@storybook/cli
Storybook CLI: Develop, document, and test UI components in isolation
100
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
ndelangenshilmantmeasdayghengeveldwinkervsbecksyannbfkylegachjreinholdkasperpeulenvalentinpalkovicdomyenstorybook-bot
Keywords
storybookclidevbuildupgradeinit
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/_node-chunks/run-YXTQBW3D.js | AI (source-diff): CLI tool legitimately uses network + child_process; bundled output, not malicious. | ai | |
| source-diff | obfuscated-file:dist/_node-chunks/run-YXTQBW3D.js | AI (source-diff): esbuild-bundled output with CJS compat banner; standard Storybook build artifact. | ai | |
| source-diff | obfuscated-file:dist/_node-chunks/run-CMSUW4EI.js | AI (source-diff): esbuild-bundled output for Storybook CLI; minified chunks are expected. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Normal churn for a large CLI tool rebundled with esbuild across versions. | ai | |
| source-diff | net-exec-file:dist/_node-chunks/run-CMSUW4EI.js | AI (source-diff): CLI tool legitimately uses network + exec (e.g. init, upgrade); bundled output. | ai | |
| source-diff | net-exec-file:dist/_node-chunks/run-7LEO2IWT.js | AI (source-diff): CLI tool legitimately uses network + exec; bundled output, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/_node-chunks/run-7LEO2IWT.js | AI (source-diff): esbuild-bundled output with CJS compat banner; standard for Storybook's build pipeline. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Monorepo automated release; expected for @storybook packages. | ai | |
| phantom-deps | phantom-dep:@babel/preset-env | AI (phantom-deps): @babel/preset-env is a framework-scoped package loaded by convention in Storybook's build pipeline; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/semver | AI (phantom-deps): @types/semver is a type declaration package loaded by convention; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:jscodeshift | AI (phantom-deps): jscodeshift is a legitimate declared dependency used by convention in the CLI's codemod tooling, not a phantom dep. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): @storybook/cli is a well-established scoped package with 3000+ days of history; Levenshtein match against 'joi' is a false positive with no plausible typosquat relationship. | ai | |
| source-diff | net-exec-file:dist/_node-chunks/run-UE2YPBJ7.js | AI (source-diff): Network + code execution is expected for a CLI tool that upgrades Storybook dependencies, fetches npm package data, and runs codemods. The sample shows legitimate Storybook CLI functionality. | ai | |
| source-diff | obfuscated-file:dist/_node-chunks/run-UE2YPBJ7.js | AI (source-diff): Storybook CLI ships esbuild-bundled dist chunks with long lines; this is standard build output, not obfuscation. The CJS compat banner and named Storybook function imports confirm legitimate bundled code. | ai |
Versions (showing 100 of 919)
| Version | Deps | Published |
|---|---|---|
| 7.4.2 | 41 / 10 | |
| 7.4.1 | 41 / 10 | |
| 7.4.0 | 40 / 10 | |
| 7.3.2 | 40 / 10 | |
| 7.3.1 | 40 / 10 | |
| 7.3.0 | 40 / 10 | |
| 7.2.3 | 40 / 10 | |
| 7.2.2 | 40 / 10 | |
| 7.2.1 | 40 / 10 | |
| 7.2.0 | 40 / 10 | |
| 7.1.1 | 40 / 10 | |
| 7.1.0 | 39 / 10 | |
| 7.0.27 | 38 / 11 | |
| 7.0.26 | 38 / 11 | |
| 7.0.25 | 38 / 11 | |
| 7.0.24 | 38 / 11 | |
| 7.0.23 | 38 / 11 | |
| 7.0.22 | 38 / 11 | |
| 7.0.21 | 39 / 10 | |
| 7.0.20 | 39 / 10 | |
| 7.0.19 | 39 / 10 | |
| 7.0.18 | 39 / 10 | |
| 7.0.17 | 39 / 10 | |
| 7.0.16 | 39 / 10 | |
| 7.0.15 | 39 / 10 | |
| 7.0.14 | 39 / 10 | |
| 7.0.13 | 39 / 10 | |
| 7.0.12 | 38 / 10 | |
| 7.0.11 | 38 / 10 | |
| 7.0.10 | 38 / 10 | |
| 7.0.9 | 38 / 10 | |
| 7.0.8 | 38 / 10 | |
| 7.0.7 | 38 / 9 | |
| 7.0.6 | 38 / 9 | |
| 7.0.5 | 38 / 9 | |
| 7.0.4 | 38 / 9 | |
| 7.0.3 | 38 / 9 | |
| 7.0.2 | 38 / 9 | |
| 7.0.1 | 38 / 9 | |
| 7.0.0 | 38 / 9 | |
| 6.5.16 | 29 / 9 | |
| 6.5.15 | 29 / 9 | |
| 6.5.14 | 29 / 9 | |
| 6.5.13 | 29 / 9 | |
| 6.5.12 | 29 / 9 | |
| 6.5.11 | 29 / 9 | |
| 6.5.10 | 29 / 9 | |
| 6.5.9 | 29 / 9 | |
| 6.5.8 | 29 / 9 | |
| 6.5.7 | 29 / 9 | |
| 6.5.6 | 29 / 9 | |
| 6.5.5 | 29 / 9 | |
| 6.5.4 | 29 / 9 | |
| 6.5.3 | 29 / 9 | |
| 6.5.2 | 29 / 9 | |
| 6.5.0 | 29 / 9 | |
| 6.4.22 | 28 / 9 | |
| 6.4.21 | 28 / 9 | |
| 6.4.20 | 28 / 9 | |
| 6.4.19 | 28 / 9 | |
| 6.4.18 | 28 / 9 | |
| 6.4.17 | 28 / 9 | |
| 6.4.16 | 28 / 9 | |
| 6.4.15 | 28 / 9 | |
| 6.4.14 | 28 / 9 | |
| 6.4.13 | 28 / 9 | |
| 6.4.12 | 28 / 9 | |
| 6.4.10 | 28 / 9 | |
| 6.4.9 | 28 / 9 | |
| 6.4.8 | 28 / 9 | |
| 6.4.7 | 28 / 9 | |
| 6.4.5 | 28 / 9 | |
| 6.4.4 | 28 / 9 | |
| 6.4.3 | 28 / 9 | |
| 6.4.2 | 28 / 9 | |
| 6.4.1 | 28 / 9 | |
| 6.4.0 | 28 / 9 | |
| 6.3.13 | 26 / 9 | |
| 6.3.12 | 26 / 9 | |
| 6.3.11 | 26 / 9 | |
| 6.3.10 | 26 / 9 | |
| 6.3.9 | 26 / 9 | |
| 6.3.8 | 26 / 9 | |
| 6.3.7 | 26 / 9 | |
| 6.3.6 | 26 / 9 | |
| 6.3.5 | 26 / 9 | |
| 6.3.4 | 26 / 9 | |
| 6.3.3 | 26 / 9 | |
| 6.3.2 | 26 / 9 | |
| 6.3.1 | 26 / 9 | |
| 6.3.0 | 26 / 9 | |
| 6.2.9 | 24 / 9 | |
| 6.2.8 | 25 / 10 | |
| 6.2.7 | 25 / 10 | |
| 6.2.6 | 25 / 10 | |
| 6.2.5 | 25 / 10 | |
| 6.2.4 | 25 / 10 | |
| 6.2.3 | 25 / 10 | |
| 6.2.2 | 25 / 10 | |
| 6.2.1 | 25 / 10 |
Showing 100 of 919
Next page →