@muil/cli
Visit [Muil Docs.](https://docs.muil.io)
8
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
shahaf.muilnir.avrahamnirne
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@azure/storage-file | AI (dependencies): Azure storage SDK dep for cloud upload feature; stable usage pattern for this CLI tool. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-class-properties | AI (phantom-deps): Babel plugin loaded by convention via babel config, not direct import; stable pattern for this CLI build tool. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-optional-chaining | AI (phantom-deps): Babel plugin loaded by convention via babel config; stable pattern for this CLI build tool. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-nullish-coalescing-operator | AI (phantom-deps): Babel plugin loaded by convention via babel config; stable pattern for this CLI build tool. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Framework-scoped babel package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@babel/preset-react | AI (phantom-deps): Framework-scoped babel package loaded by convention. | ai | |
| phantom-deps | phantom-dep:@babel/preset-typescript | AI (phantom-deps): Framework-scoped babel package loaded by convention. | ai | |
| phantom-deps | phantom-dep:webpack-cli | AI (phantom-deps): Referenced in config files; standard webpack CLI tool pattern. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @muil/cli is a scoped CLI package unrelated to joi; Levenshtein match is coincidental. | ai | |
| phantom-deps | phantom-dep:url-loader | AI (phantom-deps): Referenced in webpack config; not directly imported by JS. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@muil/templates-starter-kit | AI (phantom-deps): Same org scope; loaded at runtime by CLI, not statically imported. | ai | |
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): Referenced in webpack config; not directly imported by JS. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside bundled webpack output (lib/index.js); not attacker-controlled input. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Loads user-supplied config file by resolved path; standard CLI build-tool pattern. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped babel package loaded by convention, not direct import. | ai |