@baseplate-dev/plugin-email
Contains the email plugin for Baseplate
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CW5A2Km3.js | AI (source-diff): Vite module-federation bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CkHGMgpZ.js | AI (source-diff): Vite module-federation bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Cw1q0m9J.js | AI (source-diff): Minified Vite/module-federation bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Ck1bMD0h.js | AI (source-diff): Minified Vite/module-federation bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/dist-BoFdJr3x.js | AI (source-diff): Module-federation preload/runtime code, no malicious network+exec behavior | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-C-A54zFo.js | AI (source-diff): Vite/module-federation bundled output, not obfuscation | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-CQHjfDEa.js | AI (source-diff): Bundled app code, minified build output. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-email__remoteEntry_js-DSjrGPWp.js | AI (source-diff): Module Federation remoteEntry boilerplate, standard for this architecture. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-D-tyH0Tj.js | AI (source-diff): Vite federation bundle output, not obfuscation; long lines are minified vendor code. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_email__loadShare__zod__loadShare__.js-DsTnm-KM.js | AI (source-diff): Zod validation lib bundle; no exfil behavior, false positive on pattern match. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_email__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DOc3ehsY.js | AI (source-diff): Rolldown/vite bundled vendor code (react), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_email__loadShare__zod__loadShare__.js-DsTnm-KM.js | AI (source-diff): Bundled zod library code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-email__remoteEntry_js-DfNgtFB1.js | AI (source-diff): Module Federation remoteEntry loader boilerplate, standard MF pattern. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-CAlReOKX.js | AI (source-diff): Bundled app code with named exports/comments, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BIjdESNR.js | AI (source-diff): Vite federation bundled shared chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BTNf8col.js | AI (source-diff): Vite federation bundled shared chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-B3EABWK8.js | AI (source-diff): Vite federation shared-chunk bundle output, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New vite module-federation build assets, expected for this monorepo package. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-U4ffOMik.js | AI (source-diff): Vite federation shared-chunk bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BOi2R1-0.js | AI (source-diff): Vite federation bundle chunk, minified not obfuscated, sourcemap present. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party @baseplate-dev monorepo packages at same version. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-7MpcwZj9.js | AI (source-diff): Vite federation bundle chunk, minified not obfuscated, sourcemap present. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Bundled via Vite; not directly imported in source but legitimately declared as a dep. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Bundled via Vite; not directly imported in source but legitimately declared as a dep. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-D9YAtoWY.js | AI (source-diff): Standard Vite module-federation minified bundle with accompanying source map; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components--g7fhuIZ.js | AI (source-diff): Standard Vite module-federation minified bundle with accompanying source map; not obfuscation. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 1.0.7 | 11 / 19 | |
| 1.0.1 | 11 / 18 | |
| 1.0.0 | 11 / 18 | |
| 0.6.12 | 15 / 17 | |
| 0.6.11 | 15 / 17 | |
| 0.6.10 | 15 / 17 | |
| 0.6.9 | 15 / 17 | |
| 0.6.8 | 15 / 17 | |
| 0.6.7 | 15 / 17 | |
| 0.6.6 | 15 / 17 | |
| 0.6.5 | 15 / 17 | |
| 0.6.4 | 14 / 17 | |
| 0.6.3 | 14 / 17 | |
| 0.6.2 | 11 / 18 | |
| 0.1.3 | 11 / 18 | |
| 0.1.2 | 11 / 18 | |
| 0.1.1 | 11 / 18 |
v1.0.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.12
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.