@osdk/widget.vite-plugin
A vite plugin that will extract parameter definitions from TS/JS files + entrypoint info into a manifest file to be uploaded to Foundry
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Palantir monorepo migrated to CI/CD publishing via GitHub Actions; SLSA attestation confirms legitimate automated publish. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-yQA8ElF6.js | AI (source-diff): Standard Vite/React bundle with modulepreload polyfill; minified, not obfuscated. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-DNbDObF0.js | AI (source-diff): Same Vite bundle pattern; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-D1FAID-A.js | AI (source-diff): Vite-bundled site assets; SVG path data and React internals produce long lines — not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-BKM9P-Lm.js | AI (source-diff): Standard Vite/React build output; React license header and modulepreload polyfill confirm bundled artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-D6Sm-vP3.js | AI (source-diff): Vite-bundled React UI asset; minified build output, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-C5U_5Xge.js | AI (source-diff): Vite-bundled React/Blueprint UI asset for the plugin's dev server; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-y3oyBPN4.js | AI (source-diff): Standard Vite/React bundled output; minified but not obfuscated. Expected artifact for this vite-plugin package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Palantir monorepo CI pipeline; rapid successive publishes across packages are expected. | ai | |
| source-diff | obfuscated-file:build/site/assets/index-BaUgq08t.js | AI (source-diff): Vite-bundled React app output; long lines are minification, not obfuscation. Stable pattern for this package's site build artifact. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): fs-extra is explicitly declared in dependencies; phantom-dep heuristic misfires here. | ai |
Versions (showing 51 of 57)
| Version | Deps | Published |
|---|---|---|
| 3.49.0 | 7 / 14 | |
| 3.48.0 | 7 / 14 | |
| 3.47.0 | 7 / 14 | |
| 3.46.0 | 7 / 14 | |
| 3.45.0 | 7 / 14 | |
| 3.44.0 | 7 / 14 | |
| 3.43.0 | 7 / 14 | |
| 3.42.0 | 7 / 14 | |
| 3.41.0 | 7 / 14 | |
| 3.40.0 | 7 / 14 | |
| 3.39.0 | 7 / 14 | |
| 3.22.0 | 7 / 14 | |
| 3.21.0 | 7 / 14 | |
| 3.20.0 | 7 / 14 | |
| 3.19.0 | 7 / 14 | |
| 3.18.0 | 7 / 14 | |
| 3.17.0 | 7 / 14 | |
| 3.16.0 | 7 / 14 | |
| 3.15.0 | 7 / 14 | |
| 3.14.0 | 7 / 14 | |
| 3.13.0 | 7 / 14 | |
| 3.12.0 | 7 / 14 | |
| 3.11.0 | 7 / 14 | |
| 3.10.0 | 7 / 14 | |
| 3.9.0 | 7 / 14 | |
| 3.8.0 | 7 / 14 | |
| 3.7.0 | 7 / 14 | |
| 3.6.0 | 7 / 14 | |
| 3.5.0 | 7 / 14 | |
| 3.4.8 | 7 / 14 | |
| 3.4.7 | 7 / 14 | |
| 3.4.6 | 7 / 14 | |
| 3.4.5 | 7 / 14 | |
| 3.4.4 | 7 / 14 | |
| 3.4.3 | 7 / 14 | |
| 3.4.2 | 7 / 14 | |
| 3.4.1 | 7 / 14 | |
| 3.4.0 | 7 / 14 | |
| 3.3.4 | 7 / 14 | |
| 3.3.3 | 7 / 14 | |
| 3.3.2 | 7 / 14 | |
| 3.3.1 | 7 / 14 | |
| 3.3.0 | 7 / 14 | |
| 3.2.10 | 7 / 14 | |
| 3.2.9 | 7 / 14 | |
| 3.2.8 | 7 / 14 | |
| 3.2.7 | 7 / 14 | |
| 3.2.6 | 7 / 14 | |
| 3.2.5 | 7 / 14 | |
| 3.2.4 | 7 / 14 | |
| 3.2.3 | 7 / 14 |
v3.49.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.47.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.46.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.45.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.44.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.43.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.42.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.41.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.40.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.39.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.15.0
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account (ericanderson) than the most recent previously approved version (GitHub Actions) on 2026-05-12, but ericanderson is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.8.0
5 findingsThis version was published by a different npm account than previous versions on 2026-04-21. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.7.0
5 findingsThis version was published by a different npm account than previous versions on 2026-04-21. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.6.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (sauravsanj) than the most recent previously approved version (palantir) on 2026-04-13, but sauravsanj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.4.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.10
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.9
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.8
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.