← Home

@vendure/create

A CLI tool for rapidly scaffolding a new Vendure server application. Heavily inspired by [create-react-app](https://github.com/facebook/create-react-app).

7
Versions
GPL-3.0-or-later
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

michaelbromleyvendure_teamdlhckhousein_is_programming

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): vendure_team is the org's CI team account; consistent with legitimate org maintenance of this long-established package. ai
semgrep semgrep:child-process-import AI (semgrep): CLI scaffolding tool legitimately uses child_process to run package installs and system commands. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is used for template rendering in this scaffolding tool; well-known library, stable usage pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require resolves ts-node from a fixed helper function, not user input; stable scaffolding pattern for this package. ai

Versions (showing 7 of 7)

Version Deps Published
3.6.4 11 / 8
3.6.3 11 / 8
3.6.2 11 / 8
3.6.1 11 / 8
3.6.0 11 / 8
3.5.6 11 / 8
2.3.4 10 / 9

v3.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.