vike
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@universal-deploy/vite | AI (dependencies): First-party ecosystem dep from same maintainer group, not a security concern. | ai | |
| provenance | missing-githead | AI (provenance): Routine publish variance for this maintainer; no behavior indicating compromise. | ai | |
| provenance | no-provenance | AI (provenance): No CI/CD provenance historically; unchanged, not a regression. | ai | |
| source-diff | obfuscated-file:dist/esm/node/vite/shared/loggerNotProd/errorWithCodeSnippet/fixture-errors/errBabelReact.js | AI (source-diff): Same fixture error object pattern; ESM variant of the same benign file. | ai | |
| source-diff | obfuscated-file:dist/cjs/node/vite/shared/loggerNotProd/errorWithCodeSnippet/fixture-errors/errBabelReact.js | AI (source-diff): Long lines are fixture error objects with embedded source code strings, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/cjs/node/vite/shared/loggerNotProd/errorWithCodeSnippet/fixture-errors/errBabelSolid.js | AI (source-diff): Fixture error object with embedded source code strings; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm/node/vite/shared/loggerNotProd/errorWithCodeSnippet/fixture-errors/errBabelSolid.js | AI (source-diff): ESM variant of the same benign fixture error object. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established package with active maintainer; long gap likely reflects development cycle, not account takeover. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 45 new files consistent with a significant feature addition in a large framework; no obfuscation or malware indicators. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @babel/core and @babel/types are well-known, widely-used packages consistent with a build-tool refactor. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): Vike is an established framework intentionally named; not a typosquat of vite. | ai |
Versions (showing 100 of 109)
| Version | Deps | Published |
|---|---|---|
| 0.4.260 | 23 / 12 | |
| 0.4.259 | 23 / 12 | |
| 0.4.258 | 23 / 11 | |
| 0.4.257 | 23 / 11 | |
| 0.4.256 | 17 / 11 | |
| 0.4.255 | 17 / 11 | |
| 0.4.254 | 17 / 11 | |
| 0.4.253 | 18 / 11 | |
| 0.4.252 | 18 / 11 | |
| 0.4.251 | 18 / 11 | |
| 0.4.250 | 18 / 11 | |
| 0.4.249 | 17 / 10 | |
| 0.4.248 | 17 / 10 | |
| 0.4.247 | 17 / 10 | |
| 0.4.246 | 17 / 10 | |
| 0.4.245 | 17 / 10 | |
| 0.4.244 | 17 / 10 | |
| 0.4.243 | 17 / 10 | |
| 0.4.242 | 17 / 10 | |
| 0.4.241 | 17 / 10 | |
| 0.4.240 | 17 / 10 | |
| 0.4.239 | 17 / 10 | |
| 0.4.238 | 17 / 10 | |
| 0.4.237 | 17 / 10 | |
| 0.4.236 | 17 / 10 | |
| 0.4.235 | 17 / 13 | |
| 0.4.234 | 17 / 13 | |
| 0.4.233 | 17 / 13 | |
| 0.4.232 | 17 / 13 | |
| 0.4.231 | 17 / 13 | |
| 0.4.230 | 17 / 13 | |
| 0.4.229 | 17 / 13 | |
| 0.4.228 | 17 / 13 | |
| 0.4.227 | 16 / 13 | |
| 0.4.226 | 16 / 13 | |
| 0.4.225 | 16 / 13 | |
| 0.4.224 | 15 / 13 | |
| 0.4.223 | 14 / 12 | |
| 0.4.222 | 14 / 12 | |
| 0.4.221 | 14 / 12 | |
| 0.4.220 | 14 / 12 | |
| 0.4.219 | 14 / 12 | |
| 0.4.218 | 14 / 12 | |
| 0.4.217 | 14 / 12 | |
| 0.4.216 | 14 / 12 | |
| 0.4.215 | 14 / 12 | |
| 0.4.214 | 14 / 12 | |
| 0.4.213 | 13 / 12 | |
| 0.4.212 | 12 / 12 | |
| 0.4.211 | 12 / 12 | |
| 0.4.210 | 12 / 12 | |
| 0.4.209 | 12 / 12 | |
| 0.4.208 | 12 / 12 | |
| 0.4.207 | 12 / 12 | |
| 0.4.206 | 12 / 12 | |
| 0.4.205 | 12 / 12 | |
| 0.4.204 | 12 / 12 | |
| 0.4.203 | 12 / 12 | |
| 0.4.202 | 12 / 12 | |
| 0.4.201 | 12 / 12 | |
| 0.4.200 | 12 / 12 | |
| 0.4.199 | 13 / 20 | |
| 0.4.198 | 13 / 20 | |
| 0.4.197 | 13 / 20 | |
| 0.4.196 | 13 / 20 | |
| 0.4.195 | 13 / 19 | |
| 0.4.194 | 13 / 19 | |
| 0.4.193 | 13 / 19 | |
| 0.4.192 | 13 / 19 | |
| 0.4.191 | 13 / 19 | |
| 0.4.190 | 13 / 19 | |
| 0.4.189 | 13 / 19 | |
| 0.4.188 | 13 / 19 | |
| 0.4.187 | 13 / 19 | |
| 0.4.186 | 13 / 19 | |
| 0.4.185 | 13 / 19 | |
| 0.4.184 | 13 / 19 | |
| 0.4.183 | 13 / 19 | |
| 0.4.182 | 13 / 23 | |
| 0.4.181 | 13 / 23 | |
| 0.4.180 | 13 / 23 | |
| 0.4.179 | 13 / 23 | |
| 0.4.178 | 13 / 23 | |
| 0.4.177 | 13 / 23 | |
| 0.4.176 | 13 / 23 | |
| 0.4.175 | 13 / 23 | |
| 0.4.174 | 13 / 23 | |
| 0.4.173 | 12 / 23 | |
| 0.4.172 | 12 / 23 | |
| 0.4.161 | 12 / 21 | |
| 0.4.160 | 12 / 21 | |
| 0.4.159 | 12 / 21 | |
| 0.4.158 | 12 / 21 | |
| 0.4.157 | 12 / 21 | |
| 0.4.156 | 12 / 21 | |
| 0.4.155 | 12 / 21 | |
| 0.4.154 | 12 / 21 | |
| 0.4.153 | 12 / 21 | |
| 0.4.152 | 12 / 21 | |
| 0.4.151 | 12 / 9 |
v0.4.229
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.228
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.227
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.226
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.225
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.224
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.223
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.222
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.221
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.220
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.219
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.218
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.217
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.216
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.215
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.214
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.213
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.212
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.211
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.210
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.209
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.208
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.207
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.206
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.205
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.204
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.203
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.202
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.201
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.200
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.199
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.198
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.197
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.196
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brillout.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.195
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.194
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.193
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.192
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.191
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.190
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.189
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.188
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.187
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.186
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.185
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.184
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.183
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.182
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.181
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.180
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.179
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.178
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.177
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.176
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.175
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.174
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.173
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.172
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.161
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.160
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.159
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.158
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.157
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.156
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.155
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.154
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.153
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.152
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.4.151
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.