← Home

@tramvai/cli

Cli инструмент для сборки и запуска приложений

15
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

super_olegmeskilltinkoffbank

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@tramvai/plugin-webpack-builder AI (phantom-deps): Same org scope; loaded by convention in tramvai ecosystem. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Same as above — config-referenced loader, not a direct import. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Webpack loader referenced in config; expected for a CLI build tool. ai
phantom-deps phantom-dep:babel-loader AI (phantom-deps): Webpack loader referenced in config; expected for a CLI build tool. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped babel dep loaded by convention; stable for this package. ai
phantom-deps phantom-dep:@babel/preset-env AI (phantom-deps): Framework-scoped babel dep loaded by convention; stable for this package. ai
phantom-deps phantom-dep:less AI (phantom-deps): Build tool; webpack loader deps referenced in config files, not direct imports — stable pattern. ai
semgrep semgrep:eval-usage AI (semgrep): eval() is in an integration test evaluating browser feature flag expressions — not production code, not a supply-chain risk. ai
semgrep semgrep:child-process-import AI (semgrep): CLI tool that spawns build processes; child_process use is expected and documented. ai
semgrep semgrep:dynamic-require AI (semgrep): Worker warmup module loader pattern; expected in a webpack dev-server worker pool. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package @tramvai/cli is not a typosquat of joi; edit-distance match is spurious. ai
semgrep semgrep:env-spread AI (semgrep): Build CLI tool intentionally passes process.env to spawned webpack processes; expected pattern. ai

Versions (showing 15 of 15)

Version Deps Published
7.21.1 144 / 20
7.21.0 144 / 20
7.18.0 144 / 20
7.16.0 144 / 20
6.80.25 143 / 20
6.80.23 143 / 20
6.80.20 143 / 20
6.80.19 143 / 20
6.80.8 143 / 20
6.80.7 143 / 20
6.80.6 143 / 20
5.53.156 147 / 22
5.53.155 147 / 22
5.53.143 147 / 22
5.53.140 147 / 22

v7.21.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v6.80.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.80.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.80.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.53.156

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.53.155

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.53.143

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v5.53.140

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.