← Home

@nuxt/schema

Nuxt types and default configuration

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nuxtbot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/_chunks/libs/@unhead/vue.d.mts AI (source-diff): Type declaration file; token matches, no actual network/exec code. ai
source-diff obfuscated-file:dist/_chunks/libs/@unhead/vue.d.mts AI (source-diff): Bundled .d.mts declaration file; long type lines, not obfuscation. ai
source-diff obfuscated-file:dist/_chunks/libs/@babel/parser.d.mts AI (source-diff): Long lines are TS type-union declarations in bundled .d.mts, not obfuscation. ai
maintainer-change maintainer-takeover AI (maintainer-change): Nuxt org moved to nuxtbot CI publishing; SLSA provenance confirms legitimate transition. ai
bogus-package bogus-package AI (bogus-package): Official Nuxt package; README links and missing keywords are not spam indicators here. ai
maintainer-change maintainer-added AI (maintainer-change): nuxtbot is the Nuxt org's CI bot account; stable across future versions. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): jiti is used indirectly via config resolution at runtime; phantom-dep pattern is expected for this package type. ai
dependencies unvetted-dep:jiti AI (dependencies): jiti is a legitimate TypeScript/ESM runtime loader, a core dependency in the Nuxt/Vite ecosystem. No malicious signals; stable use across many Nuxt versions. ai
dependencies unvetted-dep:postcss-import-resolver AI (dependencies): postcss-import-resolver is a standard PostCSS utility with no malicious signals; its use in a schema package for CSS config resolution is expected. ai
phantom-deps phantom-dep:c12 AI (phantom-deps): c12 is a Nuxt config loader used indirectly at runtime; phantom-dep pattern is expected for schema/config packages. ai
phantom-deps phantom-dep:scule AI (phantom-deps): scule is a string utility used indirectly; phantom-dep pattern is expected for schema/config packages. ai
phantom-deps phantom-dep:create-require AI (phantom-deps): create-require is a CJS compatibility shim used indirectly; phantom-dep pattern is expected for this package. ai
dependencies unvetted-dep:@nuxt/ui-templates AI (dependencies): @nuxt/ui-templates is a first-party Nuxt package; unvetted status is a false positive for ecosystem packages. ai
dependencies unvetted-dep:uncrypto AI (dependencies): uncrypto is a UnJS ecosystem utility for cross-runtime crypto. Legitimate dependency maintained by the same Nuxt/UnJS team. ai
dependencies unvetted-dep:compatx AI (dependencies): compatx is a UnJS ecosystem utility, the same org as Nuxt. Legitimate dependency with stable usage across Nuxt versions. ai
provenance publisher-changed AI (provenance): Transition from danielroe to GitHub Actions CI/CD with SLSA provenance is a standard, secure publishing practice for the Nuxt framework. ai
maintainer-change maintainer-removed AI (maintainer-change): Removed maintainers are known Nuxt core team; reflects shift to automated CI/CD publishing with provenance attestation. ai
publish-pattern new-deps-added AI (publish-pattern): pkg-types is a legitimate UnJS ecosystem package maintained by the same org as Nuxt; its addition to @nuxt/schema is expected and benign. ai
dependencies unvetted-dep:defu AI (dependencies): defu is a well-known UnJS utility maintained by the same Nuxt/UnJS team; standard dependency across the Nuxt ecosystem. ai
dependencies unvetted-dep:pkg-types AI (dependencies): pkg-types is a stable utility package widely used in the Nuxt ecosystem; unvetted status does not reflect actual risk. ai

Versions (showing 51 of 111)

View all versions
Version Deps Published
4.5.1 6 / 35
4.5.0 6 / 38
4.4.8 5 / 37
4.4.7 5 / 37
4.4.6 5 / 37
4.4.5 5 / 37
4.4.4 5 / 37
4.4.2 5 / 37
4.3.1 5 / 37
4.3.0 5 / 37
4.2.2 5 / 38
4.2.1 5 / 38
4.2.0 5 / 38
4.1.3 7 / 38
4.1.2 7 / 38
4.1.1 6 / 39
4.1.0 6 / 39
4.0.3 6 / 39
4.0.2 6 / 39
4.0.1 5 / 39
4.0.0 5 / 39
3.21.9 5 / 37
3.21.8 5 / 37
3.21.7 5 / 37
3.21.6 5 / 37
3.21.5 5 / 37
3.21.4 5 / 37
3.21.2 5 / 37
3.21.1 5 / 37
3.21.0 5 / 37
3.20.2 5 / 38
3.20.1 5 / 38
3.20.0 5 / 38
3.19.3 7 / 38
3.19.2 7 / 38
3.19.1 6 / 39
3.19.0 6 / 39
3.18.1 6 / 39
3.18.0 6 / 39
3.17.7 5 / 38
3.17.6 5 / 38
3.17.5 5 / 38
3.17.4 5 / 38
3.17.3 5 / 38
3.17.2 5 / 38
3.17.1 5 / 38
3.17.0 4 / 38
3.16.2 4 / 38
3.16.1 4 / 38
3.16.0 4 / 38
3.15.4 4 / 31

v4.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.6

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: danielroe → GitHub Actions (on 2026-05-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (danielroe) on 2026-05-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: danielroe → GitHub Actions (on 2026-03-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (danielroe) on 2026-03-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.3.1

4 findings
HIGH New obfuscated file: dist/_chunks/libs/@babel/parser.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/_chunks/libs/@unhead/vue.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/_chunks/libs/@unhead/vue.d.mts source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: danielroe → GitHub Actions (on 2025-09-02, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (danielroe) on 2025-09-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.6

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: danielroe → GitHub Actions (on 2026-05-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (danielroe) on 2026-05-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.21.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.20.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.20.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.19.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.19.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.19.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.19.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: danielroe → GitHub Actions (on 2025-09-02, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (danielroe) on 2025-09-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.18.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.17.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.16.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.16.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.15.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.