← Home

@salesforce/b2c-cli

A Salesforce B2C Commerce CLI

46
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

ire-npm-team-userjimjagsalesforce-releasesjasonschroeder-sfdcmobifylwc-adminsalesforce-admin

Keywords

salesforcecommerce-cloudsfccb2ccliecommercedeveloper-toolsdeploymentwebdavoclif

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher with SLSA attestation is the expected CI/CD pattern for this Salesforce org package. ai
source-diff large-new-source-files AI (source-diff): Salesforce org CLI with SLSA provenance; large file count reflects legitimate feature expansion across versions. ai
publish-pattern new-deps-added AI (publish-pattern): @inquirer/prompts is a well-established interactive prompt library; not a suspicious dependency. ai
phantom-deps phantom-dep:@oclif/plugin-not-found AI (phantom-deps): oclif plugins are loaded via oclif config array, not direct imports. This is standard oclif CLI architecture and not a real phantom dependency issue. ai
phantom-deps phantom-dep:@oclif/plugin-help AI (phantom-deps): oclif plugins are loaded via oclif config array, not direct imports. This is standard oclif CLI architecture and not a real phantom dependency issue. ai
phantom-deps phantom-dep:@oclif/plugin-warn-if-update-available AI (phantom-deps): oclif plugins are loaded via oclif config array, not direct imports. This is standard oclif CLI architecture and not a real phantom dependency issue. ai
phantom-deps phantom-dep:@oclif/plugin-autocomplete AI (phantom-deps): oclif plugins are loaded via oclif config array, not direct imports. This is standard oclif CLI architecture and not a real phantom dependency issue. ai
phantom-deps phantom-dep:@oclif/plugin-plugins AI (phantom-deps): oclif plugins are loaded via oclif config array, not direct imports. This is standard oclif CLI architecture and not a real phantom dependency issue. ai
phantom-deps phantom-dep:@oclif/plugin-version AI (phantom-deps): oclif plugins are loaded via oclif config array, not direct imports. This is standard oclif CLI architecture and not a real phantom dependency issue. ai

Versions (showing 46 of 46)

Version Deps Published
1.12.1 14 / 23
1.12.0 14 / 23
1.11.0 14 / 23
1.10.0 14 / 23
1.9.0 14 / 23
1.8.1 14 / 23
1.8.0 14 / 23
1.7.1 14 / 23
1.7.0 14 / 23
1.6.0 14 / 23
1.5.0 14 / 23
1.4.0 14 / 23
1.3.2 14 / 23
1.3.1 14 / 23
1.3.0 14 / 23
1.2.0 14 / 23
1.1.0 14 / 23
1.0.1 14 / 23
1.0.0 14 / 23
0.10.1 14 / 23
0.10.0 14 / 23
0.9.0 14 / 23
0.8.0 14 / 23
0.7.4 14 / 23
0.7.3 14 / 23
0.7.2 14 / 23
0.7.1 14 / 23
0.7.0 14 / 23
0.6.0 14 / 23
0.5.6 14 / 23
0.5.5 14 / 23
0.5.4 14 / 23
0.5.3 14 / 23
0.5.2 14 / 23
0.5.1 14 / 23
0.5.0 14 / 23
0.4.1 14 / 23
0.4.0 14 / 23
0.3.0 12 / 22
0.2.1 12 / 22
0.2.0 12 / 22
0.1.0 11 / 21
0.0.8 11 / 21
0.0.7 11 / 21
0.0.5 11 / 21
0.0.1 0 / 0

v1.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.