@aboutcircles/sdk-core
Circles Contracts wrapper
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-dfk1rv00.js | AI (source-diff): Minified bundle produced by bun build --minify; consistent with package.json build script across versions. | ai | |
| source-diff | obfuscated-file:dist/index-n03c1rfp.js | AI (source-diff): Minified output from bun build --minify; content is noble-hashes crypto library, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-3z1asv8t.js | AI (source-diff): Minified bundle produced by bun build --minify as declared in package.json build script; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-fda90yjh.js | AI (source-diff): Minified output from bun build --minify; expected artifact for this package's build pipeline. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.1.36 | 4 / 4 | |
| 0.1.35 | 4 / 4 | |
| 0.1.34 | 4 / 4 | |
| 0.1.33 | 4 / 4 | |
| 0.1.32 | 4 / 4 | |
| 0.1.31 | 4 / 4 | |
| 0.1.30 | 4 / 4 | |
| 0.1.29 | 4 / 4 | |
| 0.1.28 | 4 / 4 | |
| 0.1.27 | 4 / 4 | |
| 0.1.26 | 4 / 4 | |
| 0.1.24 | 4 / 4 | |
| 0.1.23 | 4 / 4 | |
| 0.1.2 | 4 / 4 | |
| 0.1.1 | 4 / 4 | |
| 0.1.0 | 4 / 4 |
v0.1.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.31
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.30
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.29
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.28
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.27
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.26
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.