provenance-cli.CLI tool for software supply chain intelligence. Queries the NetRise Provenance API to assess package risk across SBOMs, OCI containers, and individual packages. Evaluates contributor security, repo health, advisory exposure, and geo-compliance via a YAML policy engine with CI/CD-native exit codes. Outputs human tables, JSON, or SARIF.