← Home

@nuxtjs/shopify

Easily integrate Shopify with Nuxt 3 and 4 🚀

38
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

pi0atinuxdanielroeantfukonkofreb97

Keywords

nuxtnuxt3nuxt4nuxtjsnuxt-moduleshopifyecommercestorefrontstorefront-apiadmin-apigraphqltypescriptcodegen

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:graphql-yoga AI (phantom-deps): Used in codegen config, not directly imported; consistent with other accepted codegen phantom-deps. ai
provenance missing-githead AI (provenance): CI/CD publish with SLSA attestation intact; gitHead omission is not a provenance regression. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation under nuxt-modules org; legitimate automation pattern. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org-level CI/CD takeover of publishing; nuxt-modules org package with SLSA provenance. ai
dependencies unvetted-dep:@shopify/api-codegen-preset AI (dependencies): Official Shopify codegen preset; expected for this Shopify Nuxt module. ai
dependencies unvetted-dep:@shopify/graphql-client AI (dependencies): Official Shopify SDK package; stable dependency for this Shopify integration module. ai
dependencies unvetted-dep:@shopify/graphql-codegen AI (dependencies): Official Shopify codegen package; expected dependency for this module. ai
dependencies unvetted-dep:@graphql-codegen/import-types-preset AI (dependencies): Well-known graphql-codegen ecosystem package; stable for this module. ai
phantom-deps phantom-dep:@shopify/api-codegen-preset AI (phantom-deps): Config-file-only reference; not a runtime import, expected for codegen tooling. ai
phantom-deps phantom-dep:@graphql-codegen/import-types-preset AI (phantom-deps): Config-file-only reference; expected codegen tooling pattern. ai
phantom-deps phantom-dep:@graphql-codegen/plugin-helpers AI (phantom-deps): Config-file-only reference; expected codegen tooling pattern. ai
phantom-deps phantom-dep:@graphql-codegen/introspection AI (phantom-deps): Config-file-only reference; expected codegen tooling pattern. ai

Versions (showing 38 of 38)

Version Deps Published
0.7.1 25 / 19
0.7.0 25 / 19
0.6.2 23 / 18
0.6.1 23 / 18
0.6.0 23 / 18
0.5.4 23 / 19
0.5.3 23 / 19
0.5.2 23 / 19
0.5.1 23 / 19
0.5.0 23 / 19
0.4.6 23 / 17
0.4.5 23 / 17
0.4.4 23 / 16
0.4.3 23 / 16
0.4.2 23 / 16
0.4.1 23 / 16
0.4.0 23 / 16
0.3.16 21 / 17
0.3.15 21 / 17
0.3.14 19 / 17
0.3.13 20 / 17
0.3.12 20 / 17
0.3.11 20 / 17
0.3.10 20 / 17
0.3.9 19 / 18
0.3.8 19 / 18
0.3.7 19 / 18
0.3.6 19 / 18
0.3.5 19 / 18
0.3.4 19 / 18
0.3.3 19 / 18
0.3.2 18 / 18
0.3.1 18 / 18
0.3.0 18 / 18
0.2.0 14 / 17
0.1.7 14 / 17
0.1.6 14 / 17
0.1.5 14 / 18

v0.7.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v0.7.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.