← Home

vite-plugin-vue-devtools

2
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

webfansplz

Keywords

vue-devtoolsvite-pluginvite-plugin-vue-devtoolsdx

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:client/assets/timeline-C70dHO3X.js AI (source-diff): Minified timeline component bundle; legitimate devtools UI code. ai
source-diff obfuscated-file:client/assets/pages-DooL8y43.js AI (source-diff): Minified Vue router/pages bundle; legitimate devtools UI code. ai
source-diff obfuscated-file:client/assets/settings-m2v-t2vR.js AI (source-diff): Minified Vue settings component; legitimate devtools UI code. ai
source-diff obfuscated-file:client/assets/assets-rxSrDlpI.js AI (source-diff): Standard Vite-minified client bundle for devtools UI; content-hashed filename is expected pattern. ai
source-diff obfuscated-file:client/assets/graph-wnRn8UNq.js AI (source-diff): Minified vis-network library with license header; expected bundled dependency. ai
source-diff net-exec-file:client/assets/graph-wnRn8UNq.js AI (source-diff): vis-network bundle; network calls are browser DOM/fetch ops, not dropper behavior. ai
source-diff obfuscated-file:client/assets/index-tvfuK4RW.js AI (source-diff): Main Vite bundle entry; minification is expected for this devtools client package. ai
source-diff net-exec-file:client/assets/index-tvfuK4RW.js AI (source-diff): Vite modulepreload polyfill pattern; standard browser fetch for preloading, not malware. ai
source-diff obfuscated-file:client/assets/overview-DZxAymiJ.js AI (source-diff): Minified Vue component bundle; legitimate devtools UI code. ai
phantom-deps phantom-dep:@vue/devtools-shared AI (phantom-deps): Framework-scoped sibling package loaded by convention; stable false positive for this package. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires on bundled Vue runtime code; Reflect.get() is standard Vue internals, not malicious obfuscation. ai

Versions (showing 2 of 2)

Version Deps Published
8.1.2 6 / 4
8.1.1 6 / 4

v8.1.2

10 findings
HIGH New obfuscated file: client/assets/assets-rxSrDlpI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/assets/graph-wnRn8UNq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: client/assets/graph-wnRn8UNq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: client/assets/index-tvfuK4RW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: client/assets/index-tvfuK4RW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: client/assets/overview-DZxAymiJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/assets/pages-DooL8y43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/assets/settings-m2v-t2vR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: client/assets/timeline-C70dHO3X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v8.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.