← Home

@visulima/dev-toolbar

OIDC trusted publishing setup package for @visulima/dev-toolbar

2
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

prisis

Keywords

dev-toolbarvisulima

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/apps/inspector/index.js AI (source-diff): Bundled Vite/preact output, not true obfuscation. ai
source-diff obfuscated-file:dist/toolbar/index.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/packem_chunks/inject-source.js AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/packem_shared/sharedToolbarStylesheet-DCndH0A0.js AI (source-diff): Bundled CSS/JS chunk. ai
source-diff obfuscated-file:dist/mcp/server.js AI (source-diff): Bundled MCP server output. ai
provenance publisher-changed AI (provenance): CI/CD provenance improvement, not a compromise indicator. ai
phantom-deps phantom-dep:@babel/parser AI (phantom-deps): Framework-convention dependency. ai
phantom-deps phantom-dep:@babel/traverse AI (phantom-deps): Framework-convention dependency. ai
phantom-deps phantom-dep:@floating-ui/dom AI (phantom-deps): Referenced via config, not direct import. ai

Versions (showing 2 of 2)

Version Deps Published
1.0.0 6 / 0
0.0.1 0 / 0

v1.0.0

19 findings
HIGH Publisher changed: prisis → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/packem_shared/createServerRPCContext-2MNcj-v3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/a11y/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/annotations/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/assets/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/inspector/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/module-graph/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/performance/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/seo/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/settings/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/tailwind/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/timeline/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/apps/vite-config/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/toolbar/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_chunks/inject-source.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/Select-CwD-d0pi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/mcp/server.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/sharedToolbarStylesheet-DCndH0A0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.