@shopify/cli-kit
A set of utilities, interfaces, and models that are common across all the platform features
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:term-size | AI (phantom-deps): Legit utility dep, likely used in bundled dist not scanned as source. | ai | |
| phantom-deps | phantom-dep:find-versions | AI (phantom-deps): Legit utility dep, likely used in bundled dist not scanned as source. | ai | |
| dependencies | unvetted-dep:haikunator | AI (dependencies): Common name-generator lib, benign for CLI tooling. | ai | |
| provenance | publisher-changed | AI (provenance): Change is to CI/CD GitHub Actions with SLSA attestation on official Shopify package; benign automation transition. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Added deps are small, well-known utilities (which, network-interfaces), not malicious. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Same automated org rotation; no takeover behavior evidenced. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Shopify's automated publishing account rotates maintainers routinely across monorepo packages. | ai | |
| phantom-deps | phantom-dep:is-executable | AI (phantom-deps): is-executable is a declared runtime dep; phantom-dep heuristic false positive for this monorepo package. | ai | |
| dependencies | unvetted-dep:commondir | AI (dependencies): [email protected] is a stable, widely-used utility with no known issues; safe for this package. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): graphql is a declared runtime dep used via graphql-request; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@types/archiver | AI (phantom-deps): @types/archiver is a declared dep used alongside archiver; framework-scoped type package, stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Large Shopify monorepo package; empty toml entry point is a minimal re-export, README links are docs/community links, not phishing. | ai | |
| dependencies | unvetted-dep:node-abort-controller | AI (dependencies): Standard polyfill utility; expected in a CLI toolkit targeting Node 20+. | ai | |
| dependencies | unvetted-dep:@shopify/toml-patch | AI (dependencies): First-party Shopify dependency; consistent with this package's scope. | ai | |
| dependencies | unvetted-dep:network-interfaces | AI (dependencies): Standard network utility; expected in a CLI toolkit. | ai | |
| dependencies | unvetted-dep:is-executable | AI (dependencies): Standard filesystem utility; expected in a CLI toolkit. | ai | |
| dependencies | unvetted-dep:macaddress | AI (dependencies): Standard network utility; expected in a CLI toolkit for telemetry/device identification. | ai | |
| dependencies | unvetted-dep:color-json | AI (dependencies): Legitimate CLI utility dep; consistent with Shopify CLI toolkit usage. | ai |
Versions (showing 11 of 111)
| Version | Deps | Published |
|---|---|---|
| 3.62.0 | 58 / 14 | |
| 3.61.2 | 56 / 14 | |
| 3.61.1 | 56 / 14 | |
| 3.61.0 | 56 / 14 | |
| 3.60.1 | 56 / 14 | |
| 3.60.0 | 56 / 14 | |
| 3.59.3 | 56 / 14 | |
| 3.59.2 | 56 / 14 | |
| 3.59.1 | 56 / 14 | |
| 3.59.0 | 56 / 14 | |
| 3.0.25 | 43 / 7 |
v3.62.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.61.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.61.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.61.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.60.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.60.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.59.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.59.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.59.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.59.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.