← Home

@baseplate-dev/plugin-auth

Contains the auth plugin for Baseplate

23
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kingtam2000

Keywords

authenticationpluginfull-stacktypescriptbaseplatecode-generation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): First-party sibling monorepo packages published in lockstep versioning. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-zJirGIS1.js AI (source-diff): Vite/module-federation bundled chunk with source map, not true obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Ds8y9Suz.js AI (source-diff): Bundled vendor chunk (clsx/tailwind-merge/react-hook-form), matches source map. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-D1Dayhn9.js AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CmgMfkI5.js AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-auth__remoteEntry_js-Bt9-dftr.js AI (source-diff): Module Federation remoteEntry.js, standard dynamic-import loader shape. ai
source-diff obfuscated-file:dist/web/assets/dist-C6kDPCTC.js AI (source-diff): Bundled build output, long lines from bundler not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DkaXS95C.js AI (source-diff): Vite module-federation bundle output, not obfuscation; imports/exports are readable. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BvL7RO9S.js AI (source-diff): Vite/module-federation bundled chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DCA3vO4J.js AI (source-diff): Vite/module-federation bundled chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DFkMnXmX.js AI (source-diff): Vite federation bundle chunk, not obfuscated code. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-qf98MMJC.js AI (source-diff): Vite federation bundle chunk, not obfuscated code. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DA_4I2Vy.js AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CcNtL_U6.js AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-jZLf5m_y.js AI (source-diff): Vite/federation bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-FK4Jv94w.js AI (source-diff): Vite/federation bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js AI (source-diff): Bundled zod dependency chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DsLoA9K7.js AI (source-diff): Bundled vite/rolldown output (React/Zod deps), not true obfuscation. ai
source-diff obfuscated-file:dist/web/assets/dist-DicVrB_Z.js AI (source-diff): Bundled build output from module-federation setup. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js AI (source-diff): Zod library bundle; no real network+exec payload, false positive on bundled deps. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-auth__remoteEntry_js-CtbvyMZJ.js AI (source-diff): Module Federation remoteEntry loader — expected dynamic-import mechanism for this plugin architecture. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BpuFQk6s.js AI (source-diff): Vite module-federation bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-O0clDXMb.js AI (source-diff): Vite module-federation bundled chunk, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Vite build output growth from federation bundling, expected for this package. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_project_mf_2_builder_mf_2_lib__loadShare__.mjs-DMKuehfC.js AI (source-diff): Standard Vite preload-helper bundle; not obfuscated malware. ai
source-diff net-exec-file:dist/web/assets/dist-CEUHjZe8.js AI (source-diff): Dynamic imports in Vite module federation bundle; not malicious. ai
source-diff obfuscated-file:dist/web/assets/dist-BhvYza4J.js AI (source-diff): Large Vite bundle for @baseplate-dev/ui-components; expected build artifact. ai
source-diff obfuscated-file:dist/web/assets/dist-B0GpYPx6.js AI (source-diff): Minified bundle with readable imports from known internal packages; standard build output. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__prebuild__zod__prebuild__-BnF6dd62.js AI (source-diff): Zod prebuild module federation artifact; legitimate minified output. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.mjs-BalS-ZNe.js AI (source-diff): Dynamic imports in module federation share shim; not dropper malware. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.mjs-BalS-ZNe.js AI (source-diff): Zod v4 core bundle with clear source comments; standard Vite output. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__-BArWH8PX.js AI (source-diff): Minified zod module federation share; legitimate build artifact. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_tanstack_mf_1_react_mf_2_router__loadShare__.mjs-CCE3BH4R.js AI (source-diff): Minified @tanstack/react-router bundle; recognizable source, not malware. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.mjs-BwkXxd-B.js AI (source-diff): Module federation share shim for @baseplate-dev/ui-components; legitimate build output. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is declared and used in config/templates; stable FP for this code-gen plugin. ai

Versions (showing 23 of 23)

Version Deps Published
5.0.1 16 / 18
5.0.0 16 / 18
4.0.3 16 / 18
4.0.2 15 / 18
4.0.1 13 / 18
4.0.0 13 / 17
3.0.4 13 / 17
3.0.3 13 / 17
3.0.2 13 / 17
3.0.1 13 / 17
3.0.0 13 / 17
1.0.7 16 / 19
0.6.12 18 / 17
0.6.11 18 / 17
0.6.10 18 / 17
0.6.9 18 / 17
0.6.8 18 / 17
0.6.7 18 / 17
0.6.6 18 / 17
0.6.5 18 / 17
0.6.4 18 / 17
0.6.3 18 / 17
0.6.2 16 / 18

v5.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-qf98MMJC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DFkMnXmX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-O0clDXMb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BpuFQk6s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CmgMfkI5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-D1Dayhn9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.0

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CcNtL_U6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DA_4I2Vy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.4

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-FK4Jv94w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-jZLf5m_y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-FK4Jv94w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-jZLf5m_y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.2

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-FK4Jv94w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-jZLf5m_y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.7

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DCA3vO4J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BvL7RO9S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.12

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DsLoA9K7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-DicVrB_Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-auth__remoteEntry_js-CtbvyMZJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.11

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DsLoA9K7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-C6kDPCTC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-auth__remoteEntry_js-Bt9-dftr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.6

2 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DkaXS95C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.5

2 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DkaXS95C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.4

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-zJirGIS1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Ds8y9Suz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DCA3vO4J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BvL7RO9S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.