← Home

@tramvai/cli

Cli инструмент для сборки и запуска приложений

30
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

super_olegmeskilltinkoffbank

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:validate-npm-package-name AI (phantom-deps): Used by scaffolding/plop generators dynamically. ai
phantom-deps phantom-dep:lightningcss-loader AI (phantom-deps): Webpack loader referenced by generated config. ai
phantom-deps phantom-dep:postcss-loader AI (phantom-deps): Webpack loader referenced by generated config, not static import. ai
phantom-deps phantom-dep:@svgr/webpack AI (phantom-deps): Webpack loader referenced by generated config, not static import. ai
phantom-deps phantom-dep:null-loader AI (phantom-deps): Webpack loader referenced by generated config, not static import. ai
phantom-deps phantom-dep:less-loader AI (phantom-deps): Webpack loader referenced by generated config, not static import. ai
phantom-deps phantom-dep:port-used AI (phantom-deps): Used dynamically by dev-server port detection; consistent bundler-CLI pattern. ai
phantom-deps phantom-dep:css-class-generator AI (phantom-deps): Used by CSS build pipeline config. ai
phantom-deps phantom-dep:source-map-loader AI (phantom-deps): Webpack loader referenced by generated config, not static import. ai
phantom-deps phantom-dep:webpack-sources AI (phantom-deps): Used by internal webpack plugins dynamically. ai
phantom-deps phantom-dep:path-browserify AI (phantom-deps): Webpack polyfill resolved by config, not static import. ai
phantom-deps phantom-dep:@babel/cli AI (phantom-deps): Framework-scoped babel toolchain dep, stable false positive. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Implicit runtime dep, common pattern. ai
dependencies unvetted-dep:svgo AI (dependencies): Standard webpack asset tooling dep. ai
dependencies unvetted-dep:@rsdoctor/webpack-plugin AI (dependencies): Known webpack analysis plugin. ai
dependencies unvetted-dep:@tinkoff/request-plugin-protocol-http AI (dependencies): Tinkoff ecosystem dep, related maintainers. ai
dependencies unvetted-dep:svgo-loader AI (dependencies): Webpack asset loader, benign. ai
dependencies unvetted-dep:handlebars AI (dependencies): Standard templating dep used in CLI scaffolding. ai
dependencies unvetted-dep:http-proxy AI (dependencies): Standard dev-server proxying dep. ai
dependencies unvetted-dep:@tramvai/tools-migrate AI (dependencies): First-party tramvai tooling. ai
source-diff large-new-source-files AI (source-diff): Large diff is bundled build-tool source, not injected code. ai
phantom-deps phantom-dep:table AI (phantom-deps): Config-only usage typical of CLI tooling. ai
publish-pattern new-deps-added AI (publish-pattern): nanoid/@tramvai/papi are legitimate build-tool deps, not stealth crypto-style additions. ai
dependencies unvetted-dep:@tramvai/api AI (dependencies): First-party sibling package in same monorepo/org. ai
phantom-deps phantom-dep:babel-loader AI (phantom-deps): Webpack loader referenced in config; expected for a CLI build tool. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Webpack loader referenced in config; expected for a CLI build tool. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Same as above — config-referenced loader, not a direct import. ai
phantom-deps phantom-dep:less AI (phantom-deps): Build tool; webpack loader deps referenced in config files, not direct imports — stable pattern. ai
phantom-deps phantom-dep:@tramvai/plugin-webpack-builder AI (phantom-deps): Same org scope; loaded by convention in tramvai ecosystem. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Framework-scoped babel dep loaded by convention; stable for this package. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped babel dep loaded by convention; stable for this package. ai
semgrep semgrep:eval-usage AI (semgrep): eval() is in an integration test evaluating browser feature flag expressions — not production code, not a supply-chain risk. ai
semgrep semgrep:child-process-import AI (semgrep): CLI tool that spawns build processes; child_process use is expected and documented. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package @tramvai/cli is not a typosquat of joi; edit-distance match is spurious. ai
semgrep semgrep:dynamic-require AI (semgrep): Worker warmup module loader pattern; expected in a webpack dev-server worker pool. ai
semgrep semgrep:env-spread AI (semgrep): Build CLI tool intentionally passes process.env to spawned webpack processes; expected pattern. ai

Versions (showing 30 of 30)

Version Deps Published
7.31.1 145 / 20
7.27.9 145 / 20
7.26.9 145 / 20
7.26.8 145 / 20
7.21.1 144 / 20
7.21.0 144 / 20
7.18.0 144 / 20
7.16.0 144 / 20
7.4.4 146 / 20
6.82.12 143 / 20
6.82.8 143 / 20
6.81.11 143 / 20
6.80.25 143 / 20
6.80.23 143 / 20
6.80.20 143 / 20
6.80.19 143 / 20
6.80.8 143 / 20
6.80.7 143 / 20
6.80.6 143 / 20
6.79.9 145 / 20
6.78.0 146 / 20
5.53.168 147 / 22
5.53.163 147 / 22
5.53.159 147 / 22
5.53.156 147 / 22
5.53.155 147 / 22
5.53.146 147 / 22
5.53.143 147 / 22
5.53.140 147 / 22
5.53.118 146 / 22

v7.31.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.27.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.26.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.82.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.82.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.53.168

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.53.163

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.53.159

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.