@baseplate-dev/plugin-auth
Contains the auth plugin for Baseplate
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): First-party sibling monorepo packages published in lockstep versioning. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-zJirGIS1.js | AI (source-diff): Vite/module-federation bundled chunk with source map, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Ds8y9Suz.js | AI (source-diff): Bundled vendor chunk (clsx/tailwind-merge/react-hook-form), matches source map. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-D1Dayhn9.js | AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CmgMfkI5.js | AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-auth__remoteEntry_js-Bt9-dftr.js | AI (source-diff): Module Federation remoteEntry.js, standard dynamic-import loader shape. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-C6kDPCTC.js | AI (source-diff): Bundled build output, long lines from bundler not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DkaXS95C.js | AI (source-diff): Vite module-federation bundle output, not obfuscation; imports/exports are readable. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BvL7RO9S.js | AI (source-diff): Vite/module-federation bundled chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DCA3vO4J.js | AI (source-diff): Vite/module-federation bundled chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DFkMnXmX.js | AI (source-diff): Vite federation bundle chunk, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-qf98MMJC.js | AI (source-diff): Vite federation bundle chunk, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DA_4I2Vy.js | AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CcNtL_U6.js | AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-jZLf5m_y.js | AI (source-diff): Vite/federation bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-FK4Jv94w.js | AI (source-diff): Vite/federation bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js | AI (source-diff): Bundled zod dependency chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DsLoA9K7.js | AI (source-diff): Bundled vite/rolldown output (React/Zod deps), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-DicVrB_Z.js | AI (source-diff): Bundled build output from module-federation setup. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.js-DE4UUe5K.js | AI (source-diff): Zod library bundle; no real network+exec payload, false positive on bundled deps. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-auth__remoteEntry_js-CtbvyMZJ.js | AI (source-diff): Module Federation remoteEntry loader — expected dynamic-import mechanism for this plugin architecture. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BpuFQk6s.js | AI (source-diff): Vite module-federation bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-O0clDXMb.js | AI (source-diff): Vite module-federation bundled chunk, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Vite build output growth from federation bundling, expected for this package. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_project_mf_2_builder_mf_2_lib__loadShare__.mjs-DMKuehfC.js | AI (source-diff): Standard Vite preload-helper bundle; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/web/assets/dist-CEUHjZe8.js | AI (source-diff): Dynamic imports in Vite module federation bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-BhvYza4J.js | AI (source-diff): Large Vite bundle for @baseplate-dev/ui-components; expected build artifact. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-B0GpYPx6.js | AI (source-diff): Minified bundle with readable imports from known internal packages; standard build output. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__prebuild__zod__prebuild__-BnF6dd62.js | AI (source-diff): Zod prebuild module federation artifact; legitimate minified output. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.mjs-BalS-ZNe.js | AI (source-diff): Dynamic imports in module federation share shim; not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__.mjs-BalS-ZNe.js | AI (source-diff): Zod v4 core bundle with clear source comments; standard Vite output. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare__zod__loadShare__-BArWH8PX.js | AI (source-diff): Minified zod module federation share; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_tanstack_mf_1_react_mf_2_router__loadShare__.mjs-CCE3BH4R.js | AI (source-diff): Minified @tanstack/react-router bundle; recognizable source, not malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_auth__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.mjs-BwkXxd-B.js | AI (source-diff): Module federation share shim for @baseplate-dev/ui-components; legitimate build output. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is declared and used in config/templates; stable FP for this code-gen plugin. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 5.0.1 | 16 / 18 | |
| 5.0.0 | 16 / 18 | |
| 4.0.3 | 16 / 18 | |
| 4.0.2 | 15 / 18 | |
| 4.0.1 | 13 / 18 | |
| 4.0.0 | 13 / 17 | |
| 3.0.4 | 13 / 17 | |
| 3.0.3 | 13 / 17 | |
| 3.0.2 | 13 / 17 | |
| 3.0.1 | 13 / 17 | |
| 3.0.0 | 13 / 17 | |
| 1.0.7 | 16 / 19 | |
| 0.6.12 | 18 / 17 | |
| 0.6.11 | 18 / 17 | |
| 0.6.10 | 18 / 17 | |
| 0.6.9 | 18 / 17 | |
| 0.6.8 | 18 / 17 | |
| 0.6.7 | 18 / 17 | |
| 0.6.6 | 18 / 17 | |
| 0.6.5 | 18 / 17 | |
| 0.6.4 | 18 / 17 | |
| 0.6.3 | 18 / 17 | |
| 0.6.2 | 16 / 18 |
v5.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.12
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.