← Home

@remixhq/cli

Remix CLI tooling

29
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

abdelrahman_rizq97heshamg

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Move to GitHub Actions CI publisher is provenance improvement, not compromise. ai
source-diff net-exec-file:dist/cli.cjs AI (source-diff): Bundled CLI output (tsup), boilerplate matches build tooling, no malicious payload in sample. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Used in source, bundled by tsup; false positive pattern for this package. ai
phantom-deps phantom-dep:@remixhq/core AI (phantom-deps): Same-org dependency, used via build. ai
phantom-deps phantom-dep:execa AI (phantom-deps): Used in source, bundled by tsup. ai
phantom-deps phantom-dep:commander AI (phantom-deps): Used in source, bundled by tsup. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package @remixhq/cli is a CLI tool for the RemixDotOne project; name similarity to 'joi' is purely incidental and not a plausible typosquat vector. ai

Versions (showing 29 of 29)

Version Deps Published
0.1.59 12 / 10
0.1.58 12 / 10
0.1.57 12 / 10
0.1.36 11 / 8
0.1.35 11 / 8
0.1.34 11 / 8
0.1.33 11 / 8
0.1.32 11 / 8
0.1.31 11 / 8
0.1.30 11 / 8
0.1.29 11 / 8
0.1.28 11 / 8
0.1.27 11 / 8
0.1.26 11 / 7
0.1.25 11 / 7
0.1.24 11 / 7
0.1.23 11 / 7
0.1.22 11 / 7
0.1.21 11 / 7
0.1.20 11 / 7
0.1.19 11 / 7
0.1.18 11 / 7
0.1.17 11 / 7
0.1.16 11 / 7
0.1.15 11 / 7
0.1.14 11 / 7
0.1.13 11 / 7
0.1.12 11 / 7
0.1.11 11 / 7

v0.1.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.58

3 findings
HIGH Publisher changed: abdelrahman_rizq97 → GitHub Actions (on 2026-07-17) provenance

[Reject — re-review on republish] (prior reject: AI (provenance): Publisher changed from known maintainer to anonymous GitHub Actions account with no track record; generalizes as a disqualifier until verified.) This version was published by a different npm account than previous versions on 2026-07-17. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: dist/cli.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.57

3 findings
HIGH Publisher changed: abdelrahman_rizq97 → GitHub Actions (on 2026-06-30) provenance

[Reject — re-review on republish] (prior reject: AI (provenance): Publisher changed from known maintainer to anonymous GitHub Actions account with no track record; generalizes as a disqualifier until verified.) This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New file with network + code execution: dist/cli.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.