← Home

@nuxt/fonts

31
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nuxtbot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/client/_nuxt/CN03tptP.js AI (source-diff): Vite-bundled Nuxt devtools client output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/8PaFomTg.js AI (source-diff): Vite-bundled devtools client output, not obfuscation; stable for this module. ai
source-diff obfuscated-file:dist/client/_nuxt/CkYhsYtG.js AI (source-diff): Vite-bundled devtools client output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/BhCik9vP.js AI (source-diff): Vite-bundled devtools client with Vue banner; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/entry.BPQMdpfB.js AI (source-diff): Vite-bundled client output, not obfuscation; expected for this module's devtools UI. ai
source-diff obfuscated-file:dist/client/_nuxt/entry.C4sfgaoT.js AI (source-diff): Vite build output for the devtools client, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/entry.ChWTQKVO.js AI (source-diff): Vite-bundled devtools client output, not obfuscation; stable for this package. ai
source-diff source-size-tripled AI (source-diff): Size growth from bundled devtools client UI. ai
source-diff obfuscated-file:dist/client/_nuxt/DsBbub0V.js AI (source-diff): Vite-bundled devtools client output, not obfuscation. ai
npm-metadata no-description AI (npm-metadata): Cosmetic; package is a well-known Nuxt module with 437k weekly downloads. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Known Nuxt monorepo placeholder-version pattern from trusted maintainer, not a malicious throwaway. ai
source-diff obfuscated-file:dist/client/_nuxt/D4OdMmhe.js AI (source-diff): Vite-bundled devtools client output; Vue banner confirms build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/DzOoy7cx.js AI (source-diff): Bundled Nuxt error page (error-404), minified build output. ai
source-diff obfuscated-file:dist/client/_nuxt/CZa8qT6m.js AI (source-diff): Bundled Nuxt error page (error-500), minified build output. ai
source-diff obfuscated-file:dist/client/_nuxt/C3xd5lw4.js AI (source-diff): Vite-bundled error-page component; benign build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/DJdROXgZ.js AI (source-diff): Vite-bundled error-500 component; benign build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/_z-cc_Km.js AI (source-diff): Vite-bundled devtools client output with Vue banner; minified not obfuscated. ai
source-diff obfuscated-file:dist/client/_nuxt/D5o8EOdJ.js AI (source-diff): Bundled Vue error-page component; benign build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/RmdUy2OE.js AI (source-diff): Bundled Vue error-page component; benign build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/DAoqnI3T.js AI (source-diff): Vite-bundled devtools client output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/cusyTDfu.js AI (source-diff): Vite-bundled error page component, benign build output. ai
source-diff obfuscated-file:dist/client/_nuxt/CWayzxhm.js AI (source-diff): Vite-bundled devtools client output, benign minified build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/zuenRb-H.js AI (source-diff): Vite-bundled error page component, benign build output. ai
source-diff obfuscated-file:dist/client/_nuxt/DBLCrrJp.js AI (source-diff): Vite-bundled devtools client output, not obfuscation; regenerated each build. ai
source-diff obfuscated-file:dist/client/_nuxt/Bkhltqs5.js AI (source-diff): Vite-bundled Vue error page chunk; minified build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/n2KDgErh.js AI (source-diff): Vite-bundled Vue error-500 chunk; minified build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/D5zj5-gB.js AI (source-diff): Bundled Vue error-404 component, minified build output. ai
source-diff obfuscated-file:dist/client/_nuxt/CrRtOYvZ.js AI (source-diff): Vite-bundled DevTools client output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/BghpH-WH.js AI (source-diff): Bundled Vue error-page component, minified build output. ai
source-diff obfuscated-file:dist/client/_nuxt/C7lxXNWV.js AI (source-diff): Vite-bundled Nuxt devtools client output; minified not obfuscated. ai
source-diff obfuscated-file:dist/client/_nuxt/B90XATDi.js AI (source-diff): Bundled Vue error-404 page; minified build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/seMMV9S3.js AI (source-diff): Bundled Vue error-500 page; minified build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/D3ofCIpB.js AI (source-diff): Vite-bundled Vue client output with bundler banner; benign build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/B8ePnjZV.js AI (source-diff): Minified error-page client bundle imported from D3ofCIpB.js; benign build output. ai
source-diff obfuscated-file:dist/client/_nuxt/ZG52AWaE.js AI (source-diff): Bundled Nuxt error-404 template; build output. ai
source-diff obfuscated-file:dist/client/_nuxt/MovCLSxp.js AI (source-diff): Vite-bundled Nuxt client error page; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/Cic8YIcI.js AI (source-diff): Bundled Nuxt error-500 template; build output. ai
source-diff obfuscated-file:dist/client/_nuxt/BrJstNOp.js AI (source-diff): Vite-bundled Nuxt devtools client output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/kyMa4om6.js AI (source-diff): Vite-bundled Nuxt devtools client output, not obfuscation. ai
source-diff obfuscated-file:dist/client/_nuxt/xfwHGB6m.js AI (source-diff): Vite bundle chunk with vue banner; build output. ai
source-diff obfuscated-file:dist/client/_nuxt/DaZ9xEVn.js AI (source-diff): Bundled Vue error page, minified build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/9HDfN1dA.js AI (source-diff): Bundled Vue error page, minified build artifact. ai
source-diff obfuscated-file:dist/client/_nuxt/bzNtA3Ws.js AI (source-diff): Vite-bundled devtools client output, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/_nuxt/BjR2QoIU.js AI (source-diff): Vite-bundled Vue error-page component; minified build output. ai
source-diff obfuscated-file:dist/client/_nuxt/D7HPRyye.js AI (source-diff): Vite-bundled client output for Nuxt module; minified, not obfuscated. ai
source-diff obfuscated-file:dist/client/_nuxt/DB3OUodS.js AI (source-diff): Vite-bundled Nuxt client output; minified not obfuscated. ai
source-diff obfuscated-file:dist/client/_nuxt/BKMN4JO2.js AI (source-diff): Vite-bundled Vue component chunk; standard build output. ai
phantom-deps phantom-dep:ohash AI (phantom-deps): ohash is a legitimate utility used in config files; stable pattern for Nuxt modules. ai
phantom-deps phantom-dep:magic-string AI (phantom-deps): magic-string is used in config files for code transformation; stable pattern for Nuxt modules. ai
phantom-deps phantom-dep:fontaine AI (phantom-deps): fontaine is the core font processing library used in config; stable pattern for this package. ai
phantom-deps phantom-dep:css-tree AI (phantom-deps): css-tree is used in config files for font processing; stable pattern for this package. ai
phantom-deps phantom-dep:esbuild AI (phantom-deps): esbuild is a known implicit binary dependency for build tooling; stable pattern for Nuxt modules. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is a legitimate build-time dependency used in config files; stable pattern for Nuxt modules. ai
dependencies unvetted-dep:@nuxt/devtools-kit AI (dependencies): @nuxt/devtools-kit is an official Nuxt organization package; stable dependency for Nuxt modules integrating with devtools. ai
dependencies unvetted-dep:unifont AI (dependencies): unifont is a Nuxt ecosystem font utility package, contextually appropriate for @nuxt/fonts and maintained by the same community. ai
dependencies unvetted-dep:fontless AI (dependencies): fontless is a Nuxt ecosystem package appropriate for a font configuration module; no independent risk signals. ai

Versions (showing 31 of 31)

Version Deps Published
0.14.0 15 / 25
0.13.0 21 / 26
0.12.1 21 / 27
0.11.4 20 / 27
0.11.3 20 / 27
0.11.2 20 / 27
0.11.1 20 / 27
0.11.0 20 / 27
0.10.3 20 / 28
0.10.2 20 / 28
0.10.1 20 / 28
0.10.0 20 / 28
0.9.2 19 / 28
0.9.1 19 / 28
0.9.0 19 / 28
0.8.0 19 / 27
0.7.2 19 / 27
0.7.1 19 / 27
0.7.0 19 / 27
0.6.1 19 / 25
0.6.0 19 / 25
0.5.1 19 / 25
0.5.0 19 / 25
0.4.0 19 / 25
0.3.0 19 / 24
0.2.1 19 / 24
0.2.0 19 / 24
0.1.0 17 / 19
0.0.2 16 / 19
0.0.1 15 / 16
0.0.0 0 / 0

v0.11.2

4 findings
HIGH New obfuscated file: dist/client/_nuxt/BrJstNOp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/kyMa4om6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/xfwHGB6m.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.1

4 findings
HIGH New obfuscated file: dist/client/_nuxt/CZa8qT6m.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/D4OdMmhe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/DzOoy7cx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

4 findings
HIGH New obfuscated file: dist/client/_nuxt/Bkhltqs5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/DBLCrrJp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/n2KDgErh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.3

4 findings
HIGH New obfuscated file: dist/client/_nuxt/cusyTDfu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/CWayzxhm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/zuenRb-H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.2

4 findings
HIGH New obfuscated file: dist/client/_nuxt/_z-cc_Km.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/C3xd5lw4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/DJdROXgZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

4 findings
HIGH New obfuscated file: dist/client/_nuxt/D5o8EOdJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/DAoqnI3T.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/RmdUy2OE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

4 findings
HIGH New obfuscated file: dist/client/_nuxt/Cic8YIcI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/MovCLSxp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/ZG52AWaE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.2

4 findings
HIGH New obfuscated file: dist/client/_nuxt/9HDfN1dA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/bzNtA3Ws.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/DaZ9xEVn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.1

4 findings
HIGH New obfuscated file: dist/client/_nuxt/BghpH-WH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/CrRtOYvZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/D5zj5-gB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

4 findings
HIGH New obfuscated file: dist/client/_nuxt/B90XATDi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/C7lxXNWV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/client/_nuxt/seMMV9S3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

3 findings
HIGH New obfuscated file: dist/client/_nuxt/BjR2QoIU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/D7HPRyye.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

3 findings
HIGH New obfuscated file: dist/client/_nuxt/B8ePnjZV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/D3ofCIpB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

3 findings
HIGH New obfuscated file: dist/client/_nuxt/BKMN4JO2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/_nuxt/DB3OUodS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.6.1

2 findings
HIGH New obfuscated file: dist/client/_nuxt/CN03tptP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

2 findings
HIGH New obfuscated file: dist/client/_nuxt/CkYhsYtG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

2 findings
HIGH New obfuscated file: dist/client/_nuxt/8PaFomTg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

2 findings
HIGH New obfuscated file: dist/client/_nuxt/DsBbub0V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

2 findings
HIGH New obfuscated file: dist/client/_nuxt/BhCik9vP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

2 findings
HIGH New obfuscated file: dist/client/_nuxt/entry.BPQMdpfB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

2 findings
HIGH New obfuscated file: dist/client/_nuxt/entry.C4sfgaoT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

2 findings
HIGH New obfuscated file: dist/client/_nuxt/entry.ChWTQKVO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.