← Home

@nx/vite

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nrwlownernrwl-jasonjack-nrwlmaxk-nrwljameshenry

Keywords

MonorepoViteWebCLIFront-end

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:src/plugins/plugin.js AI (source-diff): Standard compiled Nx plugin code; dynamic import of esbuild is a known pattern. ai
source-diff large-new-source-files AI (source-diff): Version jump (22→23 lineage) causes full file diff; normal for @nx/* packages. ai
semgrep semgrep:new-function-constructor AI (semgrep): Wraps dynamic ESM import of esbuild to work around CJS/ESM interop; not arbitrary code execution. ai
typosquat typosquat.levenshtein:vitest AI (typosquat): @nx/vite is the official Nx Vite plugin from nrwl; not a typosquat of vitest. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): ajv is a declared runtime dependency in package.json; phantom-dep heuristic false positive. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads user-specified proxy config file path; standard Vite/webpack proxy config pattern. ai
semgrep semgrep:child-process-import AI (semgrep): Used for build coordination in the Nx daemon plugin; legitimate build-tool usage. ai

Versions (showing 51 of 57)

View all versions
Version Deps Published
23.1.0 10 / 2
23.0.2 10 / 2
23.0.1 10 / 2
23.0.0 10 / 2
22.7.7 10 / 1
22.7.6 10 / 1
22.7.5 10 / 1
22.7.4 10 / 1
22.7.3 10 / 1
22.7.2 10 / 1
22.7.1 10 / 1
22.7.0 10 / 1
22.6.5 10 / 1
22.6.4 10 / 1
22.6.3 10 / 1
22.6.2 10 / 1
22.6.1 10 / 1
22.6.0 10 / 1
22.5.4 10 / 1
22.5.3 10 / 1
22.5.2 10 / 1
22.5.1 10 / 1
22.5.0 10 / 1
22.4.5 10 / 1
22.4.4 10 / 1
22.4.3 10 / 1
22.4.2 10 / 1
22.4.1 10 / 1
22.4.0 10 / 1
22.3.3 10 / 1
22.3.2 10 / 1
22.3.1 10 / 1
22.3.0 10 / 1
22.2.7 10 / 1
22.2.6 10 / 1
22.2.5 10 / 1
22.2.4 10 / 1
22.2.3 10 / 1
22.2.2 10 / 1
22.2.1 10 / 1
22.2.0 10 / 1
22.1.3 10 / 1
22.1.2 10 / 1
22.1.1 10 / 1
22.1.0 10 / 1
22.0.4 9 / 1
22.0.3 9 / 1
22.0.2 9 / 1
22.0.1 9 / 1
22.0.0 9 / 1
21.6.11 9 / 1

v23.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v23.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v22.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.