← Home

nuxi

Nuxt CLI

24
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

danielroe

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed-stale AI (provenance): Long-standing Nuxt core team maintainer transfer, stable for years. ai
source-diff obfuscated-file:dist/shared/nuxi.70a5067d.mjs AI (source-diff): Bundled/minified rollup output, not true obfuscation; no malicious behavior present. ai
bogus-package bogus-package AI (bogus-package): False positive for well-known Nuxt CLI tool. ai
provenance missing-githead AI (provenance): CI publish with SLSA attestation; gitHead absence is a build-env artifact, not tampering. ai
source-diff obfuscated-file:dist/dist-DwEdCcyS.mjs AI (source-diff): Readable rollup/tsdown bundle output; not obfuscation. ai
source-diff obfuscated-file:dist/logger-DgyoxKia.mjs AI (source-diff): Bundled logger/consola output. ai
source-diff obfuscated-file:dist/jiti-_DRHsfPn.mjs AI (source-diff): Bundled jiti dependency output. ai
source-diff obfuscated-file:dist/jiti-CJ4dNg12.mjs AI (source-diff): Bundled jiti vendor chunk; webpack/build output, not obfuscation. ai
source-diff obfuscated-file:dist/prompt-CmW1C2pX.mjs AI (source-diff): Bundled consola prompt chunk; build output. ai
source-diff obfuscated-file:dist/logger-TGEXLs5w.mjs AI (source-diff): Bundled picocolors/consola chunk; build output. ai
source-diff obfuscated-file:dist/dist-CGV6T3ee.mjs AI (source-diff): Bundled rollup/tsdown dist output, readable vendor chunks; long lines are minification not obfuscation. ai
source-diff obfuscated-file:dist/jiti-wMqj2WBP.mjs AI (source-diff): Bundled jiti webpack output; readable vendored code. ai
source-diff obfuscated-file:dist/logger-C9cMUJ6F.mjs AI (source-diff): Bundled picocolors/consola output; minified not obfuscated. ai
source-diff obfuscated-file:dist/dist-DoMAwH4O.mjs AI (source-diff): Bundled tsdown output of vendored deps; long lines are minification, not obfuscation. ai
source-diff net-exec-file:dist/dist-CPB2ABJ-.mjs AI (source-diff): Bundled magicast/babel-parser; no hostile network+exec pattern. ai
source-diff obfuscated-file:dist/dist-BA2CLoOP.mjs AI (source-diff): Bundled build output from tsdown/rollup; readable source with region comments, not obfuscation. ai
source-diff obfuscated-file:dist/jiti-sm19nk94.mjs AI (source-diff): Bundled jiti dependency; webpack-style module wrapper, not obfuscation. ai
source-diff obfuscated-file:dist/prompt-Dq937e-Z.mjs AI (source-diff): Bundled consola prompt code; clearly readable, not obfuscation. ai
maintainer-change maintainer-takeover AI (maintainer-change): danielroe is the Nuxt framework lead; legitimate maintainer transition from nuxtbot. ai
maintainer-change maintainer-added AI (maintainer-change): danielroe is the known Nuxt lead maintainer. ai
maintainer-change maintainer-removed AI (maintainer-change): nuxtbot replaced by danielroe; expected org transition. ai
source-diff obfuscated-file:dist/dist-Bvi-he5H.mjs AI (source-diff): Bundled consola dependency; readable build output from tsdown, stable pattern. ai
source-diff large-new-source-files AI (source-diff): Build output chunks rotate filenames each release; stable pattern for this package. ai
source-diff net-exec-file:dist/dist-VQPAbvb_.mjs AI (source-diff): Bundled magicast/babel-parser; CLI tool legitimately uses network+exec. ai
source-diff obfuscated-file:dist/prompt-DcsahOCn.mjs AI (source-diff): Bundled consola prompt chunk; standard build artifact. ai
source-diff obfuscated-file:dist/jiti-BfsRAE30.mjs AI (source-diff): Bundled jiti dependency; standard build artifact. ai
source-diff net-exec-file:dist/dist-xdvxZpBN.mjs AI (source-diff): Contains bundled magicast/babel-parser; dynamic code execution is AST parsing, not dropper behavior. ai
source-diff obfuscated-file:dist/logger-CyBffPrB.mjs AI (source-diff): Bundled logger/terminal-width utilities; long lines are lookup tables, not obfuscation. ai
source-diff obfuscated-file:dist/jiti-DIDkIovA.mjs AI (source-diff): Bundled jiti (webpack-compiled CJS loader); minification is expected and matches declared devDependency [email protected]. ai
source-diff obfuscated-file:dist/dist-BP14MYpv.mjs AI (source-diff): Minified bundle of consola/logging deps; standard for nuxi CLI dist output. ai
source-diff encoded-string-file:dist/chunks/init.mjs AI (source-diff): Long string is minified proxy/fetch library code bundled from legitimate upstream deps, not obfuscation. ai
publish-pattern dormant-publish AI (publish-pattern): SLSA provenance attestation confirms legitimate CI/CD publish; dormancy is not indicative of takeover here. ai
source-diff encoded-string-file:dist/chunks/dev.mjs AI (source-diff): Long base64 string is llhttp WASM binary embedded as standard bundled dependency, not a malicious payload. ai
typosquat typosquat.levenshtein:next AI (typosquat): nuxi is the Nuxt CLI; 2-edit distance from 'next' is coincidental, not impersonation. ai
typosquat typosquat.levenshtein:nuxt AI (typosquat): nuxi IS the official Nuxt CLI; the nuxt/cli repo and bin aliases confirm this is not a typosquat. ai

Versions (showing 24 of 24)

Version Deps Published
3.36.1 0 / 45
3.36.0 0 / 45
3.35.2 0 / 45
3.35.1 0 / 45
3.35.0 0 / 45
3.34.0 0 / 45
3.33.1 0 / 46
3.33.0 0 / 46
3.32.0 0 / 45
3.31.3 0 / 45
3.31.2 0 / 45
3.31.1 0 / 45
3.31.0 0 / 45
3.30.0 0 / 41
3.29.1 0 / 40
3.29.0 0 / 40
3.2.3 1 / 28
3.2.2 1 / 28
3.2.1 1 / 28
3.2.0 1 / 28
3.1.2 1 / 28
3.1.1 1 / 28
3.1.0 1 / 28
3.0.0 1 / 28

v3.36.1

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.34.0

4 findings
HIGH New obfuscated file: dist/dist-DwEdCcyS.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/jiti-_DRHsfPn.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/logger-DgyoxKia.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.33.1

5 findings
HIGH New obfuscated file: dist/dist-CGV6T3ee.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/jiti-CJ4dNg12.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/logger-TGEXLs5w.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/prompt-CmW1C2pX.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.33.0

4 findings
HIGH New obfuscated file: dist/dist-DoMAwH4O.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/jiti-wMqj2WBP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/logger-C9cMUJ6F.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.3

3 findings
HIGH New obfuscated file: dist/shared/nuxi.70a5067d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: pi0 → danielroe (on 2023-02-28, unremoved on npm for 1243d) provenance

This version was published by a different npm account (danielroe) than the most recent previously approved version (pi0) on 2023-02-28. It has since remained available on npm for 1243 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.2

3 findings
HIGH New obfuscated file: dist/shared/nuxi.70a5067d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: pi0 → danielroe (on 2023-02-17, unremoved on npm for 1253d) provenance

This version was published by a different npm account (danielroe) than the most recent previously approved version (pi0) on 2023-02-17. It has since remained available on npm for 1253 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.1

3 findings
HIGH New obfuscated file: dist/shared/nuxi.70a5067d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: pi0 → danielroe (on 2023-02-17, unremoved on npm for 1254d) provenance

This version was published by a different npm account (danielroe) than the most recent previously approved version (pi0) on 2023-02-17. It has since remained available on npm for 1254 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.2.0

3 findings
HIGH New obfuscated file: dist/shared/nuxi.70a5067d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: pi0 → danielroe (on 2023-02-09, unremoved on npm for 1262d) provenance

This version was published by a different npm account (danielroe) than the most recent previously approved version (pi0) on 2023-02-09. It has since remained available on npm for 1262 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.2

3 findings
HIGH New obfuscated file: dist/shared/nuxi.70a5067d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: pi0 → danielroe (on 2023-02-03, unremoved on npm for 1268d) provenance

This version was published by a different npm account (danielroe) than the most recent previously approved version (pi0) on 2023-02-03. It has since remained available on npm for 1268 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.1

3 findings
HIGH New obfuscated file: dist/shared/nuxi.70a5067d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: pi0 → danielroe (on 2023-01-25, unremoved on npm for 1276d) provenance

This version was published by a different npm account (danielroe) than the most recent previously approved version (pi0) on 2023-01-25. It has since remained available on npm for 1276 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

3 findings
HIGH New obfuscated file: dist/shared/nuxi.70a5067d.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: pi0 → danielroe (on 2023-01-24, unremoved on npm for 1277d) provenance

This version was published by a different npm account (danielroe) than the most recent previously approved version (pi0) on 2023-01-24. It has since remained available on npm for 1277 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.