@alepha/devtools
Developer tools for Alepha applications.
20
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
alepha
Keywords
alephadevtools
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:assets/devtools/entry.CfgGy8wg.js | AI (source-diff): Network calls are Vite modulepreload fetch; dynamic execution is standard ES module chunk loading. | ai | |
| source-diff | obfuscated-file:assets/devtools/entry.CfgGy8wg.js | AI (source-diff): Standard Vite build output; __vite__mapDeps pattern is canonical minified bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:assets/devtools/entry.r_sixgJG.js | AI (source-diff): Vite-bundled frontend asset; minification is expected for this devtools UI package. | ai | |
| source-diff | net-exec-file:assets/devtools/entry.r_sixgJG.js | AI (source-diff): Network calls and dynamic imports are standard Vite chunk-loading patterns in a browser UI bundle. | ai | |
| source-diff | obfuscated-file:assets/devtools/entry.Bkwg306k.js | AI (source-diff): Vite-bundled frontend asset; minification is expected for this devtools UI package. | ai | |
| source-diff | net-exec-file:assets/devtools/entry.Bkwg306k.js | AI (source-diff): Network calls and dynamic module loading are standard Vite chunk-splitting patterns, not dropper behavior. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 46 new files are Vite build output chunks; expected from the newly added UI build step. | ai | |
| source-diff | net-exec-file:assets/ui/chunk.p3hCiSrt.js | AI (source-diff): Vite-bundled UI chunk containing Alepha DI framework code; network calls are fetch() for modulepreload, not exfiltration. | ai | |
| source-diff | net-exec-file:dist/public/chunk.p3hCiSrt.js | AI (source-diff): Same Vite bundle duplicated to dist/public; identical benign content. | ai | |
| source-diff | obfuscated-file:assets/ui/entry.DnXws2rz.js | AI (source-diff): Standard Vite entry point with __vite__mapDeps and SVG icon definitions; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/public/entry.DnXws2rz.js | AI (source-diff): Same Vite entry duplicated to dist/public; identical benign minified content. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by new build:ui step bundling React/Mantine/XYFlow UI into static assets. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fires in bundled React UI chunk; Reflect.get() is standard minified framework code, not malicious obfuscation. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 0.20.2 | 0 / 13 | |
| 0.19.5 | 0 / 13 | |
| 0.19.3 | 0 / 13 | |
| 0.19.2 | 0 / 13 | |
| 0.19.1 | 0 / 13 | |
| 0.15.4 | 0 / 13 | |
| 0.15.3 | 0 / 13 | |
| 0.14.2 | 0 / 13 | |
| 0.14.0 | 0 / 13 | |
| 0.13.7 | 0 / 13 | |
| 0.13.6 | 0 / 7 | |
| 0.13.5 | 0 / 7 | |
| 0.13.4 | 0 / 7 | |
| 0.13.3 | 0 / 7 | |
| 0.13.2 | 0 / 7 | |
| 0.13.1 | 0 / 7 | |
| 0.13.0 | 0 / 7 | |
| 0.12.1 | 0 / 7 | |
| 0.12.0 | 0 / 7 | |
| 0.11.12 | 0 / 7 |