← Home

@muil/cli

Visit [Muil Docs.](https://docs.muil.io)

8
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

shahaf.muilnir.avrahamnirne

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@azure/storage-file AI (dependencies): Azure storage SDK dep for cloud upload feature; stable usage pattern for this CLI tool. ai
phantom-deps phantom-dep:@babel/plugin-proposal-class-properties AI (phantom-deps): Babel plugin loaded by convention via babel config, not direct import; stable pattern for this CLI build tool. ai
phantom-deps phantom-dep:@babel/plugin-proposal-optional-chaining AI (phantom-deps): Babel plugin loaded by convention via babel config; stable pattern for this CLI build tool. ai
phantom-deps phantom-dep:@babel/plugin-proposal-nullish-coalescing-operator AI (phantom-deps): Babel plugin loaded by convention via babel config; stable pattern for this CLI build tool. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Framework-scoped babel package loaded by convention. ai
phantom-deps phantom-dep:@babel/preset-react AI (phantom-deps): Framework-scoped babel package loaded by convention. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Framework-scoped babel package loaded by convention. ai
phantom-deps phantom-dep:webpack-cli AI (phantom-deps): Referenced in config files; standard webpack CLI tool pattern. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @muil/cli is a scoped CLI package unrelated to joi; Levenshtein match is coincidental. ai
phantom-deps phantom-dep:url-loader AI (phantom-deps): Referenced in webpack config; not directly imported by JS. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): Referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:@muil/templates-starter-kit AI (phantom-deps): Same org scope; loaded at runtime by CLI, not statically imported. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Referenced in webpack config; not directly imported by JS. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside bundled webpack output (lib/index.js); not attacker-controlled input. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-supplied config file by resolved path; standard CLI build-tool pattern. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped babel package loaded by convention, not direct import. ai

Versions (showing 8 of 8)

Version Deps Published
5.0.4 29 / 1
5.0.3 29 / 1
5.0.2 29 / 1
5.0.1 29 / 1
5.0.0 29 / 1
4.1.13 32 / 1
4.1.12 32 / 1
4.1.11 32 / 1

v5.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.