
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@uipath/solution-tool
Advanced tools
Affected versions:
uip tool for managing UiPath Automation Solutions.
| Command | Description |
|---|---|
pack | Pack a UiPath solution |
publish | Publish solution package |
new | Create a new solution |
upload | Upload a solution package |
deploy run | Deploy solution to environment |
deploy status | Check deployment status |
deploy activate | Activate deployed solution |
deploy uninstall | Remove solution |
deploy list | List deployments |
deploy config get/set/link/unlink | Manage deployment configuration |
project add/import/remove | Manage projects within a solution |
packages list/delete | Manage solution packages |
uip solution pack <solutionPath>
uip solution publish <packagePath>
uip solution init --name MySolution
uip solution upload <packagePath>
uip solution deploy run --solution-name MySolution
uip solution deploy status --solution-name MySolution
uip solution projects add ./my-solution/my-project ./my-solution/my-solution.uipx
uip solution deploy run accepts --personal-workspace as an alternative to
--parent-folder-path / --parent-folder-key. When set, the CLI calls
Orchestrator's GetPersonalWorkspace endpoint once to look up the current
user's workspace name, then uses that as the deploy target — matching
StudioWeb's "Publish to Personal Workspace" UX.
uip solution deploy run \
--name my-deployment \
--package-name my-package \
--package-version 1.0.0 \
--folder-name MySolution \
--personal-workspace
The three target flags (--parent-folder-path, --parent-folder-key,
--personal-workspace) are mutually exclusive. The lookup uses whichever
auth context is active — uip login, UIPATH_CLI_ENABLE_ENV_AUTH, or
UIPATH_CLI_ENFORCE_ROBOT_AUTH — so the same command works in standalone
terminals, CI pipelines, and Studio Desktop-spawned invocations. Service
principals or robot accounts without a Personal Workspace produce a clear
"not configured" error.
uip solution pack and uip solution upload skip developer-local
directories and credential files that don't belong in a published
solution. The defaults are always applied.
Directories (matched by exact name at any depth):
.venv — Python virtualenvs (per-agent under <solution>/<agent>/.venv).node_modules — Node dependency caches.__pycache__ — Python bytecode caches..git — VCS metadata.Files (matched by name pattern at any depth):
.env, .env.local, .env.production, etc. (any file whose name is
.env or starts with .env.) — dotenv credential files. They commonly
hold API keys, database passwords, and OAuth client secrets, so they
are never shipped in the bundle. Lookalikes such as .envrc,
.environment, and myenv.txt are kept.To skip additional directories, add a .uipignore file at the solution
root (next to the .uipx file). One directory name per line; # starts a
line or trailing comment; blank lines and whitespace-only lines are
ignored. Each entry matches by exact directory name at any depth — the
same semantics as the built-in defaults. Path separators (/, \) are
not supported yet.
Example .uipignore:
# project-specific build artifacts
dist
coverage
# vendored deps we don't want shipped
vendor
A .uipignore may also be placed at a project root (next to that
project's project.uiproj). Its entries are scoped to that project only and
are merged on top of the solution-root .uipignore and the built-in
defaults. Use this when an exclude should apply to one project but not its
siblings (a solution-root entry, by contrast, applies to every project). The
file format is identical.
The bundler logs which additional excludes are being applied at upload time so the effective set is visible in CI logs.
FAQs
Create, pack, publish, and deploy UiPath Automation Solutions.
The npm package @uipath/solution-tool receives a total of 2,327 weekly downloads. As such, @uipath/solution-tool popularity was classified as popular.
We found that @uipath/solution-tool demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 24 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.