← Home

@osdk/widget.vite-plugin

A vite plugin that will extract parameter definitions from TS/JS files + entrypoint info into a manifest file to be uploaded to Foundry

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sauravsanjpalantirericandersonericjeney-palantir

Keywords

vite-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Palantir monorepo migrated to CI/CD publishing via GitHub Actions; SLSA attestation confirms legitimate automated publish. ai
source-diff obfuscated-file:build/site/assets/index-yQA8ElF6.js AI (source-diff): Standard Vite/React bundle with modulepreload polyfill; minified, not obfuscated. ai
source-diff obfuscated-file:build/site/assets/index-DNbDObF0.js AI (source-diff): Same Vite bundle pattern; minified build output, not obfuscation. ai
source-diff obfuscated-file:build/site/assets/index-D1FAID-A.js AI (source-diff): Vite-bundled site assets; SVG path data and React internals produce long lines — not true obfuscation. ai
source-diff obfuscated-file:build/site/assets/index-BKM9P-Lm.js AI (source-diff): Standard Vite/React build output; React license header and modulepreload polyfill confirm bundled artifact, not obfuscation. ai
source-diff obfuscated-file:build/site/assets/index-D6Sm-vP3.js AI (source-diff): Vite-bundled React UI asset; minified build output, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:build/site/assets/index-C5U_5Xge.js AI (source-diff): Vite-bundled React/Blueprint UI asset for the plugin's dev server; minified build output, not obfuscation. ai
source-diff obfuscated-file:build/site/assets/index-y3oyBPN4.js AI (source-diff): Standard Vite/React bundled output; minified but not obfuscated. Expected artifact for this vite-plugin package. ai
publish-pattern rapid-publish AI (publish-pattern): Palantir monorepo CI pipeline; rapid successive publishes across packages are expected. ai
source-diff obfuscated-file:build/site/assets/index-BaUgq08t.js AI (source-diff): Vite-bundled React app output; long lines are minification, not obfuscation. Stable pattern for this package's site build artifact. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): fs-extra is explicitly declared in dependencies; phantom-dep heuristic misfires here. ai

Versions (showing 51 of 57)

View all versions
Version Deps Published
3.49.0 7 / 14
3.48.0 7 / 14
3.47.0 7 / 14
3.46.0 7 / 14
3.45.0 7 / 14
3.44.0 7 / 14
3.43.0 7 / 14
3.42.0 7 / 14
3.41.0 7 / 14
3.40.0 7 / 14
3.39.0 7 / 14
3.22.0 7 / 14
3.21.0 7 / 14
3.20.0 7 / 14
3.19.0 7 / 14
3.18.0 7 / 14
3.17.0 7 / 14
3.16.0 7 / 14
3.15.0 7 / 14
3.14.0 7 / 14
3.13.0 7 / 14
3.12.0 7 / 14
3.11.0 7 / 14
3.10.0 7 / 14
3.9.0 7 / 14
3.8.0 7 / 14
3.7.0 7 / 14
3.6.0 7 / 14
3.5.0 7 / 14
3.4.8 7 / 14
3.4.7 7 / 14
3.4.6 7 / 14
3.4.5 7 / 14
3.4.4 7 / 14
3.4.3 7 / 14
3.4.2 7 / 14
3.4.1 7 / 14
3.4.0 7 / 14
3.3.4 7 / 14
3.3.3 7 / 14
3.3.2 7 / 14
3.3.1 7 / 14
3.3.0 7 / 14
3.2.10 7 / 14
3.2.9 7 / 14
3.2.8 7 / 14
3.2.7 7 / 14
3.2.6 7 / 14
3.2.5 7 / 14
3.2.4 7 / 14
3.2.3 7 / 14

v3.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.46.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.45.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.43.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.42.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.41.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.40.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.39.0

2 findings
HIGH New obfuscated file: build/site/assets/index-BaUgq08t.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.15.0

2 findings
HIGH Provenance attestation missing — previous versions had it provenance

This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.

INFO Publisher changed: GitHub Actions → ericanderson (on 2026-05-12, known maintainer) provenance

This version was published by a different npm account (ericanderson) than the most recent previously approved version (GitHub Actions) on 2026-05-12, but ericanderson is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.8.0

5 findings
HIGH Publisher changed: palantir → GitHub Actions (on 2026-04-21) provenance

This version was published by a different npm account than previous versions on 2026-04-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/site/assets/index-D1FAID-A.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/site/assets/index-DNbDObF0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/site/assets/index-yQA8ElF6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

5 findings
HIGH Publisher changed: palantir → GitHub Actions (on 2026-04-21) provenance

This version was published by a different npm account than previous versions on 2026-04-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/site/assets/index-D1FAID-A.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/site/assets/index-DNbDObF0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/site/assets/index-yQA8ElF6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.0

5 findings
HIGH New obfuscated file: build/site/assets/index-D1FAID-A.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/site/assets/index-DNbDObF0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/site/assets/index-yQA8ElF6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: palantir → sauravsanj (on 2026-04-13, known maintainer) provenance

This version was published by a different npm account (sauravsanj) than the most recent previously approved version (palantir) on 2026-04-13, but sauravsanj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v3.4.7

2 findings
HIGH New obfuscated file: build/site/assets/index-y3oyBPN4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.6

2 findings
HIGH New obfuscated file: build/site/assets/index-y3oyBPN4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.5

2 findings
HIGH New obfuscated file: build/site/assets/index-y3oyBPN4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.4

2 findings
HIGH New obfuscated file: build/site/assets/index-BKM9P-Lm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.3

2 findings
HIGH New obfuscated file: build/site/assets/index-BKM9P-Lm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.2

2 findings
HIGH New obfuscated file: build/site/assets/index-y3oyBPN4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.1

2 findings
HIGH New obfuscated file: build/site/assets/index-y3oyBPN4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.4.0

2 findings
HIGH New obfuscated file: build/site/assets/index-D6Sm-vP3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.4

2 findings
HIGH New obfuscated file: build/site/assets/index-D6Sm-vP3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.3

2 findings
HIGH New obfuscated file: build/site/assets/index-D6Sm-vP3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.2

2 findings
HIGH New obfuscated file: build/site/assets/index-D6Sm-vP3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.1

2 findings
HIGH New obfuscated file: build/site/assets/index-D6Sm-vP3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.3.0

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.10

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.9

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.8

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.7

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.6

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.5

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.4

2 findings
HIGH New obfuscated file: build/site/assets/index-C5U_5Xge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.