← Home

@anvia/studio

Studio UI and HTTP runtime for Anvia agents.

62
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

indrazm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/ui/assets/index-CXap27zX.js AI (source-diff): Vite-bundled UI output, not obfuscation; standard fetch/modulepreload code. ai
source-diff net-exec-file:dist/ui/assets/index-CXap27zX.js AI (source-diff): Bundled frontend calling own local API endpoints, not exfil. ai
source-diff obfuscated-file:dist/ui/assets/tools-page-lKH3Qwic.js AI (source-diff): Vite-bundled frontend code, consistent with other pages in this UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/tool-runner-CSdWatvc.js AI (source-diff): Vite-bundled frontend code, consistent with other pages in this UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/status-page-Bso5CKbL.js AI (source-diff): Vite-bundled React UI page code calling local /status API, benign. ai
source-diff obfuscated-file:dist/ui/assets/sessions-page-e_n4UI_v.js AI (source-diff): Vite-bundled Radix Dialog/UI code, benign. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-BKuuYE74.js AI (source-diff): Vite-bundled React UI page code, benign. ai
source-diff obfuscated-file:dist/ui/assets/memory-page-CYTlO9u_.js AI (source-diff): Vite-bundled React UI page code calling local API, benign. ai
source-diff obfuscated-file:dist/ui/assets/mcps-page-DLoK8pDp.js AI (source-diff): Vite-bundled React UI page code calling local API, benign. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-BmDCHSPk.js AI (source-diff): Vite-bundled React UI page code, benign. ai
source-diff obfuscated-file:dist/ui/assets/trace-browser-DVjeRRhn.js AI (source-diff): Vite-bundled frontend code, consistent with other pages in this UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/knowledge-page-DZ8JVRTM.js AI (source-diff): Vite-bundled React UI page code, benign. ai
source-diff obfuscated-file:dist/ui/assets/transcript-item-DHdArePI.js AI (source-diff): Vite-bundled frontend code, consistent with other pages in this UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/index-BA0GymcR.js AI (source-diff): Vite bundle output with bundler banner; large minified frontend chunk, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/index-COJ_MozM.js AI (source-diff): Vite-bundled UI entry with import-map preload shim; build output, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/renderers-CIC1VVRv.js AI (source-diff): Bundled UI helper module, minified by build tool. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-CIAhfO0w.js AI (source-diff): Bundled React page component, minified by build tool. ai
source-diff obfuscated-file:dist/ui/assets/memory-page-CxinVNJm.js AI (source-diff): Bundled React page component, minified by build tool. ai
source-diff obfuscated-file:dist/ui/assets/mcps-page-Bm4k-j7D.js AI (source-diff): Bundled React page component, minified by build tool. ai
source-diff obfuscated-file:dist/ui/assets/knowledge-page-Dt81OgNg.js AI (source-diff): Bundled React page component, minified by build tool. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-ClfscpGe.js AI (source-diff): Bundled React page component, minified by build tool. ai
source-diff obfuscated-file:dist/ui/assets/agents-page-B8Tw2e11.js AI (source-diff): Bundled React page component, minified by build tool. ai
source-diff obfuscated-file:dist/ui/assets/index-CISgSi9m.js AI (source-diff): Vite bundle output, not obfuscation; standard for UI dist builds. ai
source-diff obfuscated-file:dist/ui/assets/index-DMEhoZEd.js AI (source-diff): Vite bundle output, not obfuscation; fetches are relative app API calls. ai
source-diff net-exec-file:dist/ui/assets/index-DMEhoZEd.js AI (source-diff): Bundled Vite runtime with relative fetch to own app API, not dropper behavior. ai
source-diff obfuscated-file:dist/ui/assets/index-DMVhlBNM.js AI (source-diff): Vite-bundled UI output; sample shows standard build banner, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/sessions-page-zABdhQUl.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/transcript-item-CsKPOoJ7.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/trace-browser-mWVtzrMg.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/tools-page-Brv85Xnm.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/tool-runner-qP32ZAwv.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/status-page-BVw1UGMb.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-GOtnu1I3.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/memory-page-K1u-LDDz.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/mcps-page-Dd_gbvBb.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/knowledge-page-BciniOcu.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-DC-njvlP.js AI (source-diff): Vite-bundled UI page chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/index-Bc7sqnn5.js AI (source-diff): Vite-bundled UI output with sourcemaps, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/index-DsFqmLt-.js AI (source-diff): Vite-bundled UI output with bundler banner, not true obfuscation. ai
source-diff net-exec-file:dist/ui/assets/index-CC5mjRie.js AI (source-diff): fetch calls target package's own local runtime endpoints, not exfil. ai
source-diff obfuscated-file:dist/ui/assets/index-CC5mjRie.js AI (source-diff): Vite bundle output for UI, not true obfuscation. ai
phantom-deps phantom-dep:@hugeicons/react AI (phantom-deps): UI dep referenced via bundler config, expected for frontend package. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-DdYD59h4.js AI (source-diff): Bundled build asset, standard React/UI code. ai
phantom-deps phantom-dep:@tanstack/react-router AI (phantom-deps): UI dep referenced via bundler config, expected for frontend package. ai
phantom-deps phantom-dep:@hugeicons/core-free-icons AI (phantom-deps): UI dep referenced via bundler config, expected for frontend package. ai
source-diff obfuscated-file:dist/ui/assets/index-D7w3LxHM.js AI (source-diff): Vite bundle output with banner; large minified JS, no malicious payload observed. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-BA9WCR9D.js AI (source-diff): Vite bundle chunk, minified only. ai
source-diff obfuscated-file:dist/ui/assets/memory-page-Cn-wzJHp.js AI (source-diff): Vite bundle chunk calling local /memory endpoints, benign. ai
source-diff obfuscated-file:dist/ui/assets/mcps-page-DwZAv13N.js AI (source-diff): Vite bundle chunk calling package's own local API routes. ai
source-diff obfuscated-file:dist/ui/assets/knowledge-page-CpQCK-1A.js AI (source-diff): Vite bundle chunk, minified only. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-DYejWQfp.js AI (source-diff): Vite bundle chunk of React UI code, no malicious behavior. ai
source-diff obfuscated-file:dist/ui/assets/index-DxSIQUax.js AI (source-diff): Vite-bundled UI chunk with bundler banner; minified, not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/transcript-item-cUscZoNb.js AI (source-diff): Vite bundle chunk, consistent with other UI assets. ai
source-diff obfuscated-file:dist/ui/assets/trace-browser-C0vy4e41.js AI (source-diff): Vite bundle chunk, consistent with other UI assets. ai
source-diff obfuscated-file:dist/ui/assets/tools-page-kXLllnlT.js AI (source-diff): Vite bundle chunk, consistent with other UI assets. ai
source-diff obfuscated-file:dist/ui/assets/tool-runner-5JJHI3LO.js AI (source-diff): Vite bundle chunk, consistent with other UI assets. ai
source-diff obfuscated-file:dist/ui/assets/status-page-B8-sSeYx.js AI (source-diff): Vite bundle chunk calling local /status endpoint, benign. ai
source-diff obfuscated-file:dist/ui/assets/sessions-page-BuNnb20D.js AI (source-diff): Vite bundle chunk of Radix dialog code, benign. ai
source-diff obfuscated-file:dist/ui/assets/knowledge-page-DevVjoVt.js AI (source-diff): Minified Vite page chunk, benign fetch calls to package's own API routes. ai
source-diff obfuscated-file:dist/ui/assets/index-CDwzNuFN.js AI (source-diff): Vite bundle output with import-map banner, matches stated UI build; not true obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-7nLpk1vO.js AI (source-diff): Minified Vite page chunk, JSX runtime code, consistent with Studio UI. ai
source-diff obfuscated-file:dist/ui/assets/mcps-page-gSjG8fUN.js AI (source-diff): Minified Vite page chunk, calls own /agents API, no exfil. ai
source-diff obfuscated-file:dist/ui/assets/memory-page-LbQjoiJi.js AI (source-diff): Minified Vite page chunk, fetches own /memory endpoints. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-BDnSsw3p.js AI (source-diff): Minified Vite bundle including d3-style utility code, standard UI dep. ai
source-diff obfuscated-file:dist/ui/assets/sessions-page-DuFkengk.js AI (source-diff): Minified Vite bundle, Radix dialog primitives, no malicious behavior. ai
source-diff obfuscated-file:dist/ui/assets/status-page-Cp63l30c.js AI (source-diff): Minified Vite page chunk hitting own /status endpoint. ai
source-diff obfuscated-file:dist/ui/assets/tool-runner-D09nhpss.js AI (source-diff): Bundled Vite chunk, part of same UI build as other accepted files. ai
source-diff obfuscated-file:dist/ui/assets/tools-page-BwgQMVke.js AI (source-diff): Bundled Vite chunk, part of same UI build as other accepted files. ai
source-diff obfuscated-file:dist/ui/assets/trace-browser-B7BK2f--.js AI (source-diff): Bundled Vite chunk, part of same UI build as other accepted files. ai
source-diff obfuscated-file:dist/ui/assets/transcript-item-DEZpZ7fg.js AI (source-diff): Bundled Vite chunk, part of same UI build as other accepted files. ai
phantom-deps phantom-dep:@anvia/react-ui AI (phantom-deps): Same-org scope, monorepo build referencing pattern. ai
dependencies unvetted-dep:@anvia/react-ui AI (dependencies): Same-org first-party dependency. ai
source-diff large-new-source-files AI (source-diff): Expected growth from bundled UI assets, not injected code. ai
source-diff bulk-obfuscated-files:dist AI (source-diff): Vite/tsup build output, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/index-D5lHtsjb.js AI (source-diff): Vite bundle output, not obfuscation; fetches are same-origin app APIs. ai
source-diff net-exec-file:dist/ui/assets/index-D5lHtsjb.js AI (source-diff): Vite module-preload fetch polyfill, benign bundled code. ai
source-diff obfuscated-file:dist/ui/assets/index-BImv2lI7.js AI (source-diff): Vite bundle output for the Studio UI, not obfuscation. ai
source-diff net-exec-file:dist/ui/assets/index-BImv2lI7.js AI (source-diff): fetch calls target the package's own local API routes, not exfil. ai
source-diff obfuscated-file:dist/ui/assets/index-BiAp2ncG.js AI (source-diff): Vite-bundled build output, not obfuscation; no malicious behavior in sample. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-rS-P7eLF.js AI (source-diff): Bundled React UI chunk, standard minified output. ai
source-diff obfuscated-file:dist/ui/assets/renderers-Bc89UGTN.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/index-ChlKOnbD.js AI (source-diff): Vite-bundled build output with sourcemaps, not true obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/index-DW3P6_Qc.js AI (source-diff): Vite build bundle with sourcemap; minified not obfuscated. ai
publish-pattern new-deps-added AI (publish-pattern): Well-known UI libs (hugeicons, tanstack router) matching new dashboard features. ai
source-diff obfuscated-file:dist/ui/assets/index-NsFU1TN1.js AI (source-diff): Vite-bundled UI output, matches package's declared build pipeline; no malicious behavior in sample. ai
provenance missing-githead AI (provenance): SLSA provenance attestation present same version; likely CI metadata quirk. ai
source-diff obfuscated-file:dist/ui/assets/index-ZVqWotd2.js AI (source-diff): Vite-bundled output with sourcemap; standard build artifact. ai
source-diff obfuscated-file:dist/ui/assets/index-LEUUFgN3.js AI (source-diff): Vite/esbuild bundle with matching source map; minified build output, not obfuscation. ai
dependencies unvetted-dep:@anvia/server AI (dependencies): Same-org first-party dep for the HTTP runtime; expected. ai
source-diff obfuscated-file:dist/ui/assets/index-DfSrZD9A.js AI (source-diff): Standard Vite-bundled React app output; minification is expected for this UI studio package. ai
source-diff obfuscated-file:dist/ui/assets/status-page-BszwJuUf.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/transcript-item-rmJuWRCF.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/trace-browser-DbNpg0Zk.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/tools-page-B5Sd0DZG.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/sessions-page-C7e2jtjB.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/renderers-DLO8tpZC.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-cgBFM32i.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/memory-page-vAjRwLz5.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/mcps-page-j8Z039bK.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/knowledge-page-BedxCox0.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/index-ga3NT_WB.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-Daw2NBZy.js AI (source-diff): Standard Vite-minified React UI bundle; not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/index-BX1sXbDt.js AI (source-diff): Minified Vite frontend bundle; consistent with vite build in package.json scripts. Not obfuscated malware. ai
source-diff obfuscated-file:dist/ui/assets/index-B0bCx2Nv.js AI (source-diff): Standard Vite-minified frontend bundle with accompanying .map file; expected artifact for a Studio UI package. ai
source-diff obfuscated-file:dist/ui/assets/index-B4i1IueG.js AI (source-diff): Standard Vite/React minified bundle; sample shows normal React scheduler and module-preload polyfill code, not obfuscation. ai
phantom-deps phantom-dep:@anvia/react AI (phantom-deps): Same-org monorepo dep; used in bundled UI assets not directly imported in TS source. ai
source-diff obfuscated-file:dist/ui/assets/transcript-item-GmOQdc53.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/trace-browser-dvGDi7ji.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/tools-page-Dpj7hI8q.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/status-page-a6SMAcLu.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/sessions-page-CV8GZKjN.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/renderers-C8RHOlPz.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/pipelines-page-Byb_JYxi.js AI (source-diff): Standard Vite-minified React UI bundle with D3 dispatcher; no malicious patterns. ai
source-diff obfuscated-file:dist/ui/assets/memory-page-BCv19Tw_.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/mcps-page-B7VAqsoU.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/knowledge-page-DASnGzYP.js AI (source-diff): Standard Vite-minified React UI bundle. ai
source-diff obfuscated-file:dist/ui/assets/jsx-runtime-ZfyQks-z.js AI (source-diff): Bundled React jsx-runtime; sample confirms standard React internals. ai
source-diff obfuscated-file:dist/ui/assets/index-rc2RWnWD.js AI (source-diff): Vite entry bundle with React scheduler and module preload polyfill; no malicious patterns. ai
source-diff obfuscated-file:dist/ui/assets/agents-page-DhI_yXft.js AI (source-diff): Standard Vite-minified React UI bundle; samples confirm legitimate JSX component code. ai
source-diff obfuscated-file:dist/ui/assets/evals-page-Cx4Ycr-Y.js AI (source-diff): Standard Vite-minified React UI bundle. ai
phantom-deps phantom-dep:@phosphor-icons/react AI (phantom-deps): UI dep bundled via Vite; not directly imported in TS entry points. ai
phantom-deps phantom-dep:@xyflow/react AI (phantom-deps): UI dep bundled via Vite; not directly imported in TS entry points. ai
phantom-deps phantom-dep:class-variance-authority AI (phantom-deps): Utility used in bundled component code; stable pattern for this package. ai
phantom-deps phantom-dep:@radix-ui/react-alert-dialog AI (phantom-deps): Radix UI dependency used in bundled components; stable pattern for this package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): React UI library; dependencies used in bundled component exports. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Utility used in bundled component code; stable pattern for this package. ai
phantom-deps phantom-dep:lucide-react AI (phantom-deps): Icon library used in bundled components; stable pattern for this package. ai
phantom-deps phantom-dep:@radix-ui/react-dialog AI (phantom-deps): Radix UI dependency used in bundled components; stable pattern for this package. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Component dependency used in bundled output; stable pattern for this package. ai
phantom-deps phantom-dep:tailwind-merge AI (phantom-deps): Utility used in bundled component code; stable pattern for this package. ai
phantom-deps phantom-dep:@radix-ui/react-slot AI (phantom-deps): Radix UI dependency used in bundled components; stable pattern for this package. ai
phantom-deps phantom-dep:@radix-ui/react-scroll-area AI (phantom-deps): Radix UI dependency used in bundled components; stable pattern for this package. ai
phantom-deps phantom-dep:@radix-ui/react-separator AI (phantom-deps): Radix UI dependency used in bundled components; stable pattern for this package. ai
phantom-deps phantom-dep:react AI (phantom-deps): React UI library; dependencies used in bundled component exports. ai
phantom-deps phantom-dep:@radix-ui/react-select AI (phantom-deps): Radix UI dependency used in bundled components; stable pattern for this package. ai

Versions (showing 62 of 62)

Version Deps Published
0.7.37 20 / 13
0.7.36 20 / 14
0.7.33 20 / 14
0.7.32 20 / 14
0.7.31 20 / 14
0.7.30 20 / 14
0.7.29 20 / 14
0.7.28 20 / 14
0.7.27 20 / 14
0.7.25 20 / 14
0.7.23 20 / 14
0.7.22 20 / 14
0.7.21 20 / 14
0.7.20 20 / 14
0.7.18 20 / 14
0.7.16 20 / 14
0.7.14 20 / 14
0.7.13 20 / 14
0.7.11 20 / 14
0.7.10 20 / 14
0.7.9 20 / 14
0.7.5 20 / 14
0.7.4 19 / 14
0.7.3 19 / 14
0.7.2 18 / 14
0.7.1 18 / 13
0.7.0 19 / 12
0.6.1 19 / 12
0.6.0 19 / 12
0.5.14 19 / 12
0.5.13 19 / 12
0.5.12 19 / 12
0.5.11 19 / 12
0.5.10 19 / 12
0.5.9 19 / 12
0.5.8 19 / 12
0.5.7 19 / 12
0.5.6 19 / 12
0.5.5 19 / 12
0.5.3 19 / 12
0.5.2 19 / 12
0.5.1 17 / 12
0.5.0 17 / 12
0.4.1 17 / 12
0.4.0 17 / 12
0.3.0 17 / 12
0.2.11 17 / 12
0.2.10 17 / 12
0.2.9 17 / 12
0.2.8 17 / 12
0.2.7 17 / 12
0.2.6 17 / 12
0.2.5 17 / 12
0.2.4 17 / 12
0.2.3 17 / 12
0.2.2 17 / 12
0.2.1 17 / 12
0.2.0 17 / 12
0.1.3 16 / 12
0.1.2 16 / 12
0.1.1 16 / 12
0.1.0 16 / 12

v0.7.37

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.36

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-BdDnlVyJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-1QJywSGG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DsFqmLt-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-Bh0HYSnR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-BoMVJjHL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-B-LtyVhA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-DeIlIHCP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-IW2ZAJZw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sandboxes-page-B_Lf-UtP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-DjAuU-RX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-BaDIKvef.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-C5vzRzrt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-ClNVTM2F.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-BQ_YWG4y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-CdsVcgad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.33

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-DN6aZ9dT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-D7w3LxHM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DYwhR8Ly.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-B3e3YF6D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-BeR1NNHY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-DdYD59h4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-SAmGnFSU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-g__90tnX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-CcqIP2r3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-By0mx0ua.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-BDet5qes.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-3F08pehk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.32

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-DN6aZ9dT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-D7w3LxHM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DYwhR8Ly.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-B3e3YF6D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-BeR1NNHY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-DdYD59h4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-SAmGnFSU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-g__90tnX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-CcqIP2r3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-By0mx0ua.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-BDet5qes.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-3F08pehk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.31

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-DN6aZ9dT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-D7w3LxHM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DYwhR8Ly.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-B3e3YF6D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-BeR1NNHY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-DdYD59h4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-SAmGnFSU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-g__90tnX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-CcqIP2r3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-By0mx0ua.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-BDet5qes.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-3F08pehk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.30

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-DN6aZ9dT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-D7w3LxHM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DYwhR8Ly.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-B3e3YF6D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-BeR1NNHY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-DdYD59h4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-SAmGnFSU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-g__90tnX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-CcqIP2r3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-By0mx0ua.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-BDet5qes.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-3F08pehk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.29

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-7nLpk1vO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-CDwzNuFN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DevVjoVt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-gSjG8fUN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-LbQjoiJi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-BDnSsw3p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-DuFkengk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-Cp63l30c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-D09nhpss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-BwgQMVke.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-B7BK2f--.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-DEZpZ7fg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.28

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-7nLpk1vO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-CDwzNuFN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DevVjoVt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-gSjG8fUN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-LbQjoiJi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-BDnSsw3p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-DuFkengk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-Cp63l30c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-D09nhpss.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-BwgQMVke.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-B7BK2f--.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-DEZpZ7fg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.27

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-DYejWQfp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DxSIQUax.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-CpQCK-1A.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-DwZAv13N.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-Cn-wzJHp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-BA9WCR9D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-BuNnb20D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-B8-sSeYx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-5JJHI3LO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-kXLllnlT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-C0vy4e41.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-cUscZoNb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.25

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-BmDCHSPk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-BA0GymcR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DZ8JVRTM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-DLoK8pDp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-CYTlO9u_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-BKuuYE74.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-e_n4UI_v.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-Bso5CKbL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-CSdWatvc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-lKH3Qwic.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-DVjeRRhn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-DHdArePI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.23

13 findings
HIGH New obfuscated file: dist/ui/assets/evals-page-DC-njvlP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-Bc7sqnn5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-BciniOcu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-Dd_gbvBb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-K1u-LDDz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-GOtnu1I3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-zABdhQUl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-BVw1UGMb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-qP32ZAwv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-Brv85Xnm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-mWVtzrMg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-CsKPOoJ7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.21

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-nyn87qWN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-0x7pIugn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-NsFU1TN1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-CYLD4cys.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-Qd4wgj-B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-krtr9o5d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-DNpoe4kw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-m-gqGocU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-Cg-xwPD0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-vgm2JUc7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-zwr5Bxg2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-CmmxKJfO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-FXCuGeXt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-BF9qx3gB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.20

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-nyn87qWN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-CGlZpEpK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DMVhlBNM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DFqZ3jWS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-BcygvPZJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-B3TXiZ88.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-Cae5pcGt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-m-gqGocU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-DvFpN7Rn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-DNc8fCjw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-5wyqco4y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-DLc0kRBh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-DiaDaAtl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-C8rSd3WK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.18

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-nyn87qWN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-CGlZpEpK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DMVhlBNM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-DFqZ3jWS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-BcygvPZJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-B3TXiZ88.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-Cae5pcGt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-m-gqGocU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-DvFpN7Rn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-DNc8fCjw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-5wyqco4y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-DLc0kRBh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-DiaDaAtl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-C8rSd3WK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.16

17 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-nyn87qWN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-CrS8Nw5a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-D5lHtsjb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/index-D5lHtsjb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-bW8GeV7O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-CQV4bt_B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-BCS0r7-V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-COYYrCkj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-m-gqGocU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-DozrArmB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-BLRlLRKt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tool-runner-BB55tqKT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-JpNgNaFG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-41yNH-qC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-DGNb8jMo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.14

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-B8Tw2e11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-w-gdHmQ3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-BImv2lI7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/index-BImv2lI7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-Diqg4sSt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-XTpTg88A.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-DXesSt0M.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-Bk0Qm7db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-CIC1VVRv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-CmDz8RxM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-oWsYfXZZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-C-ht7C6S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-DaE4vnXd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-BqGgawoe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.13

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-B8Tw2e11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-eIWZ_vsI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-CC5mjRie.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/index-CC5mjRie.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-C6WkzIFh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-BJ4m_GoP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-BuerJ-04.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-Dx0uB0Dm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-CIC1VVRv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-UdXui_Zk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-DC5pVW4o.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-ByKfOqk3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-Dk7nD7KO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-DbtXMj-E.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.11

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-B8Tw2e11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-ClnPINSt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-CXap27zX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/index-CXap27zX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-wyfuwf2w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-DG71V11D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-QEPCNhGX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-BIFSxFqj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-CIC1VVRv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-CFBfYAUo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-pMbKI5IR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-D7TbCc2K.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-ENoEi_RW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-C3OIaHK3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.10

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-B8Tw2e11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-BJKMS1fR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DMEhoZEd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/index-DMEhoZEd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-COXaxj3j.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-D1e6dvNE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-Dy11ocsi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-1epSSZ5H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-CIC1VVRv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-BH7t2H-M.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-Dlb6Q1aP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-BCTZ2glH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-CkzLOQ8P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-2OjC7_oe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.9

16 findings
HIGH New obfuscated file: dist/ui/assets/agents-page-B8Tw2e11.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/evals-page-BJKMS1fR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DMEhoZEd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/index-DMEhoZEd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/knowledge-page-COXaxj3j.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/mcps-page-D1e6dvNE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/memory-page-Dy11ocsi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/pipelines-page-1epSSZ5H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/renderers-CIC1VVRv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/sessions-page-BH7t2H-M.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/status-page-Dlb6Q1aP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/tools-page-BCTZ2glH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/trace-browser-CkzLOQ8P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/transcript-item-2OjC7_oe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/utils-BN2yP0LH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.