@askrjs/askr
Actor-backed deterministic UI framework
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@askrjs/schema | AI (dependencies): First-party sibling package under same @askrjs org. | ai | |
| source-diff | net-exec-file:dist/ssr-D3t80Rc0.js | AI (source-diff): SSR bundle code, not a loader/dropper; sample shows framework internals only. | ai | |
| dependencies | unvetted-dep:@askrjs/auth | AI (dependencies): First-party sibling package under same @askrjs org. | ai | |
| source-diff | obfuscated-file:dist/runtime/fastlane.js | AI (source-diff): Minified Vite build output of fastlane optimization module. | ai | |
| source-diff | obfuscated-file:dist/node_modules/esbuild/lib/main.js | AI (source-diff): Bundled esbuild library, well-known tool; minification is expected. | ai | |
| source-diff | obfuscated-file:dist/runtime/operations.js | AI (source-diff): Minified Vite build output of resource/state operations module. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions CI with SLSA provenance attestation; this is the expected CI publishing pattern. | ai | |
| source-diff | obfuscated-file:dist/renderer/evaluate.js | AI (source-diff): Vite-minified renderer output; readable evaluation logic, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/runtime/component.js | AI (source-diff): Vite-minified framework output; readable logic, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/ssg/create-static-gen.js | AI (source-diff): Vite-minified SSG output; readable SSG pipeline logic, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/renderer/dom.js | AI (source-diff): Vite-minified renderer output; readable DOM reconciliation logic, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/runtime/for.js | AI (source-diff): Vite-minified runtime output; readable for-loop reconciliation logic, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/boot/index.js | AI (source-diff): Vite-minified boot/entry output; readable app bootstrap logic, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/main-EPE35NMW.js | AI (source-diff): tsup/esbuild minified bundle output; not obfuscated, stable pattern for this package. | ai |
Versions (showing 50 of 50)
| Version | Deps | Published |
|---|---|---|
| 0.0.53 | 2 / 10 | |
| 0.0.52 | 1 / 10 | |
| 0.0.51 | 0 / 8 | |
| 0.0.50 | 0 / 8 | |
| 0.0.49 | 0 / 8 | |
| 0.0.48 | 0 / 8 | |
| 0.0.47 | 0 / 8 | |
| 0.0.46 | 0 / 8 | |
| 0.0.45 | 0 / 8 | |
| 0.0.44 | 0 / 7 | |
| 0.0.43 | 0 / 7 | |
| 0.0.42 | 0 / 7 | |
| 0.0.41 | 0 / 7 | |
| 0.0.40 | 0 / 7 | |
| 0.0.39 | 0 / 7 | |
| 0.0.38 | 0 / 7 | |
| 0.0.37 | 0 / 7 | |
| 0.0.36 | 0 / 8 | |
| 0.0.35 | 0 / 8 | |
| 0.0.34 | 0 / 8 | |
| 0.0.33 | 0 / 8 | |
| 0.0.31 | 0 / 8 | |
| 0.0.30 | 0 / 8 | |
| 0.0.29 | 0 / 8 | |
| 0.0.28 | 0 / 13 | |
| 0.0.27 | 0 / 13 | |
| 0.0.26 | 0 / 13 | |
| 0.0.25 | 0 / 13 | |
| 0.0.24 | 0 / 13 | |
| 0.0.21 | 0 / 14 | |
| 0.0.20 | 0 / 14 | |
| 0.0.19 | 0 / 14 | |
| 0.0.18 | 0 / 14 | |
| 0.0.17 | 0 / 14 | |
| 0.0.16 | 0 / 14 | |
| 0.0.15 | 0 / 14 | |
| 0.0.14 | 0 / 14 | |
| 0.0.13 | 0 / 14 | |
| 0.0.12 | 0 / 14 | |
| 0.0.11 | 0 / 14 | |
| 0.0.10 | 0 / 14 | |
| 0.0.9 | 0 / 14 | |
| 0.0.8 | 0 / 14 | |
| 0.0.7 | 0 / 14 | |
| 0.0.6 | 0 / 14 | |
| 0.0.5 | 0 / 13 | |
| 0.0.4 | 0 / 14 | |
| 0.0.3 | 0 / 14 | |
| 0.0.2 | 0 / 14 | |
| 0.0.1 | 0 / 14 |
v0.0.53
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.52
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.51
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.50
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.49
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.48
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.47
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.0.46
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.