← Home

@apm-js-collab/code-transformer-bundler-plugins

14
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

timfishbizob2828

Keywords

rollupwebpackviteesbuildbunturbopackloaderplugininstrumentationapmtracingtransform

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cjs/core-B2U2YJvQ.cjs AI (source-diff): Vite/rollup bundled minified output, not obfuscation; hashed filenames change per build. ai
source-diff obfuscated-file:dist/esm/core-dC9TN3Ev.mjs AI (source-diff): Vite/rollup bundled minified ESM output, not obfuscation. ai
source-diff obfuscated-file:dist/cjs/core-DCHzVZ6n.cjs AI (source-diff): Vite/rollup bundled output, not obfuscation; stable for this bundler plugin. ai
source-diff obfuscated-file:dist/esm/core-IEahUYJE.mjs AI (source-diff): Bundled ESM output; long lines are minified deps, no malicious behavior. ai
phantom-deps phantom-dep:magic-string AI (phantom-deps): Build-time dep used by bundler transforms; not directly imported by design. ai
phantom-deps phantom-dep:es-module-lexer AI (phantom-deps): Bundled into dist; declared dep, stable false positive. ai

Versions (showing 14 of 14)

Version Deps Published
0.7.3 4 / 10
0.7.2 4 / 10
0.7.1 4 / 11
0.7.0 4 / 11
0.6.2 4 / 10
0.6.1 4 / 10
0.6.0 4 / 10
0.5.0 4 / 10
0.4.0 3 / 10
0.3.0 2 / 10
0.2.4 3 / 9
0.2.3 3 / 8
0.2.1 3 / 8
0.1.0 3 / 11

v0.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.0

3 findings
HIGH New obfuscated file: dist/cjs/core-B2U2YJvQ.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/core-dC9TN3Ev.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.1

3 findings
HIGH New obfuscated file: dist/cjs/core-DCHzVZ6n.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/esm/core-IEahUYJE.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.