← Home

@shopify/cli-kit

A set of utilities, interfaces, and models that are common across all the platform features

11
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jaimie.wayshopify-adminshopify-depmishsmellebuitammychris.craig

Keywords

shopifyshopify-clishopify-partners

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:term-size AI (phantom-deps): Legit utility dep, likely used in bundled dist not scanned as source. ai
phantom-deps phantom-dep:find-versions AI (phantom-deps): Legit utility dep, likely used in bundled dist not scanned as source. ai
dependencies unvetted-dep:haikunator AI (dependencies): Common name-generator lib, benign for CLI tooling. ai
provenance publisher-changed AI (provenance): Change is to CI/CD GitHub Actions with SLSA attestation on official Shopify package; benign automation transition. ai
publish-pattern new-deps-added AI (publish-pattern): Added deps are small, well-known utilities (which, network-interfaces), not malicious. ai
maintainer-change maintainer-removed AI (maintainer-change): Same automated org rotation; no takeover behavior evidenced. ai
maintainer-change maintainer-added AI (maintainer-change): Shopify's automated publishing account rotates maintainers routinely across monorepo packages. ai
phantom-deps phantom-dep:is-executable AI (phantom-deps): is-executable is a declared runtime dep; phantom-dep heuristic false positive for this monorepo package. ai
dependencies unvetted-dep:commondir AI (dependencies): [email protected] is a stable, widely-used utility with no known issues; safe for this package. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): graphql is a declared runtime dep used via graphql-request; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@types/archiver AI (phantom-deps): @types/archiver is a declared dep used alongside archiver; framework-scoped type package, stable false positive. ai
bogus-package bogus-package AI (bogus-package): Large Shopify monorepo package; empty toml entry point is a minimal re-export, README links are docs/community links, not phishing. ai
dependencies unvetted-dep:node-abort-controller AI (dependencies): Standard polyfill utility; expected in a CLI toolkit targeting Node 20+. ai
dependencies unvetted-dep:@shopify/toml-patch AI (dependencies): First-party Shopify dependency; consistent with this package's scope. ai
dependencies unvetted-dep:network-interfaces AI (dependencies): Standard network utility; expected in a CLI toolkit. ai
dependencies unvetted-dep:is-executable AI (dependencies): Standard filesystem utility; expected in a CLI toolkit. ai
dependencies unvetted-dep:macaddress AI (dependencies): Standard network utility; expected in a CLI toolkit for telemetry/device identification. ai
dependencies unvetted-dep:color-json AI (dependencies): Legitimate CLI utility dep; consistent with Shopify CLI toolkit usage. ai

Versions (showing 11 of 111)

Version Deps Published
3.62.0 58 / 14
3.61.2 56 / 14
3.61.1 56 / 14
3.61.0 56 / 14
3.60.1 56 / 14
3.60.0 56 / 14
3.59.3 56 / 14
3.59.2 56 / 14
3.59.1 56 / 14
3.59.0 56 / 14
3.0.25 43 / 7

v3.62.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.61.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.61.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.61.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.60.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.60.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.59.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.59.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.59.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.59.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.