@griffel/devtools
Griffel chrome devtools extension
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:assets/index-DAAHY8Ja.js | AI (source-diff): Vite/webpack bundle output for devtools UI, not obfuscation. | ai | |
| source-diff | net-exec-file:assets/index-DAAHY8Ja.js | AI (source-diff): Standard modulepreload fetch polyfill in bundled React UI, no malicious target. | ai | |
| source-diff | obfuscated-file:main.e85b729750b57032.js | AI (source-diff): Webpack bundle with core-js polyfills, minified not obfuscated; matches devtools extension purpose. | ai | |
| source-diff | net-exec-file:main.e85b729750b57032.js | AI (source-diff): Bundled browser extension code; no concrete malicious network/exec behavior shown. | ai | |
| source-diff | net-exec-file:main.d22c5723eb6e35ed.js | AI (source-diff): Bundled browser extension code triggers pattern match; no concrete malicious behavior found. | ai | |
| source-diff | obfuscated-file:main.d22c5723eb6e35ed.js | AI (source-diff): Webpack-bundled devtools extension code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:main.6f846facd1dcd9af.js | AI (source-diff): Webpack bundle output (core-js chunks), not obfuscation; official Microsoft devtools extension. | ai | |
| source-diff | net-exec-file:main.6f846facd1dcd9af.js | AI (source-diff): Bundled build output false-positives on network+eval pattern; no concrete malicious behavior found. | ai | |
| source-diff | net-exec-file:main.ad4e2e326241195e.js | AI (source-diff): Bundled browser devtools extension code, no exfil behavior found. | ai | |
| source-diff | obfuscated-file:main.ad4e2e326241195e.js | AI (source-diff): Webpack bundle output, not obfuscation; part of devtools extension build. | ai | |
| source-diff | obfuscated-file:assets/index-B5aUEIxB.js | AI (source-diff): Vite/React bundled devtools UI, not true obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Long-running MS-owned package; maintainer list churn expected over 1400+ days. | ai | |
| source-diff | net-exec-file:assets/index-B5aUEIxB.js | AI (source-diff): Standard modulepreload fetch polyfill in bundled build, not a dropper. | ai | |
| source-diff | obfuscated-file:assets/index-D2Fr0pV5.js | AI (source-diff): Vite-bundled browser asset for a Chrome DevTools extension; minification is expected and benign for this package. | ai | |
| source-diff | net-exec-file:assets/index-D2Fr0pV5.js | AI (source-diff): Network calls are modulepreload polyfill fetch(); no dynamic code execution beyond standard React/Vite bundle patterns. | ai | |
| source-diff | net-exec-file:assets/index-CtY3dAOe.js | AI (source-diff): fetch() is the modulepreload polyfill; no dynamic code execution (eval/Function); false positive for bundled browser assets. | ai | |
| source-diff | obfuscated-file:assets/index-CtY3dAOe.js | AI (source-diff): Minified browser bundle for a Chrome DevTools extension; standard Vite/Rollup output, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@griffel/react | AI (phantom-deps): Same-org dep used in the bundled assets; phantom-dep heuristic fires on bundled code, stable FP for this package. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 0.3.14 | 1 / 0 | |
| 0.3.13 | 1 / 0 | |
| 0.3.12 | 1 / 0 | |
| 0.3.11 | 1 / 0 | |
| 0.3.10 | 0 / 1 | |
| 0.3.9 | 0 / 1 | |
| 0.3.8 | 0 / 1 | |
| 0.3.7 | 0 / 1 | |
| 0.3.6 | 0 / 1 | |
| 0.3.5 | 0 / 1 | |
| 0.3.4 | 0 / 1 | |
| 0.3.3 | 0 / 1 | |
| 0.3.2 | 0 / 1 | |
| 0.3.1 | 0 / 1 | |
| 0.3.0 | 0 / 1 | |
| 0.2.34 | 0 / 1 | |
| 0.2.33 | 0 / 1 | |
| 0.2.32 | 0 / 1 | |
| 0.2.31 | 0 / 1 | |
| 0.2.30 | 0 / 1 | |
| 0.2.29 | 0 / 1 | |
| 0.2.28 | 0 / 1 |
v0.3.14
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.13
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.34
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.33
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.32
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.31
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.30
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.