@nextcloud/vue
Nextcloud vue components
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/chunks/_l10n-Dq_eYxz_.mjs | AI (source-diff): Long line is generated translation data bundle, not obfuscated logic. | ai | |
| dependencies | unvetted-dep:@nextcloud/timezones | AI (dependencies): First-party Nextcloud org dependency, not third-party unvetted code. | ai | |
| npm-metadata | url-dep:@nextcloud/webpack-vue-config | AI (npm-metadata): Dev-only dep pointing to official nextcloud GitHub org, not a security risk. | ai | |
| source-diff | obfuscated-file:dist/chunks/_l10n-BSFzy-71.mjs | AI (source-diff): Generated l10n translation bundle with long data lines, not obfuscated logic. | ai | |
| source-diff | obfuscated-file:dist/chunks/_l10n-CG4CuN3H.mjs | AI (source-diff): Vite-bundled l10n translation data; long lines are serialized translation strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/NcContent-BhMoPROW.mjs | AI (source-diff): Standard Vite build output for Vue component; long lines are inlined SVG/template strings. | ai | |
| source-diff | obfuscated-file:dist/chunks/NcContent-Dd15hgck.mjs | AI (source-diff): Standard Vite-bundled ESM output; long lines are inlined SVG/CSS, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Major version bump with Vue 2→3 migration; large file count increase is expected and legitimate. | ai | |
| source-diff | obfuscated-file:dist/chunks/_l10n-skrZri3h.cjs | AI (source-diff): Minified l10n translation bundle with Nextcloud copyright; long lines are translation data, not obfuscated malware. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): Scoped package @nextcloud/vue cannot typosquat 'vite'; levenshtein match is spurious. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @nextcloud/vue cannot typosquat 'yup'; levenshtein match is spurious. | ai | |
| phantom-deps | phantom-dep:clone | AI (phantom-deps): 'clone' is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 9.8.2 | 44 / 41 | |
| 9.8.1 | 44 / 41 | |
| 9.8.0 | 44 / 41 | |
| 9.7.0 | 44 / 41 | |
| 9.5.0 | 43 / 42 | |
| 9.4.0 | 43 / 42 | |
| 9.3.3 | 43 / 42 | |
| 9.3.2 | 43 / 42 | |
| 9.3.1 | 43 / 42 | |
| 9.3.0 | 43 / 42 | |
| 9.2.0 | 43 / 42 | |
| 8.40.0 | 47 / 49 | |
| 8.39.0 | 47 / 49 | |
| 8.38.0 | 47 / 49 | |
| 8.35.3 | 46 / 48 | |
| 8.35.1 | 47 / 47 | |
| 8.35.0 | 47 / 47 | |
| 8.34.0 | 47 / 47 |
v9.5.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.4.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v9.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.40.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.35.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.35.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.35.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.34.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.