@shopify/plugin-cloudflare
Enables the creation of Cloudflare tunnels from `shopify app dev`, allowing previews from any device
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Shopify migrated to GitHub Actions CI publishing; SLSA attestation confirms legitimate pipeline. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy explained by CI/CD migration; SLSA provenance and official Shopify repo confirm legitimacy. | ai | |
| phantom-deps | phantom-dep:@oclif/core | AI (phantom-deps): @oclif/core is a declared runtime dep used in oclif manifest/config, not a phantom dep. | ai |
Versions (showing 100 of 121)
| Version | Deps | Published |
|---|---|---|
| 4.5.2 | 2 / 1 | |
| 4.5.1 | 2 / 1 | |
| 4.5.0 | 2 / 1 | |
| 4.4.0 | 2 / 1 | |
| 4.3.0 | 2 / 1 | |
| 4.2.0 | 2 / 1 | |
| 4.1.0 | 2 / 1 | |
| 4.0.0 | 2 / 1 | |
| 3.94.3 | 2 / 1 | |
| 3.94.2 | 2 / 1 | |
| 3.94.1 | 2 / 1 | |
| 3.94.0 | 2 / 1 | |
| 3.93.2 | 2 / 1 | |
| 3.93.1 | 2 / 1 | |
| 3.93.0 | 2 / 1 | |
| 3.92.1 | 2 / 1 | |
| 3.92.0 | 2 / 1 | |
| 3.91.1 | 2 / 1 | |
| 3.91.0 | 2 / 1 | |
| 3.90.1 | 2 / 1 | |
| 3.90.0 | 2 / 1 | |
| 3.89.0 | 2 / 1 | |
| 3.88.1 | 2 / 1 | |
| 3.88.0 | 2 / 1 | |
| 3.87.4 | 2 / 1 | |
| 3.87.3 | 2 / 1 | |
| 3.87.2 | 2 / 1 | |
| 3.87.1 | 2 / 1 | |
| 3.87.0 | 2 / 1 | |
| 3.86.1 | 2 / 1 | |
| 3.86.0 | 2 / 1 | |
| 3.85.5 | 2 / 1 | |
| 3.85.4 | 2 / 1 | |
| 3.85.3 | 2 / 1 | |
| 3.85.2 | 2 / 1 | |
| 3.85.1 | 2 / 1 | |
| 3.85.0 | 2 / 1 | |
| 3.84.2 | 2 / 1 | |
| 3.84.1 | 2 / 1 | |
| 3.84.0 | 2 / 1 | |
| 3.83.3 | 2 / 1 | |
| 3.83.2 | 2 / 1 | |
| 3.83.1 | 2 / 1 | |
| 3.83.0 | 2 / 1 | |
| 3.82.1 | 2 / 1 | |
| 3.82.0 | 2 / 1 | |
| 3.81.2 | 2 / 1 | |
| 3.81.1 | 2 / 1 | |
| 3.81.0 | 2 / 1 | |
| 3.80.7 | 2 / 1 | |
| 3.80.6 | 2 / 1 | |
| 3.80.5 | 2 / 1 | |
| 3.80.4 | 2 / 1 | |
| 3.80.3 | 2 / 1 | |
| 3.80.2 | 2 / 1 | |
| 3.80.1 | 2 / 1 | |
| 3.80.0 | 2 / 1 | |
| 3.79.2 | 2 / 1 | |
| 3.79.1 | 2 / 1 | |
| 3.79.0 | 2 / 1 | |
| 3.78.2 | 2 / 1 | |
| 3.78.1 | 2 / 1 | |
| 3.78.0 | 2 / 1 | |
| 3.77.1 | 2 / 1 | |
| 3.77.0 | 2 / 1 | |
| 3.76.2 | 2 / 1 | |
| 3.76.1 | 2 / 1 | |
| 3.76.0 | 2 / 1 | |
| 3.75.4 | 2 / 1 | |
| 3.75.3 | 2 / 1 | |
| 3.75.2 | 2 / 1 | |
| 3.75.1 | 2 / 1 | |
| 3.75.0 | 2 / 1 | |
| 3.74.1 | 2 / 1 | |
| 3.74.0 | 2 / 1 | |
| 3.73.2 | 2 / 1 | |
| 3.73.1 | 2 / 1 | |
| 3.73.0 | 2 / 1 | |
| 3.72.2 | 2 / 1 | |
| 3.72.1 | 2 / 1 | |
| 3.72.0 | 2 / 1 | |
| 3.71.5 | 2 / 1 | |
| 3.71.4 | 2 / 1 | |
| 3.71.3 | 2 / 1 | |
| 3.71.2 | 2 / 1 | |
| 3.71.1 | 2 / 1 | |
| 3.71.0 | 2 / 1 | |
| 3.70.0 | 2 / 1 | |
| 3.69.4 | 2 / 1 | |
| 3.69.3 | 2 / 1 | |
| 3.69.2 | 2 / 1 | |
| 3.69.1 | 2 / 1 | |
| 3.69.0 | 2 / 1 | |
| 3.68.1 | 2 / 1 | |
| 3.68.0 | 2 / 1 | |
| 3.67.3 | 2 / 1 | |
| 3.67.2 | 2 / 1 | |
| 3.67.1 | 2 / 1 | |
| 3.67.0 | 2 / 1 | |
| 3.66.1 | 2 / 1 |
v4.5.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.78.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.78.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.77.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.77.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.76.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.76.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.76.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.75.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.75.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.75.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.75.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.75.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.74.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.74.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.73.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.73.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.73.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.72.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.72.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.72.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.71.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.71.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.71.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.71.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.71.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.71.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.70.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.69.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.69.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.69.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.69.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.69.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.68.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.68.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.67.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.67.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.67.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.67.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.66.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.