← Home

@cloudflare/vite-plugin

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

wrangler-publisher

Keywords

cloudflarecloudflare-workersvitevite-pluginworkers

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/dist-Cr__Sz5N.mjs AI (source-diff): Bundled dist with undici WASM + node:module hooks; expected for a Vite plugin. ai
phantom-deps phantom-dep:ws AI (phantom-deps): Runtime dep used by miniflare proxy, loaded indirectly. ai
source-diff net-exec-file:dist/dist-MawCthRW.mjs AI (source-diff): Bundled dist with undici WASM + Zod; standard for a Vite/miniflare plugin. ai
phantom-deps phantom-dep:unenv AI (phantom-deps): Known implicit runtime dependency for Cloudflare worker env. ai
phantom-deps phantom-dep:@cloudflare/unenv-preset AI (phantom-deps): Framework-scoped package loaded by convention. ai
publish-pattern new-deps-added AI (publish-pattern): defu is a well-known unjs utility; addition is benign for this established Cloudflare package. ai
source-diff net-exec-file:dist/workers/runner-worker/index.js AI (source-diff): Bundled Cloudflare worker using Vite ModuleRunner; expected network+eval pattern for this plugin. ai
source-diff encoded-string-file:dist/index.mjs AI (source-diff): Base64 WASM blob from bundled undici/llhttp; stable pattern for this package. ai

Versions (showing 51 of 136)

View all versions
Version Deps Published
1.47.0 6 / 28
1.46.0 6 / 28
1.45.1 6 / 27
1.45.0 6 / 27
1.44.0 5 / 26
1.43.3 5 / 26
1.43.2 5 / 26
1.43.1 5 / 26
1.43.0 5 / 26
1.42.4 5 / 26
1.42.3 5 / 26
1.42.2 5 / 26
1.42.1 5 / 26
1.42.0 5 / 26
1.41.0 5 / 26
1.40.2 5 / 26
1.40.1 5 / 26
1.40.0 5 / 26
1.39.2 5 / 25
1.39.1 5 / 25
1.39.0 5 / 25
1.38.0 5 / 25
1.37.3 5 / 24
1.37.2 5 / 24
1.37.1 5 / 24
1.37.0 5 / 24
1.36.4 5 / 24
1.36.3 5 / 24
1.36.2 5 / 24
1.36.1 5 / 24
1.36.0 5 / 24
1.35.0 5 / 24
1.34.0 5 / 24
1.33.2 5 / 24
1.33.1 5 / 24
1.33.0 5 / 24
1.32.3 5 / 24
1.32.2 5 / 24
1.32.1 5 / 24
1.32.0 5 / 24
1.31.2 5 / 23
1.31.1 5 / 23
1.31.0 5 / 23
1.30.3 5 / 23
1.30.2 5 / 23
1.30.1 5 / 23
1.30.0 5 / 23
1.29.1 5 / 23
1.29.0 5 / 22
1.28.0 5 / 22
1.27.0 5 / 22

v1.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.43.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.43.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.43.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.42.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.