← Home

@shopify/cli

A CLI tool to build for the Shopify platform

15
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jaimie.wayshopify-adminshopify-depmishsmellebuitammychris.craig

Keywords

shopifyshopify-clishopify-partners

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/chunk-4MLEL3VK.js AI (source-diff): Bundled esbuild CLI chunk; net+exec is dual-use build output, not malicious. Chunk names vary per build. ai
source-diff net-exec-file:dist/chunk-4TC4M4RC.js AI (source-diff): Bundled ajv codegen chunk; false positive in build output. ai
source-diff net-exec-file:dist/chunk-2HZMOK4U.js AI (source-diff): Bundled esbuild CLI chunk; network+eval are library internals, not malicious. ai
source-diff net-exec-file:dist/chunk-7BVXGS44.js AI (source-diff): esbuild bundle chunk; benign bundled deps. ai
source-diff net-exec-file:dist/chunk-3EQY5B4S.js AI (source-diff): esbuild bundle chunk of official Shopify CLI; net+exec is normal CLI code. ai
npm-metadata bundled-binaries AI (npm-metadata): yoga.wasm and toml_patch wasm are standard deps for a CLI. ai
source-diff net-exec-file:dist/chunk-BU7R7NFL.js AI (source-diff): esbuild bundle chunk (ajv codegen); benign. ai
source-diff net-exec-file:dist/chunk-47MGPVED.js AI (source-diff): Bundled esbuild output in official Shopify CLI; net+exec is normal CLI/build tooling, no obfuscation. ai
source-diff obfuscated-file:dist/acorn-7M27BPGP.js AI (source-diff): Bundled acorn parser; minified dist output is expected for this CLI package. ai
source-diff net-exec-file:dist/chunk-6LWOWDF4.js AI (source-diff): Bundled CLI chunk with glob/fs utilities; expected for CLI tool. ai
source-diff net-exec-file:dist/chunk-4QTEPWEJ.js AI (source-diff): Bundled CLI chunk; network+exec from bundled dependencies. ai
source-diff net-exec-file:dist/chunk-4J32OHLY.js AI (source-diff): Bundled CLI chunk with standard utilities; network+exec pattern from bundled deps. ai
source-diff obfuscated-file:dist/chokidar-VDIVGBZH.js AI (source-diff): Bundled chokidar file watcher; minified dist output expected. ai
source-diff obfuscated-file:dist/babel-I2RLWM7N.js AI (source-diff): Bundled Babel parser; minified dist output expected. ai
source-diff obfuscated-file:dist/angular-DW5TQVCM.js AI (source-diff): Bundled Angular compiler/parser; minified dist output expected. ai
source-diff net-exec-file:dist/chunk-JXW374CL.js AI (source-diff): Bundled CLI chunk with standard Node fs/net calls; expected for Shopify CLI dist output. ai
source-diff obfuscated-file:dist/angular-UTTM4Y4S.js AI (source-diff): Bundled Angular prettier plugin; minified esbuild output expected. ai
source-diff net-exec-file:dist/chunk-A5SQCM63.js AI (source-diff): Bundled codegen/schema chunk; standard CLI internals. ai
source-diff net-exec-file:dist/chunk-4V4DQ6W7.js AI (source-diff): Bundled CLI chunk with stream/fs utilities; no malicious patterns. ai
source-diff net-exec-file:dist/chunk-3YWUSKWF.js AI (source-diff): Standard utility chunk with fs/stream ops; bundled CLI internals. ai
source-diff obfuscated-file:dist/babel-JS32NLHY.js AI (source-diff): Bundled Babel prettier plugin; minified esbuild output expected. ai
source-diff obfuscated-file:dist/acorn-QBS5IYTX.js AI (source-diff): Bundled acorn parser; minified output from esbuild is expected for this CLI package. ai
source-diff obfuscated-file:dist/cli/commands/app/bulk/cancel.js AI (source-diff): Minified ESM bundle output from Shopify CLI build pipeline; not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Major version v4.0.0 rebuild with new bundle structure; expected for this package. ai
source-diff net-exec-file:dist/chunk-B2EHO7ZC.js AI (source-diff): Bundled stream/network utilities in CLI tool; legitimate pattern for this package. ai
source-diff net-exec-file:dist/chunk-4HHXSMD7.js AI (source-diff): Bundled ajv codegen + network utilities in CLI tool; legitimate pattern for this package. ai
source-diff obfuscated-file:dist/cli/commands/app/build.js AI (source-diff): Minified ESM bundle output from Shopify CLI build pipeline; not obfuscation. ai
source-diff net-exec-file:dist/chunk-AQOYGO3U.js AI (source-diff): Minified CLI bundle containing AJV codegen; standard build artifact for this package. ai
source-diff net-exec-file:dist/chunk-7JFIBCHH.js AI (source-diff): Minified CLI bundle containing GraphQL/TS compiler code; standard build artifact for this package. ai
source-diff net-exec-file:dist/chunk-DEW5QFGH.js AI (source-diff): Minified CLI bundle containing lodash internals; standard build artifact for this package. ai
source-diff net-exec-file:dist/chunk-R6N4NGU6.js AI (source-diff): Minified CLI bundle; standard build artifact for this package. ai
source-diff net-exec-file:dist/chunk-KVWHPGOA.js AI (source-diff): Standard bundled dist chunk for Shopify CLI; lodash/utility code, not malware. ai
source-diff net-exec-file:dist/chunk-RXF32AET.js AI (source-diff): Standard bundled dist chunk; TOML parser and other utilities, not malware. ai
source-diff net-exec-file:dist/chunk-PRNHS74J.js AI (source-diff): Standard bundled dist chunk; GraphQL/React internals, not malware. ai
source-diff net-exec-file:dist/chunk-LH4VO6EV.js AI (source-diff): Standard bundled dist chunk; AJV/codegen internals, not malware. ai
source-diff net-exec-file:dist/chunk-PB3UDYWH.js AI (source-diff): Standard bundled ESM dist chunk for Shopify CLI; SLSA provenance confirms CI/CD origin. ai
source-diff net-exec-file:dist/chunk-WOERFYNW.js AI (source-diff): Standard bundled ESM dist chunk for Shopify CLI; SLSA provenance confirms CI/CD origin. ai
source-diff net-exec-file:dist/chunk-TCRHJ3ZH.js AI (source-diff): Standard bundled ESM dist chunk for Shopify CLI; SLSA provenance confirms CI/CD origin. ai
source-diff net-exec-file:dist/chunk-SVYSLNQH.js AI (source-diff): Standard bundled ESM dist chunk for Shopify CLI; SLSA provenance confirms CI/CD origin. ai
source-diff obfuscated-file:dist/morph-DQREIZD2.js AI (source-diff): TypeScript compiler bundle — standard minified open-source code, not malware. ai
source-diff net-exec-file:dist/morph-DQREIZD2.js AI (source-diff): TypeScript compiler bundle — standard minified open-source code. ai
source-diff net-exec-file:dist/chunk-SVA22NZQ.js AI (source-diff): Semver + utility bundle — standard minified open-source library code. ai
source-diff net-exec-file:dist/chunk-D24XVLOA.js AI (source-diff): AJV codegen bundle — standard minified open-source library code. ai
source-diff net-exec-file:dist/chunk-7FYGRWMW.js AI (source-diff): Lodash + utility bundle — standard minified open-source library code. ai
source-diff net-exec-file:dist/chunk-3TG7H626.js AI (source-diff): GraphQL 16.x bundle — standard minified open-source library code. ai
source-diff net-exec-file:dist/chunk-3CRQIN6A.js AI (source-diff): TOML parser + CLI logic bundle — standard minified build artifact for Shopify CLI. ai
source-diff obfuscated-file:dist/assets/dev-console/extensions/dev-console/assets/index-Bm_GpKQW.js AI (source-diff): Minified React/Vite frontend bundle — standard build artifact. ai
source-diff obfuscated-file:dist/http-proxy-node16-TTURN6MD.js AI (source-diff): Minified http-proxy EventEmitter code — standard build artifact. ai
source-diff obfuscated-file:dist/http-proxy-node16-DSQMBVDI.js AI (source-diff): http-proxy minified bundle; standard dist output for this CLI. ai
source-diff obfuscated-file:dist/morph-Q32V442A.js AI (source-diff): TypeScript compiler bundle; long lines are expected minified output, not obfuscation. ai
source-diff net-exec-file:dist/morph-Q32V442A.js AI (source-diff): ts-morph/TypeScript compiler bundle; standard dist output for this CLI. ai
source-diff net-exec-file:dist/chunk-XVFYDYZA.js AI (source-diff): Minified bundle with semver and utility helpers; standard dist output. ai
source-diff net-exec-file:dist/chunk-MX6WWR5F.js AI (source-diff): Minified bundle with AJV code-generation; standard dist output. ai
source-diff net-exec-file:dist/chunk-5FCKEHCK.js AI (source-diff): Minified bundle with TOML parser and CLI framework code; standard dist output. ai
source-diff net-exec-file:dist/chunk-4VZV4LQX.js AI (source-diff): Minified bundle containing GraphQL/React internals; standard CLI dist output. ai
source-diff net-exec-file:dist/chunk-4QL77VYJ.js AI (source-diff): Minified bundle containing lodash/utility code; standard CLI dist output for this package. ai
phantom-deps phantom-dep:global-agent AI (phantom-deps): global-agent is referenced in config files as documented; stable false positive for this package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @shopify/cli is the official Shopify CLI; Levenshtein match to 'joi' is a false positive. ai
phantom-deps phantom-dep:esbuild AI (phantom-deps): esbuild is a known implicit runtime/binary dependency; stable for this package. ai

Versions (showing 15 of 15)

Version Deps Published
4.5.2 3 / 13
4.5.1 3 / 13
4.5.0 3 / 13
4.4.0 3 / 13
4.3.0 3 / 13
4.2.0 3 / 13
4.1.0 3 / 13
4.0.0 3 / 13
3.94.3 3 / 13
3.94.2 3 / 13
3.94.1 3 / 13
3.94.0 3 / 13
3.93.2 3 / 12
3.93.1 3 / 12
3.93.0 3 / 12

v4.5.2

3 findings
HIGH New file with network + code execution: dist/chunk-4MLEL3VK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/chunk-6VR22Z5R.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.1

3 findings
HIGH New file with network + code execution: dist/chunk-2HZMOK4U.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/chunk-4TC4M4RC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.0

5 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/toml_patch_bg.wasm • dist/yoga.wasm

HIGH New file with network + code execution: dist/chunk-3EQY5B4S.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/chunk-7BVXGS44.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/chunk-BU7R7NFL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.0

5 findings
HIGH New file with network + code execution: dist/chunk-47MGPVED.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/chunk-5W443CKL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/chunk-ATXODH6C.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/chunk-EKHWL542.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.