@shopify/cli-kit
A set of utilities, interfaces, and models that are common across all the platform features
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Change is to CI/CD GitHub Actions with SLSA attestation on official Shopify package; benign automation transition. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Added deps are small, well-known utilities (which, network-interfaces), not malicious. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Shopify's automated publishing account rotates maintainers routinely across monorepo packages. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same automated org rotation; no takeover behavior evidenced. | ai | |
| dependencies | unvetted-dep:commondir | AI (dependencies): [email protected] is a stable, widely-used utility with no known issues; safe for this package. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): graphql is a declared runtime dep used via graphql-request; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:is-executable | AI (phantom-deps): is-executable is a declared runtime dep; phantom-dep heuristic false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@types/archiver | AI (phantom-deps): @types/archiver is a declared dep used alongside archiver; framework-scoped type package, stable false positive. | ai | |
| dependencies | unvetted-dep:is-executable | AI (dependencies): Standard filesystem utility; expected in a CLI toolkit. | ai | |
| dependencies | unvetted-dep:macaddress | AI (dependencies): Standard network utility; expected in a CLI toolkit for telemetry/device identification. | ai | |
| dependencies | unvetted-dep:color-json | AI (dependencies): Legitimate CLI utility dep; consistent with Shopify CLI toolkit usage. | ai | |
| dependencies | unvetted-dep:network-interfaces | AI (dependencies): Standard network utility; expected in a CLI toolkit. | ai | |
| dependencies | unvetted-dep:@shopify/toml-patch | AI (dependencies): First-party Shopify dependency; consistent with this package's scope. | ai | |
| dependencies | unvetted-dep:node-abort-controller | AI (dependencies): Standard polyfill utility; expected in a CLI toolkit targeting Node 20+. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Large Shopify monorepo package; empty toml entry point is a minimal re-export, README links are docs/community links, not phishing. | ai |
Versions (showing 100 of 110)
| Version | Deps | Published |
|---|---|---|
| 4.5.2 | 60 / 13 | |
| 4.5.1 | 60 / 13 | |
| 4.5.0 | 60 / 13 | |
| 4.4.0 | 60 / 13 | |
| 4.3.0 | 60 / 13 | |
| 4.2.0 | 60 / 13 | |
| 4.1.0 | 56 / 12 | |
| 4.0.0 | 56 / 12 | |
| 3.94.3 | 56 / 12 | |
| 3.94.2 | 56 / 12 | |
| 3.94.1 | 56 / 12 | |
| 3.94.0 | 56 / 12 | |
| 3.93.2 | 62 / 13 | |
| 3.93.1 | 62 / 13 | |
| 3.93.0 | 62 / 13 | |
| 3.92.1 | 64 / 14 | |
| 3.92.0 | 64 / 14 | |
| 3.91.1 | 64 / 14 | |
| 3.91.0 | 64 / 14 | |
| 3.90.1 | 64 / 14 | |
| 3.90.0 | 64 / 14 | |
| 3.89.0 | 64 / 14 | |
| 3.88.1 | 64 / 14 | |
| 3.88.0 | 64 / 14 | |
| 3.87.4 | 64 / 14 | |
| 3.87.3 | 64 / 14 | |
| 3.87.2 | 64 / 14 | |
| 3.87.1 | 64 / 14 | |
| 3.87.0 | 64 / 14 | |
| 3.86.1 | 64 / 14 | |
| 3.86.0 | 64 / 14 | |
| 3.85.5 | 64 / 14 | |
| 3.85.4 | 64 / 14 | |
| 3.85.3 | 64 / 14 | |
| 3.85.2 | 64 / 14 | |
| 3.85.1 | 64 / 14 | |
| 3.85.0 | 64 / 14 | |
| 3.84.2 | 64 / 14 | |
| 3.84.1 | 64 / 14 | |
| 3.84.0 | 64 / 14 | |
| 3.83.3 | 64 / 14 | |
| 3.83.2 | 64 / 14 | |
| 3.83.1 | 64 / 14 | |
| 3.83.0 | 64 / 14 | |
| 3.82.1 | 64 / 14 | |
| 3.82.0 | 64 / 14 | |
| 3.81.2 | 64 / 14 | |
| 3.81.1 | 64 / 14 | |
| 3.81.0 | 64 / 14 | |
| 3.80.7 | 64 / 14 | |
| 3.80.6 | 64 / 14 | |
| 3.80.5 | 64 / 14 | |
| 3.80.4 | 64 / 14 | |
| 3.80.3 | 64 / 14 | |
| 3.80.2 | 64 / 14 | |
| 3.80.1 | 64 / 14 | |
| 3.80.0 | 64 / 14 | |
| 3.79.2 | 63 / 13 | |
| 3.79.1 | 63 / 13 | |
| 3.79.0 | 63 / 13 | |
| 3.78.2 | 62 / 13 | |
| 3.78.1 | 62 / 13 | |
| 3.75.3 | 61 / 12 | |
| 3.75.1 | 61 / 12 | |
| 3.74.0 | 60 / 12 | |
| 3.73.2 | 60 / 14 | |
| 3.73.1 | 60 / 14 | |
| 3.73.0 | 60 / 14 | |
| 3.72.2 | 60 / 14 | |
| 3.72.1 | 60 / 14 | |
| 3.72.0 | 60 / 14 | |
| 3.71.5 | 60 / 14 | |
| 3.71.4 | 60 / 14 | |
| 3.71.3 | 60 / 14 | |
| 3.71.2 | 60 / 14 | |
| 3.71.1 | 60 / 14 | |
| 3.71.0 | 60 / 14 | |
| 3.70.0 | 58 / 13 | |
| 3.69.4 | 58 / 13 | |
| 3.69.3 | 58 / 13 | |
| 3.69.2 | 58 / 13 | |
| 3.69.1 | 58 / 13 | |
| 3.69.0 | 58 / 13 | |
| 3.68.1 | 60 / 13 | |
| 3.68.0 | 60 / 13 | |
| 3.67.3 | 60 / 13 | |
| 3.67.2 | 60 / 13 | |
| 3.67.1 | 61 / 14 | |
| 3.67.0 | 61 / 14 | |
| 3.66.1 | 59 / 13 | |
| 3.66.0 | 59 / 13 | |
| 3.65.3 | 59 / 14 | |
| 3.65.2 | 59 / 14 | |
| 3.65.1 | 59 / 14 | |
| 3.65.0 | 59 / 14 | |
| 3.64.1 | 59 / 14 | |
| 3.64.0 | 59 / 14 | |
| 3.63.2 | 59 / 14 | |
| 3.63.1 | 59 / 14 | |
| 3.63.0 | 59 / 14 |
v4.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.94.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.94.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.94.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.93.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.78.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.75.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.75.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.74.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.73.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.73.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.73.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.72.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.72.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.72.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.71.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.70.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.69.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.69.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.69.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.69.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.69.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.68.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.68.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.67.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.67.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.67.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.67.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.66.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.66.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.65.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.65.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.65.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.65.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.64.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.64.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.63.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.63.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.63.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.