@angular/cli
CLI tool for Angular
87
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
angulargoogle-wombot
Keywords
Angular CLIAngular DevKitangularangular-clidevkitsdk
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): zod and @modelcontextprotocol/sdk are established, legitimate packages added intentionally for Angular CLI's MCP server feature in v20.1.0. No malicious signal. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Angular CLI regularly adds new source files with major/minor version bumps; 26 new files in a .3.0 release is consistent with active feature development (e.g., MCP tooling). | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): @angular/cli legitimately uses child_process to spawn build subprocesses and local CLI versions. This is expected, documented behavior for a CLI tool. | ai | |
| source-diff | net-exec-file:src/utilities/load-esm.js | AI (source-diff): Well-documented TypeScript workaround using new Function for dynamic import(); no actual network call. Standard Angular CLI pattern. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function used solely to preserve dynamic import() from TS downleveling; documented workaround in Angular CLI. | ai | |
| provenance | no-provenance | AI (provenance): Google-published Angular packages currently lack provenance; not a security concern given publisher trust level. | ai | |
| phantom-deps | phantom-dep:@schematics/angular | AI (phantom-deps): @schematics/angular is referenced in ng-update config for migrations, not directly imported in JS — expected pattern for Angular CLI. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @angular/cli has no relationship to joi; Levenshtein distance match is a structural false positive for long scoped names. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require of project-local CLI is Angular CLI's documented version-resolution mechanism; stable and intentional. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Spreading process.env into child process spawn options is standard practice in CLI tools for passing environment context. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): AES-256-GCM decryption protects a read-only Algolia search API key for Angular docs; not malicious payload hiding. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Enumerating process.env for npm proxy/registry config is standard in package management tooling. | ai |
Versions (showing 87 of 187)
| Version | Deps | Published |
|---|---|---|
| 19.2.19 | 17 / 0 | |
| 19.2.18 | 17 / 0 | |
| 19.2.17 | 17 / 0 | |
| 19.2.16 | 17 / 0 | |
| 19.2.15 | 17 / 0 | |
| 19.2.14 | 17 / 0 | |
| 19.2.13 | 17 / 0 | |
| 19.2.12 | 17 / 0 | |
| 19.2.11 | 17 / 0 | |
| 19.2.10 | 17 / 0 | |
| 19.2.9 | 17 / 0 | |
| 19.2.8 | 17 / 0 | |
| 19.2.7 | 17 / 0 | |
| 19.2.6 | 17 / 0 | |
| 19.2.5 | 17 / 0 | |
| 19.2.4 | 17 / 0 | |
| 19.2.3 | 17 / 0 | |
| 19.2.2 | 17 / 0 | |
| 19.2.1 | 17 / 0 | |
| 19.2.0 | 17 / 0 | |
| 19.1.9 | 17 / 0 | |
| 19.1.8 | 17 / 0 | |
| 19.1.7 | 17 / 0 | |
| 19.1.6 | 17 / 0 | |
| 19.1.5 | 17 / 0 | |
| 19.1.4 | 17 / 0 | |
| 19.1.3 | 17 / 0 | |
| 19.1.2 | 17 / 0 | |
| 19.1.1 | 17 / 0 | |
| 19.1.0 | 17 / 0 | |
| 19.0.7 | 17 / 0 | |
| 19.0.6 | 17 / 0 | |
| 19.0.5 | 17 / 0 | |
| 19.0.4 | 17 / 0 | |
| 19.0.3 | 17 / 0 | |
| 19.0.2 | 17 / 0 | |
| 19.0.1 | 17 / 0 | |
| 19.0.0 | 17 / 0 | |
| 18.2.21 | 17 / 0 | |
| 18.2.20 | 17 / 0 | |
| 18.2.19 | 17 / 0 | |
| 18.2.18 | 17 / 0 | |
| 18.2.17 | 17 / 0 | |
| 18.2.16 | 17 / 0 | |
| 18.2.15 | 17 / 0 | |
| 18.2.14 | 17 / 0 | |
| 18.2.13 | 17 / 0 | |
| 18.2.12 | 17 / 0 | |
| 18.2.11 | 17 / 0 | |
| 18.2.10 | 17 / 0 | |
| 18.2.9 | 17 / 0 | |
| 18.2.8 | 17 / 0 | |
| 18.2.7 | 17 / 0 | |
| 18.2.6 | 17 / 0 | |
| 18.2.5 | 17 / 0 | |
| 18.2.4 | 17 / 0 | |
| 18.2.3 | 17 / 0 | |
| 18.2.2 | 17 / 0 | |
| 18.2.1 | 17 / 0 | |
| 18.2.0 | 17 / 0 | |
| 18.1.4 | 17 / 0 | |
| 18.1.3 | 17 / 0 | |
| 18.1.2 | 17 / 0 | |
| 18.1.1 | 17 / 0 | |
| 18.1.0 | 17 / 0 | |
| 18.0.7 | 17 / 0 | |
| 18.0.6 | 17 / 0 | |
| 18.0.5 | 17 / 0 | |
| 18.0.4 | 17 / 0 | |
| 18.0.3 | 17 / 0 | |
| 18.0.2 | 17 / 0 | |
| 18.0.1 | 17 / 0 | |
| 18.0.0 | 17 / 0 | |
| 17.3.17 | 18 / 0 | |
| 17.3.16 | 18 / 0 | |
| 17.3.15 | 18 / 0 | |
| 17.3.14 | 18 / 0 | |
| 17.3.13 | 18 / 0 | |
| 17.3.12 | 18 / 0 | |
| 17.3.11 | 18 / 0 | |
| 17.3.10 | 18 / 0 | |
| 17.3.9 | 18 / 0 | |
| 17.3.8 | 18 / 0 | |
| 17.3.7 | 18 / 0 | |
| 17.3.6 | 18 / 0 | |
| 16.2.16 | 18 / 0 | |
| 16.2.15 | 18 / 0 |