← Home

@vue/devtools-electron

7
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

webfansplz

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:client/index-CMQqea10.js AI (source-diff): Bundled webpack/vite client output for devtools UI, not obfuscation. ai
bogus-package bogus-package AI (bogus-package): Established official Vue org package, sparse README is not spam indicator here. ai
source-diff net-exec-file:client/index-CMQqea10.js AI (source-diff): Bundled browser client code; no evidence of malicious exfil/exec. ai
source-diff net-exec-file:client/graph-C2BnI7DY.js AI (source-diff): vis-network library bundle, dual-use pattern only. ai
source-diff obfuscated-file:client/graph-DIj0toq6.js AI (source-diff): Vite-bundled vis-network + devtools graph UI; minified but legitimate, with copyright headers intact. ai
source-diff net-exec-file:client/graph-DIj0toq6.js AI (source-diff): Network/exec pattern is vis-network visualization library code, not dropper behavior. ai
source-diff obfuscated-file:client/index-ZSbomiEa.js AI (source-diff): Vite-bundled devtools client entry; minified standard Vue/devtools code. ai
source-diff obfuscated-file:client/overview-CU6NZ0ft.js AI (source-diff): Vite-bundled devtools overview UI; minified Vue component code. ai
source-diff net-exec-file:client/index-ZSbomiEa.js AI (source-diff): Network/exec pattern is standard devtools client code (socket.io, browser detection), not malware. ai
source-diff obfuscated-file:client/typescript-DKfvlBCw.js AI (source-diff): TypeScript syntax-highlighting grammar bundle; legitimate minified JSON. ai
source-diff obfuscated-file:client/vue-ChaKAHzo.js AI (source-diff): Vue syntax-highlighting grammar bundle; legitimate minified JSON. ai
source-diff obfuscated-file:client/vue-html-Hg1VsDox.js AI (source-diff): Vue HTML syntax-highlighting grammar bundle; legitimate minified JSON. ai
source-diff obfuscated-file:client/yaml-DcQhbMrL.js AI (source-diff): YAML syntax-highlighting grammar bundle; legitimate minified JSON. ai
phantom-deps phantom-dep:ip AI (phantom-deps): ip is used for network address resolution in Electron CLI; indirect usage is expected. ai
source-diff obfuscated-file:client/shellscript-DmhSIIKI.js AI (source-diff): Shell syntax-highlighting grammar bundle; legitimate minified JSON. ai
source-diff obfuscated-file:client/css-BnL1064W.js AI (source-diff): Vite-bundled syntax-highlighting grammar; legitimate minified JSON data. ai
source-diff obfuscated-file:client/graph-CnuUnDS4.js AI (source-diff): vis-network library bundle with Apache/MIT license header; expected devtools dependency. ai
source-diff net-exec-file:client/graph-CnuUnDS4.js AI (source-diff): vis-network uses Function() for globalThis detection; standard pattern in bundled libs. ai
source-diff obfuscated-file:client/html-Iy9EJBkL.js AI (source-diff): Vite-bundled HTML syntax-highlighting grammar; legitimate minified JSON. ai
source-diff obfuscated-file:client/index-C5Yz0nRg.js AI (source-diff): Main Vite bundle for Vue devtools client UI; standard minified output. ai
source-diff net-exec-file:client/index-C5Yz0nRg.js AI (source-diff): Dynamic code execution patterns are standard in bundled Vue/devtools UI code. ai
source-diff obfuscated-file:client/javascript-CXHlxgtu.js AI (source-diff): Vite-bundled JS syntax-highlighting grammar; legitimate minified JSON. ai
source-diff obfuscated-file:client/overview-Bq2BQf6x.js AI (source-diff): Vue devtools overview UI component bundle; legitimate minified output. ai
source-diff obfuscated-file:client/graph-B_obzJ2J.js AI (source-diff): Vite-bundled vis-network + Vue devtools client code; minified but not obfuscated, legitimate build artifact. ai
publish-pattern dormant-publish AI (publish-pattern): Established package with 92 versions; SLSA provenance confirms CI/CD publish from official vuejs org. ai
source-diff encoded-string-file:dist/devtools.js AI (source-diff): Long strings are CSS/PostCSS processing code (unicode escape handling), not encoded payloads. ai
source-diff obfuscated-file:client/overview-DRJ5Ct4r.js AI (source-diff): Vite-bundled Vue component with inline SVG; standard minified build output. ai
source-diff net-exec-file:client/index-DTQ12DuY.js AI (source-diff): Network calls are devtools socket.io communication; no malicious pattern in sampled code. ai
source-diff obfuscated-file:client/index-DTQ12DuY.js AI (source-diff): Vite-bundled devtools client entry; minified build artifact from official vuejs/devtools repo. ai
source-diff net-exec-file:client/graph-B_obzJ2J.js AI (source-diff): Network calls are vis-network/devtools UI functionality; no dropper pattern in sampled code. ai

Versions (showing 7 of 7)

Version Deps Published
8.1.5 8 / 4
8.1.4 8 / 4
8.1.3 8 / 4
8.1.2 8 / 4
8.0.7 8 / 4
8.0.6 8 / 4
7.7.10 10 / 4

v8.1.5

14 findings
HIGH New obfuscated file: client/css-CECN5uSL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/graph-C2BnI7DY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: client/graph-C2BnI7DY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: client/html-7XVNRwN7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/index-CMQqea10.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: client/index-CMQqea10.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: client/javascript-Dp1Jmi5H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/overview-B20PsVLJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/shellscript-InADTalH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/typescript-mg6ATTE8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/vue-BEZF_Tsk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/vue-html-CBbEFYtW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/yaml-DaO7k5B1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.0.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.