← Home

@vendure/create

A CLI tool for rapidly scaffolding a new Vendure server application. Heavily inspired by [create-react-app](https://github.com/facebook/create-react-app).

14
Versions
GPL-3.0-or-later
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

michaelbromleyvendure_teamdlhckhousein_is_programming

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): CI-based publish (GitHub Actions) with SLSA attestation, not an account takeover. ai
publish-pattern new-deps-added AI (publish-pattern): tar is a well-known, widely-used package; not a suspicious addition. ai
maintainer-change maintainer-added AI (maintainer-change): vendure_team is the org's CI team account; consistent with legitimate org maintenance of this long-established package. ai
semgrep semgrep:child-process-import AI (semgrep): CLI scaffolding tool legitimately uses child_process to run package installs and system commands. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is used for template rendering in this scaffolding tool; well-known library, stable usage pattern. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require resolves ts-node from a fixed helper function, not user input; stable scaffolding pattern for this package. ai

Versions (showing 14 of 14)

Version Deps Published
3.7.1 10 / 9
3.7.0 10 / 9
3.6.4 11 / 8
3.6.3 11 / 8
3.6.2 11 / 8
3.6.1 11 / 8
3.6.0 11 / 8
3.5.6 11 / 8
3.5.5 11 / 8
3.5.4 11 / 8
3.5.3 11 / 8
3.5.2 11 / 8
3.5.1 10 / 8
2.3.4 10 / 9

v3.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.5

2 findings
HIGH Publisher changed: michaelbromley → GitHub Actions (on 2026-02-27) provenance

This version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.4

2 findings
HIGH Publisher changed: michaelbromley → GitHub Actions (on 2026-02-17) provenance

This version was published by a different npm account than previous versions on 2026-02-17. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.3

2 findings
HIGH Publisher changed: michaelbromley → GitHub Actions (on 2026-01-30) provenance

This version was published by a different npm account than previous versions on 2026-01-30. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.2

2 findings
HIGH Publisher changed: michaelbromley → GitHub Actions (on 2025-12-19) provenance

This version was published by a different npm account than previous versions on 2025-12-19. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.