vueify
Vue component transform for Browserify
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): Established package with strong publisher track record; provenance is a best-practice gap, not a security defect. | ai | |
| dependencies | unvetted-dep:html-minifier | AI (dependencies): html-minifier is a well-known legitimate library; unvetted flag is a false positive for this established build tool. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): vue-template-compiler is the official Vue 2 template compiler from the same author/org; its addition is a legitimate and expected part of the Vue 2 migration for vueify. | ai | |
| phantom-deps | phantom-dep:vue-hot-reload-api | AI (phantom-deps): vue-hot-reload-api is used for hot-reload support in dev workflows and referenced in config; not directly imported in all code paths but legitimately declared. | ai | |
| dependencies | unvetted-dep:vue-template-compiler | AI (dependencies): vue-template-compiler is a core Vue.js package published by the same author/org; not a risk for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): SPAM-FLAGGED signal is a false positive for yyx990803 (Evan You), creator of Vue.js and publisher of many legitimate, widely-used packages. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads user's own vue.config.js from cwd — intentional, documented config loading behavior for a build tool, not a security risk. | ai |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 9.4.1 | 14 / 19 | |
| 9.2.4 | 12 / 18 | |
| 9.2.3 | 12 / 18 | |
| 9.2.2 | 12 / 18 | |
| 9.0.0 | 10 / 15 | |
| 8.6.0 | 15 / 12 | |
| 8.5.4 | 15 / 12 | |
| 8.5.3 | 15 / 12 | |
| 8.3.4 | 14 / 12 | |
| 8.1.1 | 11 / 12 | |
| 8.1.0 | 11 / 12 | |
| 8.0.0 | 11 / 12 | |
| 7.2.0 | 12 / 11 | |
| 7.1.0 | 12 / 11 | |
| 7.0.2 | 12 / 11 | |
| 7.0.1 | 12 / 11 | |
| 7.0.0 | 12 / 6 | |
| 6.0.1 | 11 / 7 | |
| 6.0.0 | 11 / 7 | |
| 5.0.4 | 11 / 7 | |
| 5.0.3 | 11 / 7 | |
| 5.0.2 | 11 / 7 | |
| 5.0.1 | 11 / 7 | |
| 5.0.0 | 11 / 7 | |
| 4.0.1 | 10 / 7 | |
| 4.0.0 | 10 / 7 | |
| 3.0.2 | 10 / 8 | |
| 3.0.1 | 10 / 8 | |
| 3.0.0 | 9 / 8 | |
| 2.0.1 | 5 / 8 | |
| 1.1.5 | 2 / 0 | |
| 1.1.4 | 2 / 0 | |
| 1.1.3 | 2 / 0 | |
| 1.1.2 | 2 / 0 | |
| 1.1.0 | 2 / 0 | |
| 0.1.0 | 2 / 0 |
v9.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v9.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.