@vettvangur/vite
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/vite.config.js | AI (source-diff): Base64 WASM blob from bundled undici/llhttp dependency, not a hidden payload. | ai | |
| source-diff | obfuscated-file:dist/cli/dev.js | AI (source-diff): Bundled vite CLI code, not true obfuscation; long lines are minified deps. | ai | |
| source-diff | obfuscated-file:dist/chunks/typescript.js | AI (source-diff): Bundled TypeScript compiler source, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/vite.config.js | AI (source-diff): Vite build config bundle; node builtins used for dev-server tooling, not exfil. | ai | |
| source-diff | net-exec-file:dist/chunks/typescript.js | AI (source-diff): TypeScript compiler bundle naturally imports fs/os/inspector; no malicious net+exec behavior shown. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Proprietary org package; missing description is consistent across versions and not a malware indicator here. | ai | |
| typosquat | typosquat.levenshtein:vitest | AI (typosquat): Scoped @vettvangur namespace makes typosquat implausible; this is an org-internal Vite wrapper, not impersonating vitest. | ai | |
| phantom-deps | phantom-dep:vite-tsconfig-paths | AI (phantom-deps): Bundled CLI tool; deps may be consumed at runtime via bundled dist rather than direct import. | ai | |
| phantom-deps | phantom-dep:vite-plugin-mkcert | AI (phantom-deps): Bundled CLI tool; deps may be consumed at runtime via bundled dist rather than direct import. | ai | |
| phantom-deps | phantom-dep:serve-static | AI (phantom-deps): Bundled CLI tool; deps may be consumed at runtime via bundled dist rather than direct import. | ai | |
| phantom-deps | phantom-dep:boxen | AI (phantom-deps): Bundled CLI tool; deps may be consumed at runtime via bundled dist rather than direct import. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Proprietary internal tooling; sparse metadata is expected for org-internal packages not intended for public discovery. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 1.0.84 | 6 / 10 | |
| 1.0.82 | 6 / 10 | |
| 1.0.81 | 6 / 10 | |
| 1.0.80 | 6 / 10 | |
| 1.0.79 | 6 / 10 | |
| 1.0.76 | 6 / 10 | |
| 1.0.71 | 6 / 10 | |
| 1.0.70 | 6 / 10 | |
| 1.0.69 | 6 / 10 | |
| 1.0.68 | 6 / 10 | |
| 1.0.66 | 6 / 10 | |
| 1.0.28 | 5 / 9 |
v1.0.84
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.76
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 9.6MB bundled file with network+exec patterns; no repo to audit against.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Reject — re-review on republish] (prior reject: AI (source-diff): New large bundled file with network+exec patterns and no source repo to verify legitimacy.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.71
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 9.6MB bundled file with network+exec patterns; no repo to audit against.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Reject — re-review on republish] (prior reject: AI (source-diff): New large bundled file with network+exec patterns and no source repo to verify legitimacy.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.70
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 9.6MB bundled file with network+exec patterns; no repo to audit against.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Reject — re-review on republish] (prior reject: AI (source-diff): New large bundled file with network+exec patterns and no source repo to verify legitimacy.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.69
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 9.6MB bundled file with network+exec patterns; no repo to audit against.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Reject — re-review on republish] (prior reject: AI (source-diff): New large bundled file with network+exec patterns and no source repo to verify legitimacy.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.68
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 9.6MB bundled file with network+exec patterns; no repo to audit against.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Reject — re-review on republish] (prior reject: AI (source-diff): New large bundled file with network+exec patterns and no source repo to verify legitimacy.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.66
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 9.6MB bundled file with network+exec patterns; no repo to audit against.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Reject — re-review on republish] (prior reject: AI (source-diff): New large bundled file with network+exec patterns and no source repo to verify legitimacy.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.