@tarojs/cli
3
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
yuchexuanzebindefaultleedrchankyjoqq592743779advancedcatbaosiqingzakaryliuzejiavasily.cjjhardenzheng2
Keywords
taroweapp
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:npm-check | AI (phantom-deps): Config-referenced usage. | ai | |
| phantom-deps | phantom-dep:glob | AI (phantom-deps): Config-file usage, not a direct import gap. | ai | |
| phantom-deps | phantom-dep:eslint | AI (phantom-deps): Used via config, standard devtool dep. | ai | |
| phantom-deps | phantom-dep:xml2js | AI (phantom-deps): Config-referenced usage. | ai | |
| phantom-deps | phantom-dep:request | AI (phantom-deps): Config-referenced usage. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Deps are standard CLI tooling and first-party siblings tied to v4 restructure. | ai | |
| dependencies | unvetted-dep:@tarojs/plugin-doctor | AI (dependencies): First-party @tarojs sibling package, same monorepo/publisher. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @tarojs/cli is the official Taro CLI; no resemblance to 'joi' in intent or namespace. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require appears in test files (update.spec.ts) and CLI plugin-loading patterns; expected for this scaffolding tool. | ai | |
| phantom-deps | phantom-dep:ejs | AI (phantom-deps): Template rendering dependency; used indirectly via scaffolding templates, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:babylon | AI (phantom-deps): AST tooling dependency used transitively; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:tapable | AI (phantom-deps): Plugin system dependency used transitively via webpack/service layer; stable false positive. | ai | |
| phantom-deps | phantom-dep:resolve | AI (phantom-deps): Module resolution utility used transitively; stable false positive for this CLI package. | ai | |
| phantom-deps | phantom-dep:regenerator-runtime | AI (phantom-deps): Known implicit runtime dependency for async/generator transpilation; stable false positive. | ai |
v4.0.5
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.