@nuxt/cli
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-takeover | AI (maintainer-change): danielroe is the Nuxt project lead; transition from nuxtbot bot account is legitimate. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance present; gitHead absence is a CI config change, not a risk signal. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): danielroe is the known Nuxt lead maintainer. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from individual maintainer to GitHub Actions CI/CD; SLSA provenance confirms legitimate automation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Nuxt org moved to CI publishing; maintainers still control the GitHub repo. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @nuxt/cli is the official Nuxt CLI under the @nuxt org scope; edit-distance match to 'joi' is a spurious false positive with no impersonation risk. | ai | |
| dependencies | unvetted-dep:youch | AI (dependencies): youch is a well-known UnJS/Nuxt ecosystem error renderer; its use in @nuxt/cli is expected and legitimate. | ai | |
| dependencies | unvetted-dep:tinyclip | AI (dependencies): tinyclip is a small utility in the UnJS ecosystem; its use in the official Nuxt CLI is expected. | ai | |
| dependencies | unvetted-dep:listhen | AI (dependencies): listhen is a standard UnJS server listener utility used across the Nuxt ecosystem; no risk. | ai | |
| dependencies | unvetted-dep:pkg-types | AI (dependencies): pkg-types is a widely-used UnJS package for package.json type utilities; standard dependency for Nuxt tooling. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 3.37.0 | 28 / 17 | |
| 3.36.1 | 28 / 17 | |
| 3.36.0 | 28 / 17 | |
| 3.35.2 | 28 / 17 | |
| 3.35.1 | 28 / 17 | |
| 3.35.0 | 28 / 17 | |
| 3.34.0 | 28 / 17 | |
| 3.33.1 | 28 / 17 | |
| 3.33.0 | 28 / 17 | |
| 3.32.0 | 27 / 17 | |
| 3.31.3 | 27 / 17 | |
| 3.31.2 | 27 / 17 | |
| 3.31.1 | 27 / 17 | |
| 3.31.0 | 27 / 17 | |
| 3.30.0 | 24 / 16 | |
| 3.29.3 | 27 / 10 | |
| 3.29.2 | 27 / 10 | |
| 3.29.1 | 27 / 10 | |
| 3.29.0 | 27 / 10 | |
| 3.28.0 | 26 / 10 | |
| 3.27.0 | 26 / 10 | |
| 3.26.4 | 26 / 10 | |
| 3.26.3 | 26 / 10 | |
| 3.26.2 | 25 / 10 | |
| 3.26.1 | 25 / 10 | |
| 3.26.0 | 26 / 9 | |
| 3.25.1 | 24 / 8 | |
| 3.25.0 | 24 / 8 | |
| 3.24.1 | 24 / 8 | |
| 3.24.0 | 24 / 8 | |
| 3.23.1 | 23 / 7 | |
| 3.23.0 | 23 / 7 | |
| 3.22.5 | 23 / 7 | |
| 3.22.4 | 23 / 7 | |
| 3.22.3 | 23 / 7 | |
| 3.22.2 | 23 / 7 | |
| 3.22.1 | 23 / 7 | |
| 3.22.0 | 23 / 7 | |
| 3.21.1 | 23 / 7 | |
| 3.20.0 | 23 / 20 |
v3.37.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v3.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.23.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.23.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.22.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.22.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.22.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.22.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.22.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.21.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.