← Home

@griffel/devtools

Griffel chrome devtools extension

22
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

layershifterjustslonemiroslavstastnyuifabricteam

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:assets/index-DAAHY8Ja.js AI (source-diff): Vite/webpack bundle output for devtools UI, not obfuscation. ai
source-diff net-exec-file:assets/index-DAAHY8Ja.js AI (source-diff): Standard modulepreload fetch polyfill in bundled React UI, no malicious target. ai
source-diff obfuscated-file:main.e85b729750b57032.js AI (source-diff): Webpack bundle with core-js polyfills, minified not obfuscated; matches devtools extension purpose. ai
source-diff net-exec-file:main.e85b729750b57032.js AI (source-diff): Bundled browser extension code; no concrete malicious network/exec behavior shown. ai
source-diff net-exec-file:main.d22c5723eb6e35ed.js AI (source-diff): Bundled browser extension code triggers pattern match; no concrete malicious behavior found. ai
source-diff obfuscated-file:main.d22c5723eb6e35ed.js AI (source-diff): Webpack-bundled devtools extension code, not true obfuscation. ai
source-diff obfuscated-file:main.6f846facd1dcd9af.js AI (source-diff): Webpack bundle output (core-js chunks), not obfuscation; official Microsoft devtools extension. ai
source-diff net-exec-file:main.6f846facd1dcd9af.js AI (source-diff): Bundled build output false-positives on network+eval pattern; no concrete malicious behavior found. ai
source-diff net-exec-file:main.ad4e2e326241195e.js AI (source-diff): Bundled browser devtools extension code, no exfil behavior found. ai
source-diff obfuscated-file:main.ad4e2e326241195e.js AI (source-diff): Webpack bundle output, not obfuscation; part of devtools extension build. ai
source-diff obfuscated-file:assets/index-B5aUEIxB.js AI (source-diff): Vite/React bundled devtools UI, not true obfuscation. ai
maintainer-change maintainer-removed AI (maintainer-change): Long-running MS-owned package; maintainer list churn expected over 1400+ days. ai
source-diff net-exec-file:assets/index-B5aUEIxB.js AI (source-diff): Standard modulepreload fetch polyfill in bundled build, not a dropper. ai
source-diff obfuscated-file:assets/index-D2Fr0pV5.js AI (source-diff): Vite-bundled browser asset for a Chrome DevTools extension; minification is expected and benign for this package. ai
source-diff net-exec-file:assets/index-D2Fr0pV5.js AI (source-diff): Network calls are modulepreload polyfill fetch(); no dynamic code execution beyond standard React/Vite bundle patterns. ai
source-diff net-exec-file:assets/index-CtY3dAOe.js AI (source-diff): fetch() is the modulepreload polyfill; no dynamic code execution (eval/Function); false positive for bundled browser assets. ai
source-diff obfuscated-file:assets/index-CtY3dAOe.js AI (source-diff): Minified browser bundle for a Chrome DevTools extension; standard Vite/Rollup output, not obfuscation. ai
phantom-deps phantom-dep:@griffel/react AI (phantom-deps): Same-org dep used in the bundled assets; phantom-dep heuristic fires on bundled code, stable FP for this package. ai

Versions (showing 22 of 22)

Version Deps Published
0.3.14 1 / 0
0.3.13 1 / 0
0.3.12 1 / 0
0.3.11 1 / 0
0.3.10 0 / 1
0.3.9 0 / 1
0.3.8 0 / 1
0.3.7 0 / 1
0.3.6 0 / 1
0.3.5 0 / 1
0.3.4 0 / 1
0.3.3 0 / 1
0.3.2 0 / 1
0.3.1 0 / 1
0.3.0 0 / 1
0.2.34 0 / 1
0.2.33 0 / 1
0.2.32 0 / 1
0.2.31 0 / 1
0.2.30 0 / 1
0.2.29 0 / 1
0.2.28 0 / 1

v0.3.14

3 findings
HIGH New obfuscated file: assets/index-B5aUEIxB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: assets/index-B5aUEIxB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.13

3 findings
HIGH New obfuscated file: assets/index-DAAHY8Ja.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: assets/index-DAAHY8Ja.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.2

3 findings
HIGH New obfuscated file: main.e85b729750b57032.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.e85b729750b57032.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

3 findings
HIGH New obfuscated file: main.d22c5723eb6e35ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.d22c5723eb6e35ed.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

3 findings
HIGH New obfuscated file: main.d22c5723eb6e35ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.d22c5723eb6e35ed.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.34

3 findings
HIGH New obfuscated file: main.6f846facd1dcd9af.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.6f846facd1dcd9af.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.33

3 findings
HIGH New obfuscated file: main.6f846facd1dcd9af.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.6f846facd1dcd9af.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.32

3 findings
HIGH New obfuscated file: main.6f846facd1dcd9af.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.6f846facd1dcd9af.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.31

3 findings
HIGH New obfuscated file: main.6f846facd1dcd9af.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.6f846facd1dcd9af.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.30

3 findings
HIGH New obfuscated file: main.ad4e2e326241195e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: main.ad4e2e326241195e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.