@abi-software/simulationvuer
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-fCMLAifd.js | AI (source-diff): Vite/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/quill-CCULFmEg-CRsckMP4.js | AI (source-diff): Same bundling artifact as index bundle. | ai | |
| source-diff | obfuscated-file:dist/quill-CCULFmEg-CRsckMP4.js | AI (source-diff): Bundled quill/lodash helper code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/index-fCMLAifd.js | AI (source-diff): CDN ESM imports (plotly/mathjs) bundled by build tool, not a loader. | ai | |
| source-diff | net-exec-file:dist/quill-BxQjL-ej-25V7CwUX.js | AI (source-diff): Bundled chunk importing from sibling bundle file, not network+exec malware. | ai | |
| source-diff | obfuscated-file:dist/index-ChFjeQ-Z.js | AI (source-diff): Vite/Rollup bundled output, long minified lines misidentified as obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-ChFjeQ-Z.js | AI (source-diff): CDN ESM imports for plotly/mathjs in bundled build code, not a loader. | ai | |
| source-diff | obfuscated-file:dist/quill-BxQjL-ej-25V7CwUX.js | AI (source-diff): Bundled quill dependency chunk, standard minified output. | ai | |
| source-diff | obfuscated-file:dist/quill-CNUBlgYr-80jSqpZl.js | AI (source-diff): Minified bundled quill dependency chunk. | ai | |
| source-diff | net-exec-file:dist/quill-CNUBlgYr-80jSqpZl.js | AI (source-diff): Bundled chunk, no real network exec behavior. | ai | |
| source-diff | obfuscated-file:dist/index-Bkmcm34g.js | AI (source-diff): Minified Vite bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Bkmcm34g.js | AI (source-diff): CDN ESM imports in bundled build, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/index-CxyMFRSV.js | AI (source-diff): Vite-bundled output, not obfuscation; consistent with package build tooling. | ai | |
| source-diff | net-exec-file:dist/quill-ZWdpIhA1-C71nSqhg.js | AI (source-diff): Bundled file referencing sibling bundle import, not malicious net+exec. | ai | |
| source-diff | obfuscated-file:dist/quill-ZWdpIhA1-C71nSqhg.js | AI (source-diff): Bundled quill dependency chunk, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CxyMFRSV.js | AI (source-diff): CDN ESM imports for plotly/mathjs in bundle, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/quill-DR7SCAb4-D_-5OTP9.js | AI (source-diff): Bundled quill dependency, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-DHJee2zx.js | AI (source-diff): Bundled Vite/Rollup build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/quill-DR7SCAb4-D_-5OTP9.js | AI (source-diff): Bundler pattern, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/index-DHJee2zx.js | AI (source-diff): Bundler dynamic-import pattern, no payload fetch/exec of untrusted code. | ai | |
| source-diff | obfuscated-file:dist/quill-CHYkspSK-Dk0gIpPQ.js | AI (source-diff): Bundled quill vendor lib, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/quill-CHYkspSK-Dk0gIpPQ.js | AI (source-diff): Bundled vendor code, no concrete malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/index-BVpzE-4C.js | AI (source-diff): Vite/Rollup bundle output, not obfuscation; no malicious behavior found. | ai | |
| source-diff | net-exec-file:dist/index-BVpzE-4C.js | AI (source-diff): Bundled ESM imports from jsdelivr CDN for plotly/mathjs, not a dropper pattern. | ai | |
| source-diff | net-exec-file:dist/index-BX7g0eM9.js | AI (source-diff): Bundled CDN ESM imports (plotly.js/mathjs), no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/index-BX7g0eM9.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/quill-B7JfuUb2-B-kKsgWs.js | AI (source-diff): Bundled build artifact, no concrete malicious destination. | ai | |
| source-diff | obfuscated-file:dist/quill-B7JfuUb2-B-kKsgWs.js | AI (source-diff): Bundled quill editor dependency, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/quill-c3wy0V4g-xOU6dJmZ.js | AI (source-diff): Bundled lodash-shaped vendor code, minified not obfuscated. | ai | |
| phantom-deps | phantom-dep:@abi-software/plotvuer | AI (phantom-deps): Same-org internal dep, used via bundled import. | ai | |
| source-diff | net-exec-file:dist/quill-c3wy0V4g-xOU6dJmZ.js | AI (source-diff): Bundled vendor file, no real network exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/index-DtImQ0dj.js | AI (source-diff): Vite/Rollup bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DtImQ0dj.js | AI (source-diff): Static CDN import specifiers in bundled code, not dynamic exfil. | ai | |
| phantom-deps | phantom-dep:@opencor/opencor | AI (phantom-deps): @opencor/opencor is referenced in config files as a runtime peer; phantom-dep false positive for this package. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 3.2.6 | 7 / 19 | |
| 3.2.5 | 7 / 19 | |
| 3.2.4 | 7 / 19 | |
| 3.2.3 | 7 / 19 | |
| 3.2.2 | 7 / 19 | |
| 3.2.1 | 7 / 19 | |
| 3.2.0 | 7 / 19 | |
| 3.1.1 | 7 / 19 | |
| 3.1.0 | 7 / 19 | |
| 3.0.20 | 7 / 19 | |
| 3.0.19 | 7 / 19 | |
| 3.0.18 | 7 / 19 | |
| 3.0.17 | 7 / 19 | |
| 3.0.16 | 7 / 19 | |
| 3.0.15 | 7 / 19 | |
| 3.0.14 | 7 / 19 | |
| 3.0.13 | 7 / 19 | |
| 3.0.12 | 7 / 15 | |
| 3.0.11 | 7 / 15 | |
| 3.0.10 | 7 / 15 | |
| 3.0.9 | 7 / 15 | |
| 3.0.8 | 7 / 15 | |
| 3.0.7 | 7 / 15 | |
| 3.0.6 | 7 / 15 | |
| 3.0.5 | 7 / 15 | |
| 3.0.4 | 7 / 15 | |
| 3.0.3 | 7 / 15 | |
| 3.0.2 | 7 / 15 | |
| 3.0.1 | 6 / 15 | |
| 3.0.0 | 6 / 15 |
v3.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.20
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.17
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.9
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.8
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.7
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.6
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.5
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.4
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.