@actual-app/web
Actual on the web
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/static/js/extends.CfN_tLZB.chunk.js | AI (source-diff): Standard Vite/Rolldown minified chunk; long lines are bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/chart-theme.CD7eAce3.chunk.js | AI (source-diff): Standard Vite/Rolldown minified chunk; long lines are bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/ScheduleEditForm.DVZwyX6V.chunk.js | AI (source-diff): Standard Vite/Rolldown minified chunk; long lines are bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/ReportRouter.DWloFi3y.chunk.js | AI (source-diff): Standard Vite/Rolldown minified chunk; long lines are bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:build/static/js/merge.C77XY6IK.chunk.js | AI (source-diff): Vite chunk with app-internal fetch calls; no exfiltration to unrelated destination. | ai | |
| source-diff | net-exec-file:build/static/js/chart-theme.CD7eAce3.chunk.js | AI (source-diff): Vite chunk with app-internal fetch calls; no exfiltration to unrelated destination. | ai | |
| source-diff | net-exec-file:build/kcab/kcab.worker.Df_vXNHn.js | AI (source-diff): App's own backend worker bundle; network+exec pattern is the app's internal worker/fetch infrastructure, not malicious dropper behavior. | ai | |
| source-diff | obfuscated-file:build/static/js/narrow.CjKQQxBs.chunk.js | AI (source-diff): Standard Vite/Rolldown minified chunk; long lines are bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/merge.C77XY6IK.chunk.js | AI (source-diff): Standard Vite/Rolldown minified chunk; long lines are bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/index.__BZenhJ.js | AI (source-diff): Standard Vite/Rolldown minified chunk; long lines are bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/static/js/extends.DJT9Cguz.chunk.js | AI (source-diff): Minified Vite chunk, not obfuscated. | ai | |
| source-diff | obfuscated-file:build/static/js/ReportRouter.DNZZKDge.chunk.js | AI (source-diff): Minified Vite chunk, not obfuscated. | ai | |
| source-diff | obfuscated-file:build/workbox-2fbc6a65.js | AI (source-diff): Standard workbox service worker bundle. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large number of files is expected for a full web app build with locale chunks. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): CI-only publish pipeline; human maintainer removal is expected when GitHub Actions is the sole publisher. | ai | |
| source-diff | obfuscated-file:build/kcab/kcab.worker.BGKt0ne7.js | AI (source-diff): Standard Vite/esbuild bundle output; no true obfuscation signatures present. | ai | |
| source-diff | net-exec-file:build/kcab/kcab.worker.BGKt0ne7.js | AI (source-diff): Web worker bundle for budgeting app; network+exec pattern is normal for a browser worker. | ai | |
| source-diff | net-exec-file:build/static/js/index.CaWhj7qX.js | AI (source-diff): Main app bundle; network calls and dynamic code are expected in a React SPA. | ai | |
| source-diff | obfuscated-file:build/static/js/index.CaWhj7qX.js | AI (source-diff): Minified Vite build output, not obfuscated. | ai | |
| source-diff | obfuscated-file:build/static/js/ScheduleEditForm.BXXG23Sk.chunk.js | AI (source-diff): Standard Vite minified chunk. | ai | |
| source-diff | obfuscated-file:build/static/js/ReportRouter.DZ2C94Cy.chunk.js | AI (source-diff): Standard Vite minified chunk; imports are clearly named React/app modules. | ai | |
| source-diff | obfuscated-file:build/static/js/Value.BytJXiib.chunk.js | AI (source-diff): Standard Vite minified chunk; imports are clearly named React/app modules. | ai | |
| source-diff | net-exec-file:build/static/js/Value.BytJXiib.chunk.js | AI (source-diff): Vite build artifact; network calls are app-level fetch, not dropper behavior. | ai | |
| source-diff | net-exec-file:build/kcab/kcab.worker.BxG26swk.js | AI (source-diff): Rolldown worker bundle for absurd-sql/KCAB; standard build output for this package. | ai | |
| source-diff | obfuscated-file:build/static/js/chart-theme.DIYMvoov.chunk.js | AI (source-diff): Standard Vite minified chunk for chart theme component. | ai | |
| source-diff | net-exec-file:build/static/js/chart-theme.DIYMvoov.chunk.js | AI (source-diff): Vite build artifact; not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/static/js/extends.B4LxODoX.chunk.js | AI (source-diff): Standard Vite minified chunk. | ai | |
| source-diff | obfuscated-file:build/static/js/index.CIcGifLe.js | AI (source-diff): Standard Vite minified entry bundle. | ai | |
| source-diff | obfuscated-file:build/static/js/narrow.D2jKRljJ.chunk.js | AI (source-diff): Standard Vite minified chunk. | ai | |
| source-diff | obfuscated-file:build/static/js/TransactionEdit.D_A_Dmhn.chunk.js | AI (source-diff): Standard Vite minified chunk. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established open-source project; README and metadata signals are false positives. | ai | |
| source-diff | obfuscated-file:build/static/js/ReportRouter.CSslilBc.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher is GitHub Actions CI with SLSA provenance attestation; automated publishing is expected for this project. | ai | |
| source-diff | net-exec-file:build/static/js/chart-theme.2NQOy8Lq.chunk.js | AI (source-diff): Standard Vite chunk with vitePreload (lazy loading); not a dropper. | ai | |
| source-diff | net-exec-file:build/static/js/Value.CF-3_RXM.chunk.js | AI (source-diff): Standard Vite chunk with vitePreload (lazy loading); not a dropper. | ai | |
| source-diff | net-exec-file:build/kcab/kcab.worker.tCyo0gRC.js | AI (source-diff): Rolldown/Vite worker bundle for the budget backend; network calls are IndexedDB/fetch for local budget data, not exfiltration. | ai | |
| source-diff | obfuscated-file:build/static/js/narrow.ChOmIrMx.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| source-diff | obfuscated-file:build/static/js/indexeddb-main-thread-worker-e59fee74.xguYkce3.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| source-diff | obfuscated-file:build/static/js/index.BFVNfkrn.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| source-diff | obfuscated-file:build/static/js/extends.RRv7gyle.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| source-diff | obfuscated-file:build/static/js/chart-theme.2NQOy8Lq.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| source-diff | obfuscated-file:build/static/js/Value.CF-3_RXM.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| source-diff | obfuscated-file:build/static/js/TransactionEdit.CfIQzCoh.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai | |
| source-diff | obfuscated-file:build/static/js/ScheduleEditForm.CCO05hlt.chunk.js | AI (source-diff): Standard Vite build output; minified ES module chunks are expected for this web app package. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 26.7.0 | 0 / 77 | |
| 26.6.0 | 0 / 83 | |
| 26.5.2 | 0 / 81 | |
| 26.5.0 | 0 / 80 | |
| 26.4.0 | 0 / 82 | |
| 26.3.0 | 0 / 81 | |
| 26.2.1 | 0 / 77 | |
| 26.2.0 | 0 / 77 | |
| 26.1.0 | 0 / 78 | |
| 25.12.0 | 0 / 78 | |
| 25.11.0 | 0 / 78 |
v26.7.0
35 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.