@nuxt/fonts
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/_nuxt/CN03tptP.js | AI (source-diff): Vite-bundled Nuxt devtools client output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/8PaFomTg.js | AI (source-diff): Vite-bundled devtools client output, not obfuscation; stable for this module. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CkYhsYtG.js | AI (source-diff): Vite-bundled devtools client output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BhCik9vP.js | AI (source-diff): Vite-bundled devtools client with Vue banner; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/entry.BPQMdpfB.js | AI (source-diff): Vite-bundled client output, not obfuscation; expected for this module's devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/entry.C4sfgaoT.js | AI (source-diff): Vite build output for the devtools client, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/entry.ChWTQKVO.js | AI (source-diff): Vite-bundled devtools client output, not obfuscation; stable for this package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size growth from bundled devtools client UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DsBbub0V.js | AI (source-diff): Vite-bundled devtools client output, not obfuscation. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Cosmetic; package is a well-known Nuxt module with 437k weekly downloads. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Known Nuxt monorepo placeholder-version pattern from trusted maintainer, not a malicious throwaway. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/D4OdMmhe.js | AI (source-diff): Vite-bundled devtools client output; Vue banner confirms build artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DzOoy7cx.js | AI (source-diff): Bundled Nuxt error page (error-404), minified build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CZa8qT6m.js | AI (source-diff): Bundled Nuxt error page (error-500), minified build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/C3xd5lw4.js | AI (source-diff): Vite-bundled error-page component; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DJdROXgZ.js | AI (source-diff): Vite-bundled error-500 component; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/_z-cc_Km.js | AI (source-diff): Vite-bundled devtools client output with Vue banner; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/D5o8EOdJ.js | AI (source-diff): Bundled Vue error-page component; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/RmdUy2OE.js | AI (source-diff): Bundled Vue error-page component; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DAoqnI3T.js | AI (source-diff): Vite-bundled devtools client output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/cusyTDfu.js | AI (source-diff): Vite-bundled error page component, benign build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CWayzxhm.js | AI (source-diff): Vite-bundled devtools client output, benign minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/zuenRb-H.js | AI (source-diff): Vite-bundled error page component, benign build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DBLCrrJp.js | AI (source-diff): Vite-bundled devtools client output, not obfuscation; regenerated each build. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/Bkhltqs5.js | AI (source-diff): Vite-bundled Vue error page chunk; minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/n2KDgErh.js | AI (source-diff): Vite-bundled Vue error-500 chunk; minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/D5zj5-gB.js | AI (source-diff): Bundled Vue error-404 component, minified build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CrRtOYvZ.js | AI (source-diff): Vite-bundled DevTools client output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BghpH-WH.js | AI (source-diff): Bundled Vue error-page component, minified build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/C7lxXNWV.js | AI (source-diff): Vite-bundled Nuxt devtools client output; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/B90XATDi.js | AI (source-diff): Bundled Vue error-404 page; minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/seMMV9S3.js | AI (source-diff): Bundled Vue error-500 page; minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/D3ofCIpB.js | AI (source-diff): Vite-bundled Vue client output with bundler banner; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/B8ePnjZV.js | AI (source-diff): Minified error-page client bundle imported from D3ofCIpB.js; benign build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/ZG52AWaE.js | AI (source-diff): Bundled Nuxt error-404 template; build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/MovCLSxp.js | AI (source-diff): Vite-bundled Nuxt client error page; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/Cic8YIcI.js | AI (source-diff): Bundled Nuxt error-500 template; build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BrJstNOp.js | AI (source-diff): Vite-bundled Nuxt devtools client output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/kyMa4om6.js | AI (source-diff): Vite-bundled Nuxt devtools client output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/xfwHGB6m.js | AI (source-diff): Vite bundle chunk with vue banner; build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DaZ9xEVn.js | AI (source-diff): Bundled Vue error page, minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/9HDfN1dA.js | AI (source-diff): Bundled Vue error page, minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/bzNtA3Ws.js | AI (source-diff): Vite-bundled devtools client output, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BjR2QoIU.js | AI (source-diff): Vite-bundled Vue error-page component; minified build output. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/D7HPRyye.js | AI (source-diff): Vite-bundled client output for Nuxt module; minified, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DB3OUodS.js | AI (source-diff): Vite-bundled Nuxt client output; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BKMN4JO2.js | AI (source-diff): Vite-bundled Vue component chunk; standard build output. | ai | |
| phantom-deps | phantom-dep:ohash | AI (phantom-deps): ohash is a legitimate utility used in config files; stable pattern for Nuxt modules. | ai | |
| phantom-deps | phantom-dep:magic-string | AI (phantom-deps): magic-string is used in config files for code transformation; stable pattern for Nuxt modules. | ai | |
| phantom-deps | phantom-dep:fontaine | AI (phantom-deps): fontaine is the core font processing library used in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:css-tree | AI (phantom-deps): css-tree is used in config files for font processing; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): esbuild is a known implicit binary dependency for build tooling; stable pattern for Nuxt modules. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): jiti is a legitimate build-time dependency used in config files; stable pattern for Nuxt modules. | ai | |
| dependencies | unvetted-dep:@nuxt/devtools-kit | AI (dependencies): @nuxt/devtools-kit is an official Nuxt organization package; stable dependency for Nuxt modules integrating with devtools. | ai | |
| dependencies | unvetted-dep:unifont | AI (dependencies): unifont is a Nuxt ecosystem font utility package, contextually appropriate for @nuxt/fonts and maintained by the same community. | ai | |
| dependencies | unvetted-dep:fontless | AI (dependencies): fontless is a Nuxt ecosystem package appropriate for a font configuration module; no independent risk signals. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 0.14.0 | 15 / 25 | |
| 0.13.0 | 21 / 26 | |
| 0.12.1 | 21 / 27 | |
| 0.11.4 | 20 / 27 | |
| 0.11.3 | 20 / 27 | |
| 0.11.2 | 20 / 27 | |
| 0.11.1 | 20 / 27 | |
| 0.11.0 | 20 / 27 | |
| 0.10.3 | 20 / 28 | |
| 0.10.2 | 20 / 28 | |
| 0.10.1 | 20 / 28 | |
| 0.10.0 | 20 / 28 | |
| 0.9.2 | 19 / 28 | |
| 0.9.1 | 19 / 28 | |
| 0.9.0 | 19 / 28 | |
| 0.8.0 | 19 / 27 | |
| 0.7.2 | 19 / 27 | |
| 0.7.1 | 19 / 27 | |
| 0.7.0 | 19 / 27 | |
| 0.6.1 | 19 / 25 | |
| 0.6.0 | 19 / 25 | |
| 0.5.1 | 19 / 25 | |
| 0.5.0 | 19 / 25 | |
| 0.4.0 | 19 / 25 | |
| 0.3.0 | 19 / 24 | |
| 0.2.1 | 19 / 24 | |
| 0.2.0 | 19 / 24 | |
| 0.1.0 | 17 / 19 | |
| 0.0.2 | 16 / 19 | |
| 0.0.1 | 15 / 16 | |
| 0.0.0 | 0 / 0 |
v0.11.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.11.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.