← Home

@preact/preset-vite

33
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

preactjsdevelopitmarvinhagemeisterdrewiggjdecroockrschristian

Keywords

preactvitevite-pluginvite-presetpreset

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:resolve AI (phantom-deps): resolve used programmatically in build logic, not import-scannable. ai
phantom-deps phantom-dep:@babel/plugin-transform-react-jsx AI (phantom-deps): Framework-scoped babel plugin loaded by convention. ai
phantom-deps phantom-dep:@babel/plugin-transform-react-jsx-development AI (phantom-deps): Framework-scoped babel plugin loaded by convention. ai
maintainer-change maintainer-added AI (maintainer-change): Known org maintainer roster churn, not suspicious for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Known org maintainer roster churn, not suspicious for this package. ai
phantom-deps phantom-dep:babel-plugin-transform-hook-names AI (phantom-deps): Used via babel config for hook name transforms, not direct import; known Preact tooling. ai

Versions (showing 33 of 33)

Version Deps Published
2.10.6 10 / 16
2.10.5 10 / 15
2.10.4 10 / 15
2.10.3 8 / 15
2.10.2 8 / 18
2.10.1 8 / 18
2.10.0 8 / 18
2.9.4 12 / 18
2.9.3 12 / 18
2.9.2 12 / 18
2.9.1 12 / 18
2.9.0 13 / 19
2.8.3 13 / 19
2.8.2 12 / 19
2.8.1 10 / 17
2.8.0 11 / 17
2.7.0 8 / 13
2.6.0 8 / 13
2.5.0 8 / 13
2.4.0 8 / 13
2.3.1 8 / 13
2.3.0 8 / 13
2.2.0 8 / 13
2.1.7 7 / 13
2.1.6 7 / 13
2.1.5 6 / 12
2.1.4 6 / 12
2.1.3 4 / 11
2.1.2 4 / 11
2.1.1 4 / 11
2.1.0 4 / 11
2.0.1 3 / 9
2.0.0 3 / 9

v2.10.6

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: rschristian → GitHub Actions (on 2026-07-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (rschristian) on 2026-07-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.10.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinhagemeister → rschristian (on 2025-02-02, known maintainer) provenance

This version was published by a different npm account (rschristian) than the most recent previously approved version (marvinhagemeister) on 2025-02-02, but rschristian is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.2

2 findings
MEDIUM Publisher changed: marvinhagemeister → rschristian (on 2024-03-15, unremoved on npm for 858d) provenance

This version was published by a different npm account (rschristian) than the most recent previously approved version (marvinhagemeister) on 2024-03-15. It has since remained available on npm for 858 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.1

2 findings
MEDIUM Publisher changed: marvinhagemeister → rschristian (on 2024-01-02, unremoved on npm for 931d) provenance

This version was published by a different npm account (rschristian) than the most recent previously approved version (marvinhagemeister) on 2024-01-02. It has since remained available on npm for 931 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.8.0

2 findings
MEDIUM Publisher changed: marvinhagemeister → rschristian (on 2024-01-02, unremoved on npm for 931d) provenance

This version was published by a different npm account (rschristian) than the most recent previously approved version (marvinhagemeister) on 2024-01-02. It has since remained available on npm for 931 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinhagemeister → jdecroock (on 2023-11-17, known maintainer) provenance

This version was published by a different npm account (jdecroock) than the most recent previously approved version (marvinhagemeister) on 2023-11-17, but jdecroock is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.6.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinhagemeister → jdecroock (on 2023-10-14, known maintainer) provenance

This version was published by a different npm account (jdecroock) than the most recent previously approved version (marvinhagemeister) on 2023-10-14, but jdecroock is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.5.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinhagemeister → jdecroock (on 2022-12-14, known maintainer) provenance

This version was published by a different npm account (jdecroock) than the most recent previously approved version (marvinhagemeister) on 2022-12-14, but jdecroock is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jdecroock → marvinhagemeister (on 2022-03-29, known maintainer) provenance

This version was published by a different npm account (marvinhagemeister) than the most recent previously approved version (jdecroock) on 2022-03-29, but marvinhagemeister is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinhagemeister → jdecroock (on 2021-12-23, known maintainer) provenance

This version was published by a different npm account (jdecroock) than the most recent previously approved version (marvinhagemeister) on 2021-12-23, but jdecroock is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.