@cedarjs/vite
29
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
tobbe
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@universal-deploy/vite | AI (dependencies): Companion package in same monorepo ecosystem, no malicious indicators. | ai | |
| phantom-deps | phantom-dep:rou3 | AI (phantom-deps): Used via config reference, consistent with other accepted phantom deps in this package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @babel/types is a well-known first-party Babel package, benign addition. | ai | |
| phantom-deps | phantom-dep:fastify | AI (phantom-deps): fastify is a declared runtime dep used in config/server setup; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@universal-deploy/node | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@fastify/url-data | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:fastify-raw-body | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:core-js | AI (phantom-deps): core-js is a common implicit polyfill dependency; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): fs-extra referenced in config files; stable false positive for this build/config package. | ai | |
| provenance | no-provenance | AI (provenance): Large established monorepo package; lack of provenance is common and not a risk signal here. | ai | |
| dependencies | unvetted-dep:@fastify/url-data | AI (dependencies): Official @fastify scoped plugin; well-known ecosystem package. | ai | |
| dependencies | unvetted-dep:@universal-deploy/node | AI (dependencies): Used for universal deployment support; consistent with framework feature addition. | ai | |
| dependencies | unvetted-dep:fastify-raw-body | AI (dependencies): Legitimate fastify plugin for raw body parsing; no malware signals. | ai | |
| phantom-deps | phantom-dep:rimraf | AI (phantom-deps): rimraf is a declared runtime dep; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:cookie | AI (phantom-deps): cookie is a declared runtime dep; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): buffer is a declared runtime dep; phantom-dep heuristic fires on config-file references. | ai | |
| typosquat | typosquat.levenshtein:vitest | AI (typosquat): @cedarjs/vite is a scoped Vite config package for CedarJS, not a typosquat of vitest. | ai | |
| phantom-deps | phantom-dep:execa | AI (phantom-deps): execa is a declared runtime dep; phantom-dep heuristic fires on config-file references. | ai | |
| phantom-deps | phantom-dep:@cedarjs/cookie-jar | AI (phantom-deps): Same org scope; declared runtime dep, phantom-dep heuristic is a false positive here. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 5.0.4 | 44 / 20 | |
| 5.0.0 | 44 / 20 | |
| 4.2.0 | 47 / 16 | |
| 4.1.0 | 42 / 16 | |
| 4.0.0 | 34 / 15 | |
| 3.1.1 | 34 / 15 | |
| 3.1.0 | 34 / 15 | |
| 3.0.0 | 34 / 15 | |
| 2.8.1 | 35 / 15 | |
| 2.8.0 | 35 / 15 | |
| 2.7.0 | 35 / 15 | |
| 2.6.0 | 35 / 15 | |
| 2.5.1 | 35 / 15 | |
| 2.5.0 | 35 / 15 | |
| 2.4.1 | 35 / 15 | |
| 2.4.0 | 35 / 15 | |
| 2.3.0 | 35 / 15 | |
| 2.2.1 | 35 / 15 | |
| 2.2.0 | 36 / 16 | |
| 2.1.1 | 36 / 16 | |
| 2.1.0 | 36 / 16 | |
| 2.0.3 | 36 / 16 | |
| 2.0.2 | 36 / 16 | |
| 2.0.1 | 36 / 16 | |
| 2.0.0 | 36 / 16 | |
| 1.1.2 | 36 / 16 | |
| 1.1.1 | 36 / 16 | |
| 1.1.0 | 36 / 16 | |
| 1.0.0 | 36 / 16 |
v5.0.4
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.