@tramvai/cli
Cli инструмент для сборки и запуска приложений
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:validate-npm-package-name | AI (phantom-deps): Used by scaffolding/plop generators dynamically. | ai | |
| phantom-deps | phantom-dep:lightningcss-loader | AI (phantom-deps): Webpack loader referenced by generated config. | ai | |
| phantom-deps | phantom-dep:postcss-loader | AI (phantom-deps): Webpack loader referenced by generated config, not static import. | ai | |
| phantom-deps | phantom-dep:@svgr/webpack | AI (phantom-deps): Webpack loader referenced by generated config, not static import. | ai | |
| phantom-deps | phantom-dep:null-loader | AI (phantom-deps): Webpack loader referenced by generated config, not static import. | ai | |
| phantom-deps | phantom-dep:less-loader | AI (phantom-deps): Webpack loader referenced by generated config, not static import. | ai | |
| phantom-deps | phantom-dep:port-used | AI (phantom-deps): Used dynamically by dev-server port detection; consistent bundler-CLI pattern. | ai | |
| phantom-deps | phantom-dep:css-class-generator | AI (phantom-deps): Used by CSS build pipeline config. | ai | |
| phantom-deps | phantom-dep:source-map-loader | AI (phantom-deps): Webpack loader referenced by generated config, not static import. | ai | |
| phantom-deps | phantom-dep:webpack-sources | AI (phantom-deps): Used by internal webpack plugins dynamically. | ai | |
| phantom-deps | phantom-dep:path-browserify | AI (phantom-deps): Webpack polyfill resolved by config, not static import. | ai | |
| phantom-deps | phantom-dep:@babel/cli | AI (phantom-deps): Framework-scoped babel toolchain dep, stable false positive. | ai | |
| phantom-deps | phantom-dep:core-js | AI (phantom-deps): Implicit runtime dep, common pattern. | ai | |
| dependencies | unvetted-dep:svgo | AI (dependencies): Standard webpack asset tooling dep. | ai | |
| dependencies | unvetted-dep:@rsdoctor/webpack-plugin | AI (dependencies): Known webpack analysis plugin. | ai | |
| dependencies | unvetted-dep:@tinkoff/request-plugin-protocol-http | AI (dependencies): Tinkoff ecosystem dep, related maintainers. | ai | |
| dependencies | unvetted-dep:svgo-loader | AI (dependencies): Webpack asset loader, benign. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Standard templating dep used in CLI scaffolding. | ai | |
| dependencies | unvetted-dep:http-proxy | AI (dependencies): Standard dev-server proxying dep. | ai | |
| dependencies | unvetted-dep:@tramvai/tools-migrate | AI (dependencies): First-party tramvai tooling. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large diff is bundled build-tool source, not injected code. | ai | |
| phantom-deps | phantom-dep:table | AI (phantom-deps): Config-only usage typical of CLI tooling. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): nanoid/@tramvai/papi are legitimate build-tool deps, not stealth crypto-style additions. | ai | |
| dependencies | unvetted-dep:@tramvai/api | AI (dependencies): First-party sibling package in same monorepo/org. | ai | |
| phantom-deps | phantom-dep:babel-loader | AI (phantom-deps): Webpack loader referenced in config; expected for a CLI build tool. | ai | |
| phantom-deps | phantom-dep:css-loader | AI (phantom-deps): Webpack loader referenced in config; expected for a CLI build tool. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Same as above — config-referenced loader, not a direct import. | ai | |
| phantom-deps | phantom-dep:less | AI (phantom-deps): Build tool; webpack loader deps referenced in config files, not direct imports — stable pattern. | ai | |
| phantom-deps | phantom-dep:@tramvai/plugin-webpack-builder | AI (phantom-deps): Same org scope; loaded by convention in tramvai ecosystem. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): Framework-scoped babel dep loaded by convention; stable for this package. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped babel dep loaded by convention; stable for this package. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() is in an integration test evaluating browser feature flag expressions — not production code, not a supply-chain risk. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI tool that spawns build processes; child_process use is expected and documented. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package @tramvai/cli is not a typosquat of joi; edit-distance match is spurious. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Worker warmup module loader pattern; expected in a webpack dev-server worker pool. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Build CLI tool intentionally passes process.env to spawned webpack processes; expected pattern. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 7.31.1 | 145 / 20 | |
| 7.27.9 | 145 / 20 | |
| 7.26.9 | 145 / 20 | |
| 7.26.8 | 145 / 20 | |
| 7.21.1 | 144 / 20 | |
| 7.21.0 | 144 / 20 | |
| 7.18.0 | 144 / 20 | |
| 7.16.0 | 144 / 20 | |
| 7.4.4 | 146 / 20 | |
| 6.82.12 | 143 / 20 | |
| 6.82.8 | 143 / 20 | |
| 6.81.11 | 143 / 20 | |
| 6.80.25 | 143 / 20 | |
| 6.80.23 | 143 / 20 | |
| 6.80.20 | 143 / 20 | |
| 6.80.19 | 143 / 20 | |
| 6.80.8 | 143 / 20 | |
| 6.80.7 | 143 / 20 | |
| 6.80.6 | 143 / 20 | |
| 6.79.9 | 145 / 20 | |
| 6.78.0 | 146 / 20 | |
| 5.53.168 | 147 / 22 | |
| 5.53.163 | 147 / 22 | |
| 5.53.159 | 147 / 22 | |
| 5.53.156 | 147 / 22 | |
| 5.53.155 | 147 / 22 | |
| 5.53.146 | 147 / 22 | |
| 5.53.143 | 147 / 22 | |
| 5.53.140 | 147 / 22 | |
| 5.53.118 | 146 / 22 |
v7.31.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.27.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.26.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.82.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.82.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.53.168
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.53.163
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.53.159
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.