← Home

vitepress

21
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

yyx990803posvakiakingantfubrc-dd

Keywords

vitevuevitepress

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/node/chunk-L6-oDwDi.js AI (source-diff): Rollup-bundled node build chunk for an SSG; net+exec APIs are expected and non-malicious. ai
source-diff obfuscated-file:dist/node/serve-Bvg4Nr_L.js AI (source-diff): Rollup/esbuild bundled dev-server output, not obfuscation; regenerated with hashed name each release. ai
source-diff net-exec-file:dist/node/serve-Bvg4Nr_L.js AI (source-diff): Bundled Vite dev server; http+child_process are expected for an SSG server. ai
source-diff net-exec-file:dist/node/serve-BwR5EPUJ.js AI (source-diff): Dev-server bundle legitimately uses http + child_process; core function of an SSG. ai
source-diff obfuscated-file:dist/node/serve-BwR5EPUJ.js AI (source-diff): Rollup-bundled dist output for the dev server; minified not obfuscated. ai
source-diff net-exec-file:dist/node/chunk-BGE1nmDJ.js AI (source-diff): Rolled-up SSG build bundle; network+exec APIs are inherent to vitepress node runtime, not a dropper. ai
source-diff net-exec-file:dist/node/chunk-D0czDMtb.js AI (source-diff): Bundled node CLI chunk; network+exec are legit dev-server/build APIs for this SSG. ai
source-diff net-exec-file:dist/node/serve-oY-f4fXJ.js AI (source-diff): SSG dev/preview server legitimately uses http + child_process; no hostile target. ai
source-diff obfuscated-file:dist/node/serve-oY-f4fXJ.js AI (source-diff): Rollup-bundled node build output; minified not obfuscated, expected per build:node script. ai
source-diff net-exec-file:dist/node/serve-CEEKiiuH.js AI (source-diff): Dev-server bundle legitimately uses http+child_process via vite; benign for this package. ai
source-diff obfuscated-file:dist/node/serve-CEEKiiuH.js AI (source-diff): Rollup-bundled dev-server output; minified not obfuscated, stable per release. ai
source-diff net-exec-file:dist/node/chunk-BuJ66qxQ.js AI (source-diff): Rollup-bundled SSG node build legitimately combines network + exec; stable build artifact. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are established shiki/iconify packages matching declared functionality. ai
source-diff net-exec-file:dist/node/chunk-BZEQqoFe.js AI (source-diff): Rollup-bundled node build for the SSG; network+exec are the dev server/build engine, not malware. Filename hash varies per release. ai
source-diff obfuscated-file:dist/node/serve-4DnZ8_Si.js AI (source-diff): Rollup build output; readable ESM imports, no obfuscation signature. ai
source-diff net-exec-file:dist/node/serve-4DnZ8_Si.js AI (source-diff): Bundled SSG dev server; net+exec expected for vite-powered tooling. ai
source-diff net-exec-file:dist/node/serve-CFRRJDfQ.js AI (source-diff): SSG dev-server bundle legitimately uses http/child_process/vite; no exfil target. ai
source-diff obfuscated-file:dist/node/serve-CFRRJDfQ.js AI (source-diff): Rollup bundle output, not obfuscation; new hashed filename per build. ai
source-diff net-exec-file:dist/node/chunk-Zsoi3j4v.js AI (source-diff): Bundled node build output; VitePress dev server legitimately needs http/child_process/fs. Stable per-release chunk. ai
source-diff net-exec-file:dist/node/chunk-Fcjkb921.js AI (source-diff): Rolled-up node bundle for an SSG/dev-server; net+exec imports are inherent build output, not malicious behavior. ai
source-diff net-exec-file:dist/node/chunk-DMuPggCS.js AI (source-diff): Rollup-bundled node CLI chunk; network+exec are inherent to the SSG build, not malware. ai
source-diff net-exec-file:dist/node/serve-BSNQCR34.js AI (source-diff): Bundled vite dev server legitimately uses http + child_process; expected for this package. ai
source-diff obfuscated-file:dist/node/serve-BSNQCR34.js AI (source-diff): Rollup-bundled dev-server output; minified not obfuscated. Filename hash changes per build. ai
source-diff obfuscated-file:dist/node/serve-lJPQ9bCN.js AI (source-diff): Rollup-bundled server output; minified long lines, not obfuscation. ai
source-diff net-exec-file:dist/node/serve-lJPQ9bCN.js AI (source-diff): SSG server bundle legitimately uses http+child_process; no hostile target. ai
source-diff obfuscated-file:dist/node/serve-f1iMCw7A.js AI (source-diff): Rollup-bundled SSR server output, minified not obfuscated; expected build artifact for vitepress. ai
source-diff net-exec-file:dist/node/serve-f1iMCw7A.js AI (source-diff): Dev/preview server legitimately uses http + module loading; inherent to a static-site-generator. ai
source-diff net-exec-file:dist/node/serve-BhLFz9dF.js AI (source-diff): Dev/SSR server bundle legitimately uses http + module loading; benign for this tool. ai
source-diff obfuscated-file:dist/node/serve-BhLFz9dF.js AI (source-diff): Rollup-bundled SSR server output, not obfuscated; stable build artifact. ai
source-diff obfuscated-file:dist/node/serve-DGS-XFVh.js AI (source-diff): Rollup-bundled dev-server output; long lines are minification, not obfuscation. ai
source-diff net-exec-file:dist/node/serve-DGS-XFVh.js AI (source-diff): Dev server legitimately needs http + module loading; benign for this SSG. ai
phantom-deps phantom-dep:@iconify-json/simple-icons AI (phantom-deps): Icon data bundled into vitepress; not directly imported. ai
phantom-deps phantom-dep:@types/markdown-it AI (phantom-deps): Type-only dependency used in type declarations; framework-scoped pattern. ai
phantom-deps phantom-dep:@docsearch/css AI (phantom-deps): Algolia DocSearch CSS; bundled into vitepress theme, not directly imported. ai
phantom-deps phantom-dep:@shikijs/core AI (phantom-deps): Shiki syntax highlighting core; bundled into vitepress, not directly imported. ai
phantom-deps phantom-dep:@docsearch/js AI (phantom-deps): Algolia DocSearch widget; bundled into vitepress theme, not directly imported. ai
phantom-deps phantom-dep:focus-trap AI (phantom-deps): Bundled/re-exported by vitepress build; not directly imported but legitimately used. ai
phantom-deps phantom-dep:mark.js AI (phantom-deps): Bundled/re-exported by vitepress build; not directly imported but legitimately used. ai
phantom-deps phantom-dep:@vueuse/integrations AI (phantom-deps): VueUse integrations bundled into vitepress theme; not directly imported. ai

Versions (showing 21 of 21)

Version Deps Published
1.6.4 18 / 74
1.6.3 18 / 74
1.6.2 18 / 74
1.6.1 18 / 74
1.6.0 18 / 74
1.5.0 18 / 75
1.4.5 17 / 74
1.4.4 17 / 74
1.4.3 17 / 74
1.4.2 17 / 73
1.4.1 17 / 73
1.4.0 17 / 73
1.3.4 16 / 73
1.3.3 16 / 73
1.3.2 16 / 73
1.3.1 16 / 73
1.3.0 16 / 73
1.2.3 16 / 75
1.2.2 16 / 75
1.2.1 16 / 77
1.2.0 16 / 77

v1.6.3

2 findings
HIGH New file with network + code execution: dist/node/chunk-Zsoi3j4v.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.2

2 findings
HIGH New file with network + code execution: dist/node/chunk-BuJ66qxQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.1

2 findings
HIGH New file with network + code execution: dist/node/chunk-Fcjkb921.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.0

2 findings
HIGH New file with network + code execution: dist/node/chunk-BZEQqoFe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

2 findings
HIGH New file with network + code execution: dist/node/chunk-DMuPggCS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.5

2 findings
HIGH New file with network + code execution: dist/node/chunk-D0czDMtb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.4

2 findings
HIGH New file with network + code execution: dist/node/chunk-L6-oDwDi.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.3

2 findings
HIGH New file with network + code execution: dist/node/chunk-BGE1nmDJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2

3 findings
HIGH New obfuscated file: dist/node/serve-BSNQCR34.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-BSNQCR34.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.1

3 findings
HIGH New obfuscated file: dist/node/serve-4DnZ8_Si.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-4DnZ8_Si.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

3 findings
HIGH New obfuscated file: dist/node/serve-Bvg4Nr_L.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-Bvg4Nr_L.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.4

3 findings
HIGH New obfuscated file: dist/node/serve-CFRRJDfQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-CFRRJDfQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.3

3 findings
HIGH New obfuscated file: dist/node/serve-lJPQ9bCN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-lJPQ9bCN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

3 findings
HIGH New obfuscated file: dist/node/serve-f1iMCw7A.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-f1iMCw7A.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

3 findings
HIGH New obfuscated file: dist/node/serve-oY-f4fXJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-oY-f4fXJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

3 findings
HIGH New obfuscated file: dist/node/serve-BhLFz9dF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-BhLFz9dF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.3

3 findings
HIGH New obfuscated file: dist/node/serve-CEEKiiuH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-CEEKiiuH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

3 findings
HIGH New obfuscated file: dist/node/serve-BwR5EPUJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-BwR5EPUJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

3 findings
HIGH New obfuscated file: dist/node/serve-DGS-XFVh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/serve-DGS-XFVh.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.