@visulima/vite-overlay
Improved vite overlay
15
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
prisis
Keywords
error-handlingerror-overlayoverlayreactsource-mapsveltetypescriptvisulimavitevite-error-overlayvite-overlayvite-pluginvue
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@shikijs/cli | AI (dependencies): @shikijs/cli is part of the shiki ecosystem already used by this package; addition is coherent and low-risk. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is @shikijs/cli, a known shiki sub-package; not a suspicious addition. | ai | |
| provenance | slsa-provenance | AI (provenance): Package consistently published with SLSA provenance via CI/CD; stable signal for this package. | ai | |
| phantom-deps | phantom-dep:@shikijs/cli | AI (phantom-deps): Declared runtime dep used via config/indirect reference; phantom-dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:fastest-levenshtein | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic fires on config-file references, not a real concern. | ai | |
| phantom-deps | phantom-dep:@jridgewell/trace-mapping | AI (phantom-deps): Declared runtime dep for source-map tracing; phantom-dep heuristic is a false positive. | ai |