nuxt-graphql-middleware
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/_nuxt/DKGPmQRi.js | AI (source-diff): Standard Vite/Nuxt minified client bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CKZE-Gmz.js | AI (source-diff): Standard Vite/Nuxt minified client bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/DPP_zJIh.js | AI (source-diff): Standard Vite/Nuxt minified client bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CLvFsrJf.js | AI (source-diff): Standard Vite/Nuxt minified client bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/gyQx9VSj.js | AI (source-diff): Standard Vite-bundled Nuxt DevTools client UI output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/C9p-Va5c.js | AI (source-diff): Standard Vite-bundled Nuxt DevTools client UI output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/Bkyil6hz.js | AI (source-diff): Standard Vite-bundled Nuxt DevTools client UI output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BPB7Y782.js | AI (source-diff): Standard Vite-bundled Nuxt DevTools client UI output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CghSORGW.js | AI (source-diff): Standard Vite-minified Nuxt devtools UI component; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/4Fsya3Lb.js | AI (source-diff): Standard Vite-minified Nuxt client bundle output; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BKIQXJNq.js | AI (source-diff): Standard Vite-minified Nuxt error page component; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/BMPkTe12.js | AI (source-diff): Standard Vite-minified Vue 3 runtime bundle; not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:minisearch | AI (phantom-deps): minisearch is a declared runtime dep used in devtools search; phantom-dep heuristic false positive. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CyxO-88q.js | AI (source-diff): Vite-minified Nuxt error-500 page component; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/CrwW1KlQ.js | AI (source-diff): Vite-minified devtools UI component bundle; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/C6_BMIRJ.js | AI (source-diff): Vite-minified Nuxt chunk with NuxtLink and router code; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/client/_nuxt/B-BZSpkz.js | AI (source-diff): Standard Vite-minified Nuxt client bundle; samples show Vue 3 runtime code, not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:@clack/prompts | AI (phantom-deps): @clack/prompts is a declared runtime dep used in CLI/build tooling context; phantom-dep heuristic fires but it's legitimately bundled. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 5.4.0 | 12 / 39 | |
| 5.3.2 | 12 / 39 | |
| 5.3.1 | 12 / 39 | |
| 5.3.0 | 12 / 39 | |
| 5.2.3 | 8 / 32 | |
| 5.2.2 | 8 / 31 | |
| 5.2.1 | 8 / 31 | |
| 5.2.0 | 8 / 29 | |
| 5.1.1 | 8 / 29 | |
| 5.1.0 | 8 / 29 |
v5.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.2.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.