← Home

@bigcommerce/create-catalyst

Create a new Catalyst project, and optionally connect the project to a BigCommerce store. Add `--help` to the end of any command to learn about available subcommands and options.

9
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

bcnpmuserchanceaclarkjairobcjmwiesejorgemoyacilotoma-rdavidchin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@bigcommerce/catalyst AI (dependencies): Same-org first-party package, part of monorepo refactor. ai
phantom-deps phantom-dep:@bigcommerce/catalyst AI (phantom-deps): Same-org sibling package, likely used via subprocess/scaffold, not direct import. ai
provenance publisher-changed AI (provenance): Change from manual to GitHub Actions CI/CD publish for BigCommerce org; SLSA attestation confirms legitimate transition. ai
phantom-deps phantom-dep:giget AI (phantom-deps): giget is declared and used as a direct dependency; phantom-dep heuristic is a false positive. ai
phantom-deps phantom-dep:commander AI (phantom-deps): commander is declared and used indirectly via @commander-js/extra-typings; stable false positive. ai
phantom-deps phantom-dep:@inquirer/type AI (phantom-deps): @inquirer/type is declared and used indirectly via @inquirer/prompts; stable false positive. ai

Versions (showing 9 of 9)

Version Deps Published
2.0.3 2 / 12
2.0.2 2 / 12
2.0.1 2 / 12
2.0.0 2 / 12
1.1.0 23 / 17
1.0.3 23 / 17
1.0.2 23 / 17
1.0.1 23 / 17
1.0.0 23 / 17

v2.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.