← Home

@voidzero-dev/vite-plus-core

The Unified Toolchain for the Web

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

yyx990803vitebotbroooooklynboshen

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/tsdown/dist-wWM45aJq.js AI (source-diff): Bundled build output from tsdown; long lines from minification, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Package bundles vite+rolldown+tsdown; large dist is expected and file count varies with chunk hashes. ai
source-diff encoded-string-file:dist/vite/node/chunks/build.js AI (source-diff): WebAssembly modules (xxhash64, etc.) encoded as base64 — standard for bundled hash implementations. ai
source-diff obfuscated-file:dist/rolldown/shared/rolldown-build-CgMNHFY3.mjs AI (source-diff): Bundled rolldown build module; minified output standard for this package. ai
source-diff obfuscated-file:dist/rolldown/shared/prompt-DV1XbtjC.mjs AI (source-diff): Bundled consola prompt module; minified but readable, not obfuscated. ai
source-diff net-exec-file:dist/tsdown/dist-wWM45aJq.js AI (source-diff): Build tool legitimately uses child_process (fork/spawn) and network APIs for dev server. ai
source-diff net-exec-file:dist/tsdown/dist-DTzJRoOQ.js AI (source-diff): Build tool legitimately uses child_process (fork/spawn) and network APIs. ai
source-diff obfuscated-file:dist/tsdown/dist-DTzJRoOQ.js AI (source-diff): Bundled build output from tsdown; long lines are minified vendor code, not obfuscation. ai
source-diff obfuscated-file:dist/tsdown/dist-DL4hnQY2.js AI (source-diff): Bundled build output from tsdown; minified but not obfuscated. Stable for this package. ai
source-diff net-exec-file:dist/tsdown/dist-DL4hnQY2.js AI (source-diff): Build tool legitimately uses child_process (fork/spawn) and network; not malicious. ai
source-diff obfuscated-file:dist/rolldown/shared/rolldown-build-DrXmg2RO.mjs AI (source-diff): Bundled rolldown build output; long lines from minification, not obfuscation. ai
source-diff encoded-string-file:dist/vite/node/chunks/dist.js AI (source-diff): HTML entity decode trie (entities package) and WASM binary — standard bundled data. ai
source-diff obfuscated-file:dist/tsdown/dist-CtF_Stv5.js AI (source-diff): File is minified build output of tsdown bundler — readable imports, standard sourcemap codec, no obfuscation. Expected artifact for a build toolchain package. ai
source-diff net-exec-file:dist/tsdown/dist-CtF_Stv5.js AI (source-diff): Network and child_process usage is expected in a build tool (Vite dev server + TypeScript compiler invocation). No dropper/loader patterns in the sample. ai
source-diff obfuscated-file:dist/rolldown/shared/rolldown-build-CYoDea9V.mjs AI (source-diff): Bundled rolldown distribution file. Minified lines are expected bundler output for rolldown internals. Not malicious obfuscation. ai
source-diff net-exec-file:dist/tsdown/dist-CY3M22aR.js AI (source-diff): Network+exec pattern comes from build tooling (fork/spawn child processes for compilation, fs reads). This is expected behavior for a build toolchain package, not dropper malware. ai
source-diff obfuscated-file:dist/tsdown/dist-CY3M22aR.js AI (source-diff): This is bundled/minified build tool output (tsdown integration). Long lines are expected in bundled dist files for this build toolchain package. ai
source-diff obfuscated-file:dist/tsdown/dist-dJp148cE.js AI (source-diff): This is a bundled build artifact from tsdown/rolldown with content-hash filename. The sample shows readable, legitimate build-tool code — not obfuscation. Pattern is stable for this package. ai
source-diff net-exec-file:dist/tsdown/dist-dJp148cE.js AI (source-diff): fork/spawn usage is expected in a TypeScript build toolchain (tsdown). Network + process execution is the core functionality of a build tool, not malware. SLSA provenance confirms legitimate CI publish. ai
source-diff encoded-string-file:dist/vite/node/chunks/build2.js AI (source-diff): Long encoded strings are Base64-encoded WebAssembly binaries (xxhash64 from loader-utils) bundled into the dist output — a standard and legitimate pattern for WASM embedding. ai
source-diff encoded-string-file:dist/vite/node/chunks/node.js AI (source-diff): Long encoded string is a Base64-encoded WebAssembly binary (CSS/JS parser) bundled into dist output — standard WASM embedding pattern used by build tools like lightningcss. ai
source-diff obfuscated-file:dist/tsdown/dist-DSi2MWPQ.js AI (source-diff): Large bundled build artifact from tsdown bundler; content is readable minified JS with standard imports, not obfuscation. Expected for a build tool package. ai
source-diff net-exec-file:dist/tsdown/dist-DSi2MWPQ.js AI (source-diff): fork/spawn usage is for TypeScript compilation orchestration in a build tool; network calls are standard toolchain operations. No malicious dropper pattern present. ai
bogus-package bogus-package AI (bogus-package): yyx990803 flag is a false positive for this legitimate VoidZero/Vite ecosystem package with SLSA provenance and official GitHub repo. ai

Versions (showing 100 of 120)

Hide prereleases
Version Deps Published
0.1.23 4 / 24
0.1.22 4 / 24
0.1.21 4 / 24
0.1.20 4 / 24
0.1.19 4 / 24
0.1.18 4 / 24
0.1.17 4 / 24
0.1.16 4 / 24
0.1.15 4 / 24
0.1.14 4 / 24
0.1.13 4 / 24
0.1.12 4 / 24
0.1.11 4 / 24
0.1.10 4 / 24
0.1.9 4 / 24
0.1.8 4 / 24
0.1.7 4 / 24
0.1.6 4 / 24
0.1.5 4 / 24
0.1.4 4 / 24
0.1.3 4 / 24
0.1.2 4 / 24
0.1.1 4 / 24
0.1.0 4 / 24
0.1.20-alpha.1 4 / 24
0.1.20-alpha.0 4 / 24
0.1.19-alpha.3 4 / 24
0.1.19-alpha.2 4 / 24
0.1.19-alpha.1 4 / 24
0.1.19-alpha.0 4 / 24
0.1.18-alpha.0 4 / 24
0.1.17-alpha.5 4 / 24
0.1.17-alpha.4 4 / 24
0.1.17-alpha.3 4 / 24
0.1.17-alpha.2 4 / 24
0.1.17-alpha.1 4 / 24
0.1.17-alpha.0 4 / 24
0.1.16-alpha.4 4 / 24
0.1.16-alpha.3 4 / 24
0.1.16-alpha.2 4 / 24
0.1.16-alpha.1 4 / 24
0.1.16-alpha.0 4 / 24
0.1.15-alpha.7 4 / 24
0.1.15-alpha.6 4 / 24
0.1.15-alpha.5 4 / 24
0.1.15-alpha.4 4 / 24
0.1.15-alpha.3 4 / 24
0.1.15-alpha.2 4 / 24
0.1.15-alpha.1 4 / 24
0.1.15-alpha.0 4 / 24
0.1.14-alpha.3 4 / 24
0.1.14-alpha.2 4 / 24
0.1.14-alpha.1 4 / 24
0.1.14-alpha.0 4 / 24
0.1.13-alpha.5 4 / 24
0.1.13-alpha.4 4 / 24
0.1.13-alpha.3 4 / 24
0.1.13-alpha.2 4 / 24
0.1.13-alpha.1 4 / 24
0.1.13-alpha.0 4 / 24
0.1.12-alpha.2 4 / 24
0.1.12-alpha.1 4 / 24
0.1.5-alpha.0 4 / 24
0.1.1-alpha.0 4 / 24
0.1.0-alpha.0 4 / 24
0.0.2-gd8fe16bf.20260302-1535 4 / 24
0.0.2-ga54d12e6.20260302-0503 4 / 24
0.0.2-g9a3a310d.20260303-0757 4 / 24
0.0.2-g5d96ecf4.20260228-1157 4 / 24
0.0.2-g3cb78c3c.20260305-0800 4 / 24
0.0.2-g17a37daf.20260304-1136 4 / 24
0.0.0-gd42e0ca6.20260225-0619 4 / 24
0.0.0-gbe8891a5.20260227-1615 4 / 24
0.0.0-g999c5046.20260226-1450 4 / 24
0.0.0-g61d318d2.20260227-0939 4 / 24
0.0.0-g52709db6.20260226-1136 4 / 24
0.0.0-g28c55a1f.20260226-0707 4 / 24
0.0.0-g0fd4d06d.20260225-1306 4 / 24
0.0.0-ffb4d08a8edafe855c59736c0a38ee85a2373ebb 4 / 24
0.0.0-f8668d9f60293be54f0729bc91ad614ba861cd97 4 / 24
0.0.0-f74442ad.20260222-0755 4 / 24
0.0.0-f48af939.20260205-0533 4 / 24
0.0.0-ecd77118cbba8f0cb5fe091af0f6c7e14bf38261 4 / 24
0.0.0-e8feafb8f8a08d271fb227752fbda933a3dfadfc 4 / 24
0.0.0-e7cbd08c.20260221-0702 4 / 24
0.0.0-e72bfc225443d870e54915e93033c0a0e3668e04 4 / 24
0.0.0-e32b32e5.20260224-0706 4 / 24
0.0.0-dfd5c99899261c54d5b19dceaa831fab310d6171 4 / 24
0.0.0-de8bd982.20260205-1433 4 / 24
0.0.0-c878a19a.20260205-0605 4 / 24
0.0.0-c8731b7ca8cddc6c6902e84dbac920cd584d6458 4 / 24
0.0.0-c73461a6e273ac5538a5d633d30d37e0afc1f56a 4 / 24
0.0.0-c4fc6a94f8d46492352a7c1b416c35d9c603cb23 4 / 24
0.0.0-bd0a60d54878156c05bcd110ac4351d7e40f6bd6 4 / 24
0.0.0-b356849c.20260207-0631 4 / 24
0.0.0-b19dc2a6.20260221-1545 4 / 24
0.0.0-b1666489.20260220-0254 4 / 24
0.0.0-ae9e260ac1617d0a3acea0ff37239f6ff1acf8c3 4 / 24
0.0.0-ab0b0858cb619f270f5e0a698fea3d6f5622a761 4 / 23
0.0.0-a9c652c5753d93f1945ac33b16422f345b518ae9 4 / 23
Showing 100 of 120 Next page →

v0.1.23

6 findings
HIGH New obfuscated file: dist/tsdown/dist-wWM45aJq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-wWM45aJq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/rolldown/shared/prompt-DV1XbtjC.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/rolldown/shared/rolldown-build-CgMNHFY3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/vite/node/chunks/build.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.22

3 findings
HIGH New obfuscated file: dist/tsdown/dist-DTzJRoOQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-DTzJRoOQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.21

5 findings
HIGH New obfuscated file: dist/tsdown/dist-C5D85WLF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-C5D85WLF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/rolldown/shared/rolldown-build-CNhzgsn2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/vite/node/chunks/build.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.20

5 findings
HIGH New obfuscated file: dist/tsdown/dist-DL4hnQY2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-DL4hnQY2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/rolldown/shared/rolldown-build-DrXmg2RO.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/vite/node/chunks/dist.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.19

3 findings
HIGH New obfuscated file: dist/tsdown/dist-DSi2MWPQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-DSi2MWPQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.18

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.16

3 findings
HIGH New obfuscated file: dist/tsdown/dist-CY3M22aR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-CY3M22aR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.14

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.13

3 findings
HIGH New obfuscated file: dist/tsdown/dist-CtF_Stv5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-CtF_Stv5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.12

3 findings
HIGH New obfuscated file: dist/tsdown/dist-dJp148cE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-dJp148cE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.10

3 findings
HIGH Long encoded string in modified file: dist/vite/node/chunks/build2.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/vite/node/chunks/node.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

4 findings
HIGH New obfuscated file: dist/tsdown/dist-dJp148cE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/tsdown/dist-dJp148cE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/rolldown/shared/rolldown-build-CYoDea9V.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.