@nuxt/hints
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/_nuxt/0QfVe7z6.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/B5ZiCXm-.js | AI (source-diff): Standard Vite-bundled client asset (Vue runtime + Nuxt devtools UI). | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BgLLdLcJ.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/Blg8Mpta.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/Bsv6sHU9.js | AI (source-diff): Standard Vite-bundled client asset (Nuxt error-500 page component). | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BTxIHKoM.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/C2nqPHhB.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CKgxn7_D.js | AI (source-diff): Standard Vite-bundled client asset (Nuxt error-404 page component). | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CwfHEBz0.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/D6dXRY2y.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/Du_CL2nr.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/gQBZ1dwH.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/xCRX-wXg.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/XM71VPcv.js | AI (source-diff): Standard Vite-bundled client asset for @nuxt/hints devtools UI. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are Vite-split client bundle chunks for the devtools UI; expected for this package type. | ai | |
| phantom-deps | phantom-dep:unstorage | AI (phantom-deps): unstorage is a declared runtime dep used indirectly via Nuxt/Nitro internals; phantom-dep heuristic is a false positive here. | ai |
v1.1.2
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.