← Home

@tauri-apps/cli

Command line interface for building Tauri apps

43
Versions
Apache-2.0 OR MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

nothingismagicklucasfernogtauri-apps-ci-userjboldafabianlarsamrbashirbeanow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Tauri migrated to GitHub Actions CI publishing with SLSA attestation; this is the expected publisher going forward. ai
publish-pattern dormant-publish AI (publish-pattern): Active package with 167 versions; dormancy flag is a false positive for this established project. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @tauri-apps/cli is the official Tauri CLI; no relation to joi. ai
semgrep semgrep:child-process-import AI (semgrep): Used solely for musl detection via ldd --version; stable pattern for this native CLI package. ai
semgrep semgrep:child-process-execsync AI (semgrep): execSync('ldd --version') is a benign OS detection call; stable for this package. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads napi-rs native binary from NAPI_RS_NATIVE_LIBRARY_PATH env var; standard napi-rs pattern. ai

Versions (showing 43 of 43)

Version Deps Published
2.11.4 0 / 4
2.11.3 0 / 4
2.11.2 0 / 4
2.11.1 0 / 4
2.11.0 0 / 4
2.10.1 0 / 4
2.10.0 0 / 4
2.9.6 0 / 4
2.9.5 0 / 4
2.9.4 0 / 4
2.9.3 0 / 4
2.9.2 0 / 4
2.9.1 0 / 4
2.9.0 0 / 4
2.8.4 0 / 4
2.8.3 0 / 4
2.8.2 0 / 4
2.8.1 0 / 4
2.8.0 0 / 4
2.7.1 0 / 4
2.7.0 0 / 4
2.6.2 0 / 4
2.6.1 0 / 4
2.6.0 0 / 4
2.5.0 0 / 4
2.4.1 0 / 4
2.4.0 0 / 4
2.3.1 0 / 4
2.3.0 0 / 4
2.2.7 0 / 4
2.2.6 0 / 4
2.2.5 0 / 4
2.2.4 0 / 4
2.2.3 0 / 4
2.2.2 0 / 4
2.2.1 0 / 4
2.2.0 0 / 4
2.1.0 0 / 4
2.0.4 0 / 4
2.0.3 0 / 4
2.0.2 0 / 4
2.0.1 0 / 4
2.0.0 0 / 4

v2.11.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.