@tanstack/devtools-vite
40
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
tannerlinsleyalemtuzlakkevinvandy
Keywords
devtools
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is an official TanStack sibling package, consistent with the removed-deps refactor. | ai | |
| dependencies | unvetted-dep:@tanstack/devtools-bundler-core | AI (dependencies): First-party TanStack package consolidating prior deps; not an unvetted third party. | ai | |
| source-diff | net-exec-file:src/virtual-console.test.ts | AI (source-diff): Test file using vitest mocks for fetch/EventSource; not real network or exec. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): new Function() in test file exercises generateConsolePipeCode; not a runtime concern. | ai | |
| provenance | publisher-changed | AI (provenance): Moved to GitHub Actions CI/CD publishing with SLSA provenance; legitimate for TanStack org. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known TanStack team members (tkdodo, kevinvandy, etc.). | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): kylemathews removal is part of normal TanStack team rotation. | ai | |
| dependencies | unvetted-dep:@tanstack/devtools-client | AI (dependencies): First-party TanStack sibling package; expected dependency for this devtools plugin. | ai | |
| dependencies | unvetted-dep:launch-editor | AI (dependencies): launch-editor is a well-known VS Code/editor opener used by many dev tools; stable dependency for this package. | ai | |
| dependencies | unvetted-dep:@tanstack/devtools-event-bus | AI (dependencies): First-party TanStack sibling package; expected dependency for this devtools plugin. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 0.8.2 | 4 / 1 | |
| 0.8.1 | 7 / 2 | |
| 0.8.0 | 7 / 2 | |
| 0.7.2 | 7 / 2 | |
| 0.7.1 | 7 / 2 | |
| 0.7.0 | 7 / 2 | |
| 0.6.1 | 10 / 5 | |
| 0.6.0 | 10 / 5 | |
| 0.5.5 | 10 / 5 | |
| 0.5.4 | 10 / 5 | |
| 0.5.3 | 10 / 5 | |
| 0.5.2 | 10 / 5 | |
| 0.5.1 | 10 / 5 | |
| 0.5.0 | 10 / 5 | |
| 0.4.1 | 10 / 5 | |
| 0.4.0 | 10 / 5 | |
| 0.3.12 | 10 / 5 | |
| 0.3.11 | 10 / 5 | |
| 0.3.10 | 10 / 5 | |
| 0.3.9 | 10 / 5 | |
| 0.3.8 | 9 / 4 | |
| 0.3.7 | 9 / 4 | |
| 0.3.6 | 9 / 4 | |
| 0.3.5 | 8 / 4 | |
| 0.3.4 | 8 / 4 | |
| 0.3.3 | 8 / 4 | |
| 0.3.2 | 8 / 4 | |
| 0.3.1 | 8 / 4 | |
| 0.3.0 | 8 / 4 | |
| 0.2.14 | 8 / 4 | |
| 0.2.13 | 8 / 4 | |
| 0.2.12 | 7 / 4 | |
| 0.2.11 | 7 / 4 | |
| 0.2.10 | 7 / 4 | |
| 0.2.9 | 7 / 4 | |
| 0.2.8 | 7 / 4 | |
| 0.2.6 | 7 / 4 | |
| 0.2.5 | 7 / 4 | |
| 0.2.4 | 7 / 3 | |
| 0.2.3 | 2 / 0 |
v0.8.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.