← Home

weapp-tailwindcss

把 tailwindcss 原子化样式思想,带给小程序开发者们! bring tailwindcss to miniprogram developers!

17
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

icebreaker

Keywords

tailwindcssweappwechatminiminiprogrammini appweapp-twweapp-tailwindcsstarouni-appremaxraxmpxjitmpandroidios小程序vitepostcsswebpackwebpack-plugingulpgulp-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/watch-dependencies-zwx4EhBn.js AI (source-diff): Rolldown runtime boilerplate + node:fs/node:path usage; no actual network fetch or dynamic code execution payload. ai
source-diff obfuscated-file:dist/precheck-lfenbOTF.mjs AI (source-diff): ESM counterpart of the same rolldown bundle; same reasoning applies. ai
source-diff obfuscated-file:dist/precheck-DgpVCvYk.js AI (source-diff): Standard rolldown bundle with readable source comments and known deps; not obfuscated. ai
source-diff obfuscated-file:dist/precheck-BrNwLG2e.mjs AI (source-diff): Minified rolldown bundle output; legitimate build artifact for this package. ai
source-diff obfuscated-file:dist/vite-DOprpdH-.mjs AI (source-diff): Minified rolldown bundle output; legitimate build artifact for this package. ai
source-diff obfuscated-file:dist/precheck-DPtJjZmV.js AI (source-diff): Minified rolldown bundle output; legitimate build artifact for this package. ai
source-diff obfuscated-file:dist/vite-Ec0uX6kF.js AI (source-diff): Minified rolldown bundle output; legitimate build artifact for this package. ai
source-diff net-exec-file:dist/runtime-registry-DpcR3IHI.js AI (source-diff): Rolldown runtime registry with CommonJS interop helpers; no actual network calls or exec in the sample. ai
source-diff net-exec-file:dist/vite-Ec0uX6kF.js AI (source-diff): Bundled vite plugin code; network/exec pattern is normal build-tool operation. ai
source-diff net-exec-file:dist/vite-DOprpdH-.mjs AI (source-diff): Bundled vite plugin code; network/exec pattern is normal build-tool operation. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): yaml is a declared runtime dep used in config loading; stable false positive for this package. ai
phantom-deps phantom-dep:@tailwindcss-mangle/config AI (phantom-deps): Declared runtime dep referenced in config files; phantom-dep heuristic misfires here. ai
phantom-deps phantom-dep:cac AI (phantom-deps): cac is a declared runtime dependency used via CLI; phantom-dep heuristic misfires here. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall patches tailwindcss internals — documented behavior for this tool; stable across versions. ai
semgrep semgrep:dynamic-require AI (semgrep): Requires a path.resolve'd, existence-checked local file (dist/cli.js); not arbitrary module loading. ai

Versions (showing 17 of 17)

Version Deps Published
5.0.4 23 / 1
5.0.0 21 / 3
4.11.2 25 / 0
4.11.1 25 / 0
4.7.8 22 / 0
4.7.7 22 / 0
4.7.5 22 / 0
4.7.2 20 / 0
4.7.0 20 / 0
4.6.2 20 / 4
4.6.1 20 / 4
4.6.0 20 / 4
4.5.2 21 / 4
4.2.2 22 / 0
4.2.1 22 / 0
4.2.0 22 / 0
4.1.7 20 / 0

v5.0.4

4 findings
HIGH New obfuscated file: dist/precheck-DgpVCvYk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/watch-dependencies-zwx4EhBn.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/precheck-lfenbOTF.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

8 findings
HIGH New obfuscated file: dist/precheck-DPtJjZmV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/runtime-registry-DpcR3IHI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/vite-Ec0uX6kF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/vite-Ec0uX6kF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/precheck-BrNwLG2e.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/vite-DOprpdH-.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/vite-DOprpdH-.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.