@vue/devtools-electron
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:client/index-CMQqea10.js | AI (source-diff): Bundled webpack/vite client output for devtools UI, not obfuscation. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established official Vue org package, sparse README is not spam indicator here. | ai | |
| source-diff | net-exec-file:client/index-CMQqea10.js | AI (source-diff): Bundled browser client code; no evidence of malicious exfil/exec. | ai | |
| source-diff | net-exec-file:client/graph-C2BnI7DY.js | AI (source-diff): vis-network library bundle, dual-use pattern only. | ai | |
| source-diff | obfuscated-file:client/graph-DIj0toq6.js | AI (source-diff): Vite-bundled vis-network + devtools graph UI; minified but legitimate, with copyright headers intact. | ai | |
| source-diff | net-exec-file:client/graph-DIj0toq6.js | AI (source-diff): Network/exec pattern is vis-network visualization library code, not dropper behavior. | ai | |
| source-diff | obfuscated-file:client/index-ZSbomiEa.js | AI (source-diff): Vite-bundled devtools client entry; minified standard Vue/devtools code. | ai | |
| source-diff | obfuscated-file:client/overview-CU6NZ0ft.js | AI (source-diff): Vite-bundled devtools overview UI; minified Vue component code. | ai | |
| source-diff | net-exec-file:client/index-ZSbomiEa.js | AI (source-diff): Network/exec pattern is standard devtools client code (socket.io, browser detection), not malware. | ai | |
| source-diff | obfuscated-file:client/typescript-DKfvlBCw.js | AI (source-diff): TypeScript syntax-highlighting grammar bundle; legitimate minified JSON. | ai | |
| source-diff | obfuscated-file:client/vue-ChaKAHzo.js | AI (source-diff): Vue syntax-highlighting grammar bundle; legitimate minified JSON. | ai | |
| source-diff | obfuscated-file:client/vue-html-Hg1VsDox.js | AI (source-diff): Vue HTML syntax-highlighting grammar bundle; legitimate minified JSON. | ai | |
| source-diff | obfuscated-file:client/yaml-DcQhbMrL.js | AI (source-diff): YAML syntax-highlighting grammar bundle; legitimate minified JSON. | ai | |
| phantom-deps | phantom-dep:ip | AI (phantom-deps): ip is used for network address resolution in Electron CLI; indirect usage is expected. | ai | |
| source-diff | obfuscated-file:client/shellscript-DmhSIIKI.js | AI (source-diff): Shell syntax-highlighting grammar bundle; legitimate minified JSON. | ai | |
| source-diff | obfuscated-file:client/css-BnL1064W.js | AI (source-diff): Vite-bundled syntax-highlighting grammar; legitimate minified JSON data. | ai | |
| source-diff | obfuscated-file:client/graph-CnuUnDS4.js | AI (source-diff): vis-network library bundle with Apache/MIT license header; expected devtools dependency. | ai | |
| source-diff | net-exec-file:client/graph-CnuUnDS4.js | AI (source-diff): vis-network uses Function() for globalThis detection; standard pattern in bundled libs. | ai | |
| source-diff | obfuscated-file:client/html-Iy9EJBkL.js | AI (source-diff): Vite-bundled HTML syntax-highlighting grammar; legitimate minified JSON. | ai | |
| source-diff | obfuscated-file:client/index-C5Yz0nRg.js | AI (source-diff): Main Vite bundle for Vue devtools client UI; standard minified output. | ai | |
| source-diff | net-exec-file:client/index-C5Yz0nRg.js | AI (source-diff): Dynamic code execution patterns are standard in bundled Vue/devtools UI code. | ai | |
| source-diff | obfuscated-file:client/javascript-CXHlxgtu.js | AI (source-diff): Vite-bundled JS syntax-highlighting grammar; legitimate minified JSON. | ai | |
| source-diff | obfuscated-file:client/overview-Bq2BQf6x.js | AI (source-diff): Vue devtools overview UI component bundle; legitimate minified output. | ai | |
| source-diff | obfuscated-file:client/graph-B_obzJ2J.js | AI (source-diff): Vite-bundled vis-network + Vue devtools client code; minified but not obfuscated, legitimate build artifact. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established package with 92 versions; SLSA provenance confirms CI/CD publish from official vuejs org. | ai | |
| source-diff | encoded-string-file:dist/devtools.js | AI (source-diff): Long strings are CSS/PostCSS processing code (unicode escape handling), not encoded payloads. | ai | |
| source-diff | obfuscated-file:client/overview-DRJ5Ct4r.js | AI (source-diff): Vite-bundled Vue component with inline SVG; standard minified build output. | ai | |
| source-diff | net-exec-file:client/index-DTQ12DuY.js | AI (source-diff): Network calls are devtools socket.io communication; no malicious pattern in sampled code. | ai | |
| source-diff | obfuscated-file:client/index-DTQ12DuY.js | AI (source-diff): Vite-bundled devtools client entry; minified build artifact from official vuejs/devtools repo. | ai | |
| source-diff | net-exec-file:client/graph-B_obzJ2J.js | AI (source-diff): Network calls are vis-network/devtools UI functionality; no dropper pattern in sampled code. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 8.1.5 | 8 / 4 | |
| 8.1.4 | 8 / 4 | |
| 8.1.3 | 8 / 4 | |
| 8.1.2 | 8 / 4 | |
| 8.0.7 | 8 / 4 | |
| 8.0.6 | 8 / 4 | |
| 7.7.10 | 10 / 4 |
v8.1.5
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.