← Home

@capacitor/cli

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

itschacedionicjsjcesarmobilevmfojpendermark-ionicchuckytuhalexgerardojacintoos-pedrobilroharvdoggyjpender-osndrkepatotorui.mendesmarkemercapacitor-plugin-boteric-ionicos-ruialves

Keywords

ionicionic frameworkcapacitoruniversal appprogressive web appscross platform

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
typosquat typosquat.levenshtein:joi AI (typosquat): @capacitor/cli is the official Ionic/Capacitor CLI under the @capacitor scope — no relation to 'joi'. Levenshtein match is a false positive that will apply to every version. ai
phantom-deps phantom-dep:native-run AI (phantom-deps): native-run is a CLI tool invoked as a subprocess by capacitor-cli, not imported as a module. Declared dependency is correct; phantom-dep finding is a stable false positive. ai
dependencies unvetted-dep:native-run AI (dependencies): native-run is an official Ionic tool for running apps on devices/emulators; a well-known dependency of the Capacitor CLI ecosystem. ai
dependencies unvetted-dep:@ionic/utils-terminal AI (dependencies): @ionic/utils-terminal is an internal Ionic utility package from the same organization as @capacitor/cli; expected dependency. ai
dependencies unvetted-dep:@ionic/utils-subprocess AI (dependencies): @ionic/utils-subprocess is an internal Ionic utility package from the same organization as @capacitor/cli; expected dependency. ai
dependencies unvetted-dep:@ionic/cli-framework-output AI (dependencies): @ionic/cli-framework-output is an internal Ionic CLI framework package from the same organization as @capacitor/cli; expected dependency. ai

Versions (showing 20 of 20)

Version Deps Published
8.4.0 17 / 14
8.3.4 17 / 14
8.3.3 17 / 14
8.3.2 17 / 14
8.3.1 17 / 14
8.3.0 17 / 14
8.2.0 17 / 14
8.1.0 17 / 14
8.0.2 17 / 14
8.0.1 17 / 15
8.0.0 17 / 15
7.6.6 17 / 14
7.6.5 17 / 14
7.6.4 17 / 14
7.6.3 17 / 14
7.6.2 17 / 14
7.6.1 17 / 14
7.6.0 17 / 14
7.5.0 17 / 14
7.4.5 17 / 15

v8.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v7.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.