@bigcommerce/create-catalyst
Create a new Catalyst project, and optionally connect the project to a BigCommerce store. Add `--help` to the end of any command to learn about available subcommands and options.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@bigcommerce/catalyst | AI (dependencies): Same-org first-party package, part of monorepo refactor. | ai | |
| phantom-deps | phantom-dep:@bigcommerce/catalyst | AI (phantom-deps): Same-org sibling package, likely used via subprocess/scaffold, not direct import. | ai | |
| provenance | publisher-changed | AI (provenance): Change from manual to GitHub Actions CI/CD publish for BigCommerce org; SLSA attestation confirms legitimate transition. | ai | |
| phantom-deps | phantom-dep:giget | AI (phantom-deps): giget is declared and used as a direct dependency; phantom-dep heuristic is a false positive. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): commander is declared and used indirectly via @commander-js/extra-typings; stable false positive. | ai | |
| phantom-deps | phantom-dep:@inquirer/type | AI (phantom-deps): @inquirer/type is declared and used indirectly via @inquirer/prompts; stable false positive. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 2.0.3 | 2 / 12 | |
| 2.0.2 | 2 / 12 | |
| 2.0.1 | 2 / 12 | |
| 2.0.0 | 2 / 12 | |
| 1.1.0 | 23 / 17 | |
| 1.0.3 | 23 / 17 | |
| 1.0.2 | 23 / 17 | |
| 1.0.1 | 23 / 17 | |
| 1.0.0 | 23 / 17 |
v2.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.