vitepress
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/node/chunk-L6-oDwDi.js | AI (source-diff): Rollup-bundled node build chunk for an SSG; net+exec APIs are expected and non-malicious. | ai | |
| source-diff | obfuscated-file:dist/node/serve-Bvg4Nr_L.js | AI (source-diff): Rollup/esbuild bundled dev-server output, not obfuscation; regenerated with hashed name each release. | ai | |
| source-diff | net-exec-file:dist/node/serve-Bvg4Nr_L.js | AI (source-diff): Bundled Vite dev server; http+child_process are expected for an SSG server. | ai | |
| source-diff | net-exec-file:dist/node/serve-BwR5EPUJ.js | AI (source-diff): Dev-server bundle legitimately uses http + child_process; core function of an SSG. | ai | |
| source-diff | obfuscated-file:dist/node/serve-BwR5EPUJ.js | AI (source-diff): Rollup-bundled dist output for the dev server; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/node/chunk-BGE1nmDJ.js | AI (source-diff): Rolled-up SSG build bundle; network+exec APIs are inherent to vitepress node runtime, not a dropper. | ai | |
| source-diff | net-exec-file:dist/node/chunk-D0czDMtb.js | AI (source-diff): Bundled node CLI chunk; network+exec are legit dev-server/build APIs for this SSG. | ai | |
| source-diff | net-exec-file:dist/node/serve-oY-f4fXJ.js | AI (source-diff): SSG dev/preview server legitimately uses http + child_process; no hostile target. | ai | |
| source-diff | obfuscated-file:dist/node/serve-oY-f4fXJ.js | AI (source-diff): Rollup-bundled node build output; minified not obfuscated, expected per build:node script. | ai | |
| source-diff | net-exec-file:dist/node/serve-CEEKiiuH.js | AI (source-diff): Dev-server bundle legitimately uses http+child_process via vite; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/node/serve-CEEKiiuH.js | AI (source-diff): Rollup-bundled dev-server output; minified not obfuscated, stable per release. | ai | |
| source-diff | net-exec-file:dist/node/chunk-BuJ66qxQ.js | AI (source-diff): Rollup-bundled SSG node build legitimately combines network + exec; stable build artifact. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are established shiki/iconify packages matching declared functionality. | ai | |
| source-diff | net-exec-file:dist/node/chunk-BZEQqoFe.js | AI (source-diff): Rollup-bundled node build for the SSG; network+exec are the dev server/build engine, not malware. Filename hash varies per release. | ai | |
| source-diff | obfuscated-file:dist/node/serve-4DnZ8_Si.js | AI (source-diff): Rollup build output; readable ESM imports, no obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/node/serve-4DnZ8_Si.js | AI (source-diff): Bundled SSG dev server; net+exec expected for vite-powered tooling. | ai | |
| source-diff | net-exec-file:dist/node/serve-CFRRJDfQ.js | AI (source-diff): SSG dev-server bundle legitimately uses http/child_process/vite; no exfil target. | ai | |
| source-diff | obfuscated-file:dist/node/serve-CFRRJDfQ.js | AI (source-diff): Rollup bundle output, not obfuscation; new hashed filename per build. | ai | |
| source-diff | net-exec-file:dist/node/chunk-Zsoi3j4v.js | AI (source-diff): Bundled node build output; VitePress dev server legitimately needs http/child_process/fs. Stable per-release chunk. | ai | |
| source-diff | net-exec-file:dist/node/chunk-Fcjkb921.js | AI (source-diff): Rolled-up node bundle for an SSG/dev-server; net+exec imports are inherent build output, not malicious behavior. | ai | |
| source-diff | net-exec-file:dist/node/chunk-DMuPggCS.js | AI (source-diff): Rollup-bundled node CLI chunk; network+exec are inherent to the SSG build, not malware. | ai | |
| source-diff | net-exec-file:dist/node/serve-BSNQCR34.js | AI (source-diff): Bundled vite dev server legitimately uses http + child_process; expected for this package. | ai | |
| source-diff | obfuscated-file:dist/node/serve-BSNQCR34.js | AI (source-diff): Rollup-bundled dev-server output; minified not obfuscated. Filename hash changes per build. | ai | |
| source-diff | obfuscated-file:dist/node/serve-lJPQ9bCN.js | AI (source-diff): Rollup-bundled server output; minified long lines, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/node/serve-lJPQ9bCN.js | AI (source-diff): SSG server bundle legitimately uses http+child_process; no hostile target. | ai | |
| source-diff | obfuscated-file:dist/node/serve-f1iMCw7A.js | AI (source-diff): Rollup-bundled SSR server output, minified not obfuscated; expected build artifact for vitepress. | ai | |
| source-diff | net-exec-file:dist/node/serve-f1iMCw7A.js | AI (source-diff): Dev/preview server legitimately uses http + module loading; inherent to a static-site-generator. | ai | |
| source-diff | net-exec-file:dist/node/serve-BhLFz9dF.js | AI (source-diff): Dev/SSR server bundle legitimately uses http + module loading; benign for this tool. | ai | |
| source-diff | obfuscated-file:dist/node/serve-BhLFz9dF.js | AI (source-diff): Rollup-bundled SSR server output, not obfuscated; stable build artifact. | ai | |
| source-diff | obfuscated-file:dist/node/serve-DGS-XFVh.js | AI (source-diff): Rollup-bundled dev-server output; long lines are minification, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/node/serve-DGS-XFVh.js | AI (source-diff): Dev server legitimately needs http + module loading; benign for this SSG. | ai | |
| phantom-deps | phantom-dep:@iconify-json/simple-icons | AI (phantom-deps): Icon data bundled into vitepress; not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/markdown-it | AI (phantom-deps): Type-only dependency used in type declarations; framework-scoped pattern. | ai | |
| phantom-deps | phantom-dep:@docsearch/css | AI (phantom-deps): Algolia DocSearch CSS; bundled into vitepress theme, not directly imported. | ai | |
| phantom-deps | phantom-dep:@shikijs/core | AI (phantom-deps): Shiki syntax highlighting core; bundled into vitepress, not directly imported. | ai | |
| phantom-deps | phantom-dep:@docsearch/js | AI (phantom-deps): Algolia DocSearch widget; bundled into vitepress theme, not directly imported. | ai | |
| phantom-deps | phantom-dep:focus-trap | AI (phantom-deps): Bundled/re-exported by vitepress build; not directly imported but legitimately used. | ai | |
| phantom-deps | phantom-dep:mark.js | AI (phantom-deps): Bundled/re-exported by vitepress build; not directly imported but legitimately used. | ai | |
| phantom-deps | phantom-dep:@vueuse/integrations | AI (phantom-deps): VueUse integrations bundled into vitepress theme; not directly imported. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 1.6.4 | 18 / 74 | |
| 1.6.3 | 18 / 74 | |
| 1.6.2 | 18 / 74 | |
| 1.6.1 | 18 / 74 | |
| 1.6.0 | 18 / 74 | |
| 1.5.0 | 18 / 75 | |
| 1.4.5 | 17 / 74 | |
| 1.4.4 | 17 / 74 | |
| 1.4.3 | 17 / 74 | |
| 1.4.2 | 17 / 73 | |
| 1.4.1 | 17 / 73 | |
| 1.4.0 | 17 / 73 | |
| 1.3.4 | 16 / 73 | |
| 1.3.3 | 16 / 73 | |
| 1.3.2 | 16 / 73 | |
| 1.3.1 | 16 / 73 | |
| 1.3.0 | 16 / 73 | |
| 1.2.3 | 16 / 75 | |
| 1.2.2 | 16 / 75 | |
| 1.2.1 | 16 / 77 | |
| 1.2.0 | 16 / 77 |
v1.6.3
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.2
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.6.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.5
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.4
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.