← Home

@shopify/cli-kit

A set of utilities, interfaces, and models that are common across all the platform features

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jaimie.wayshopify-adminshopify-depmishsmellebuitammychris.craig

Keywords

shopifyshopify-clishopify-partners

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Change is to CI/CD GitHub Actions with SLSA attestation on official Shopify package; benign automation transition. ai
publish-pattern new-deps-added AI (publish-pattern): Added deps are small, well-known utilities (which, network-interfaces), not malicious. ai
maintainer-change maintainer-added AI (maintainer-change): Shopify's automated publishing account rotates maintainers routinely across monorepo packages. ai
maintainer-change maintainer-removed AI (maintainer-change): Same automated org rotation; no takeover behavior evidenced. ai
dependencies unvetted-dep:commondir AI (dependencies): [email protected] is a stable, widely-used utility with no known issues; safe for this package. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): graphql is a declared runtime dep used via graphql-request; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:is-executable AI (phantom-deps): is-executable is a declared runtime dep; phantom-dep heuristic false positive for this monorepo package. ai
phantom-deps phantom-dep:@types/archiver AI (phantom-deps): @types/archiver is a declared dep used alongside archiver; framework-scoped type package, stable false positive. ai
dependencies unvetted-dep:is-executable AI (dependencies): Standard filesystem utility; expected in a CLI toolkit. ai
dependencies unvetted-dep:macaddress AI (dependencies): Standard network utility; expected in a CLI toolkit for telemetry/device identification. ai
dependencies unvetted-dep:color-json AI (dependencies): Legitimate CLI utility dep; consistent with Shopify CLI toolkit usage. ai
dependencies unvetted-dep:network-interfaces AI (dependencies): Standard network utility; expected in a CLI toolkit. ai
dependencies unvetted-dep:@shopify/toml-patch AI (dependencies): First-party Shopify dependency; consistent with this package's scope. ai
dependencies unvetted-dep:node-abort-controller AI (dependencies): Standard polyfill utility; expected in a CLI toolkit targeting Node 20+. ai
bogus-package bogus-package AI (bogus-package): Large Shopify monorepo package; empty toml entry point is a minimal re-export, README links are docs/community links, not phishing. ai

Versions (showing 100 of 110)

Version Deps Published
4.5.2 60 / 13
4.5.1 60 / 13
4.5.0 60 / 13
4.4.0 60 / 13
4.3.0 60 / 13
4.2.0 60 / 13
4.1.0 56 / 12
4.0.0 56 / 12
3.94.3 56 / 12
3.94.2 56 / 12
3.94.1 56 / 12
3.94.0 56 / 12
3.93.2 62 / 13
3.93.1 62 / 13
3.93.0 62 / 13
3.92.1 64 / 14
3.92.0 64 / 14
3.91.1 64 / 14
3.91.0 64 / 14
3.90.1 64 / 14
3.90.0 64 / 14
3.89.0 64 / 14
3.88.1 64 / 14
3.88.0 64 / 14
3.87.4 64 / 14
3.87.3 64 / 14
3.87.2 64 / 14
3.87.1 64 / 14
3.87.0 64 / 14
3.86.1 64 / 14
3.86.0 64 / 14
3.85.5 64 / 14
3.85.4 64 / 14
3.85.3 64 / 14
3.85.2 64 / 14
3.85.1 64 / 14
3.85.0 64 / 14
3.84.2 64 / 14
3.84.1 64 / 14
3.84.0 64 / 14
3.83.3 64 / 14
3.83.2 64 / 14
3.83.1 64 / 14
3.83.0 64 / 14
3.82.1 64 / 14
3.82.0 64 / 14
3.81.2 64 / 14
3.81.1 64 / 14
3.81.0 64 / 14
3.80.7 64 / 14
3.80.6 64 / 14
3.80.5 64 / 14
3.80.4 64 / 14
3.80.3 64 / 14
3.80.2 64 / 14
3.80.1 64 / 14
3.80.0 64 / 14
3.79.2 63 / 13
3.79.1 63 / 13
3.79.0 63 / 13
3.78.2 62 / 13
3.78.1 62 / 13
3.75.3 61 / 12
3.75.1 61 / 12
3.74.0 60 / 12
3.73.2 60 / 14
3.73.1 60 / 14
3.73.0 60 / 14
3.72.2 60 / 14
3.72.1 60 / 14
3.72.0 60 / 14
3.71.5 60 / 14
3.71.4 60 / 14
3.71.3 60 / 14
3.71.2 60 / 14
3.71.1 60 / 14
3.71.0 60 / 14
3.70.0 58 / 13
3.69.4 58 / 13
3.69.3 58 / 13
3.69.2 58 / 13
3.69.1 58 / 13
3.69.0 58 / 13
3.68.1 60 / 13
3.68.0 60 / 13
3.67.3 60 / 13
3.67.2 60 / 13
3.67.1 61 / 14
3.67.0 61 / 14
3.66.1 59 / 13
3.66.0 59 / 13
3.65.3 59 / 14
3.65.2 59 / 14
3.65.1 59 / 14
3.65.0 59 / 14
3.64.1 59 / 14
3.64.0 59 / 14
3.63.2 59 / 14
3.63.1 59 / 14
3.63.0 59 / 14
Showing 100 of 110 Next page →

v4.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.94.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.94.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.94.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.93.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.78.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.75.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.75.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.74.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.73.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.73.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.73.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.72.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.72.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.72.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.71.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.71.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.71.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.71.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.71.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.71.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.70.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.69.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.69.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.69.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.69.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.69.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.68.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.68.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.67.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.67.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.67.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.67.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.66.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.66.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.65.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.65.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.65.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.65.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.64.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.64.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.63.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.63.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.63.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.