@nuxt/cli
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from individual maintainer to GitHub Actions CI/CD; SLSA provenance confirms legitimate automation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Nuxt org moved to CI publishing; maintainers still control the GitHub repo. | ai | |
| dependencies | unvetted-dep:listhen | AI (dependencies): listhen is a standard UnJS server listener utility used across the Nuxt ecosystem; no risk. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @nuxt/cli is the official Nuxt CLI under the @nuxt org scope; edit-distance match to 'joi' is a spurious false positive with no impersonation risk. | ai | |
| dependencies | unvetted-dep:pkg-types | AI (dependencies): pkg-types is a widely-used UnJS package for package.json type utilities; standard dependency for Nuxt tooling. | ai | |
| dependencies | unvetted-dep:tinyclip | AI (dependencies): tinyclip is a small utility in the UnJS ecosystem; its use in the official Nuxt CLI is expected. | ai | |
| dependencies | unvetted-dep:youch | AI (dependencies): youch is a well-known UnJS/Nuxt ecosystem error renderer; its use in @nuxt/cli is expected and legitimate. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 3.35.2 | 28 / 17 | |
| 3.35.1 | 28 / 17 | |
| 3.35.0 | 28 / 17 | |
| 3.34.0 | 28 / 17 | |
| 3.33.1 | 28 / 17 | |
| 3.33.0 | 28 / 17 | |
| 3.32.0 | 27 / 17 | |
| 3.31.3 | 27 / 17 | |
| 3.31.2 | 27 / 17 | |
| 3.31.1 | 27 / 17 | |
| 3.31.0 | 27 / 17 | |
| 3.30.0 | 24 / 16 | |
| 3.29.3 | 27 / 10 | |
| 3.29.2 | 27 / 10 | |
| 3.29.1 | 27 / 10 | |
| 3.29.0 | 27 / 10 | |
| 3.28.0 | 26 / 10 | |
| 3.27.0 | 26 / 10 | |
| 3.26.4 | 26 / 10 | |
| 3.26.3 | 26 / 10 | |
| 3.26.2 | 25 / 10 | |
| 3.26.1 | 25 / 10 | |
| 3.26.0 | 26 / 9 | |
| 3.25.1 | 24 / 8 |
v3.35.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.34.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.29.3
2 findingsThis version was published by a different npm account than previous versions on 2025-10-09. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.29.2
2 findingsThis version was published by a different npm account than previous versions on 2025-10-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.29.1
2 findingsThis version was published by a different npm account than previous versions on 2025-10-07. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.29.0
2 findingsThis version was published by a different npm account than previous versions on 2025-10-06. This could indicate a legitimate maintainer transition or an account compromise.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.28.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.27.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.26.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.26.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.26.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.26.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.25.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.