@shopify/cli-kit
A set of utilities, interfaces, and models that are common across all the platform features
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:commondir | AI (dependencies): [email protected] is a stable, widely-used utility with no known issues; safe for this package. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): graphql is a declared runtime dep used via graphql-request; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:is-executable | AI (phantom-deps): is-executable is a declared runtime dep; phantom-dep heuristic false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@types/archiver | AI (phantom-deps): @types/archiver is a declared dep used alongside archiver; framework-scoped type package, stable false positive. | ai | |
| dependencies | unvetted-dep:network-interfaces | AI (dependencies): Standard network utility; expected in a CLI toolkit. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Large Shopify monorepo package; empty toml entry point is a minimal re-export, README links are docs/community links, not phishing. | ai | |
| dependencies | unvetted-dep:node-abort-controller | AI (dependencies): Standard polyfill utility; expected in a CLI toolkit targeting Node 20+. | ai | |
| dependencies | unvetted-dep:@shopify/toml-patch | AI (dependencies): First-party Shopify dependency; consistent with this package's scope. | ai | |
| dependencies | unvetted-dep:color-json | AI (dependencies): Legitimate CLI utility dep; consistent with Shopify CLI toolkit usage. | ai | |
| dependencies | unvetted-dep:macaddress | AI (dependencies): Standard network utility; expected in a CLI toolkit for telemetry/device identification. | ai | |
| dependencies | unvetted-dep:is-executable | AI (dependencies): Standard filesystem utility; expected in a CLI toolkit. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 4.1.0 | 56 / 12 | |
| 4.0.0 | 56 / 12 | |
| 3.94.3 | 56 / 12 | |
| 3.93.1 | 62 / 13 | |
| 3.88.0 | 64 / 14 | |
| 3.87.4 | 64 / 14 | |
| 3.87.3 | 64 / 14 | |
| 3.87.2 | 64 / 14 | |
| 3.87.1 | 64 / 14 | |
| 3.87.0 | 64 / 14 | |
| 3.86.1 | 64 / 14 | |
| 3.86.0 | 64 / 14 | |
| 3.85.5 | 64 / 14 | |
| 3.85.4 | 64 / 14 | |
| 3.85.3 | 64 / 14 | |
| 3.85.2 | 64 / 14 | |
| 3.85.1 | 64 / 14 | |
| 3.85.0 | 64 / 14 | |
| 3.84.2 | 64 / 14 | |
| 3.84.1 | 64 / 14 | |
| 3.84.0 | 64 / 14 | |
| 3.83.3 | 64 / 14 | |
| 3.83.2 | 64 / 14 | |
| 3.83.1 | 64 / 14 | |
| 3.83.0 | 64 / 14 | |
| 3.82.1 | 64 / 14 | |
| 3.82.0 | 64 / 14 | |
| 3.81.2 | 64 / 14 | |
| 3.81.1 | 64 / 14 | |
| 3.81.0 | 64 / 14 | |
| 3.80.7 | 64 / 14 | |
| 3.80.6 | 64 / 14 | |
| 3.80.5 | 64 / 14 | |
| 3.80.4 | 64 / 14 | |
| 3.80.3 | 64 / 14 | |
| 3.80.2 | 64 / 14 | |
| 3.80.1 | 64 / 14 | |
| 3.80.0 | 64 / 14 | |
| 3.79.2 | 63 / 13 | |
| 3.79.1 | 63 / 13 | |
| 3.79.0 | 63 / 13 | |
| 3.78.2 | 62 / 13 |
v4.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.93.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.88.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.87.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.87.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.87.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.87.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.87.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.86.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.86.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.85.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.85.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.85.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.85.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.85.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.85.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.84.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.84.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.84.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.83.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.83.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.83.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.83.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.82.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.82.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.81.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.81.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.81.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.80.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.79.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.79.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.79.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.78.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.