react-devtools-inline
Embed react-devtools within a website
2
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
brianvaughnryancatjstejadaxiaobumondaychenlunaruanhoxyq
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/hookNames.js | AI (source-diff): Standard webpack bundle for React DevTools hook name parsing; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/hookNames.js | AI (source-diff): Webpack bundle with worker RPC and URL handling; no malicious network+exec pattern. | ai | |
| source-diff | obfuscated-file:dist/importFile.worker.worker.js | AI (source-diff): Standard webpack bundle for Chrome CPU profile import; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/importFile.worker.worker.js | AI (source-diff): Webpack bundle for profiler file import; no malicious network+exec pattern. | ai | |
| source-diff | obfuscated-file:dist/parseSourceAndMetadata.worker.worker.js | AI (source-diff): Standard webpack bundle for source map parsing; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/parseSourceAndMetadata.worker.worker.js | AI (source-diff): Webpack bundle with URL parsing for source maps; no malicious network+exec pattern. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects new worker bundles for hook names and file import features in major version bump. | ai | |
| phantom-deps | phantom-dep:source-map-js | AI (phantom-deps): Used as webpack bundled dependency for source map resolution; stable false positive. | ai | |
| phantom-deps | phantom-dep:@jridgewell/sourcemap-codec | AI (phantom-deps): Used as webpack bundled dependency for source map codec; stable false positive. | ai |