITY.md §Release integrity gives the full recipe.
Node.js ^22.22.2 || ^24.14.1 || >=25.8.2 (CVE-2026-21713). The tarball on this Release is the registry's, with its SBOMs and a Sigstore attestation; SECURITY.md §Release integrity has the verification commands.