← Home

@baseplate-dev/plugin-observability

Observability plugins for Baseplate (Sentry error monitoring, performance tracking)

12
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kingtam2000

Keywords

baseplatecode-generationerror-monitoringfull-stackobservabilitypluginsentrytypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-eZ5JIkIT.js AI (source-diff): Vite module-federation shared chunk, bundled not obfuscated. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.mjs-C_3Afnrc.js AI (source-diff): Bundled zod/module-federation loader, no malicious network/exec behavior. ai
source-diff obfuscated-file:dist/web/assets/dist-CCdoP-r3.js AI (source-diff): Vite/module-federation bundled output, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js AI (source-diff): Vite module-federation bundle chunk, not obfuscation; readable imports/exports. ai
source-diff obfuscated-file:dist/web/assets/dist-Kz3fjd8u.js AI (source-diff): Bundled app code via rolldown/vite, long lines are minification not obfuscation. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-observability__remoteEntry_js-6H3wEJt3.js AI (source-diff): Standard Module Federation remoteEntry bootstrap, matches package's plugin architecture. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js AI (source-diff): Zod library code, no actual network+exec dropper behavior. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js AI (source-diff): Bundled zod vendor chunk, minified build output. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-observability__remoteEntry_js-DQBxVdnI.js AI (source-diff): Module Federation remoteEntry runtime, standard microfrontend loading, not malware. ai
source-diff obfuscated-file:dist/web/assets/dist-B7uMHx9t.js AI (source-diff): Bundled app code from Vite build, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DCdCzH5F.js AI (source-diff): Bundled react/zod vendor chunk from Vite/Module Federation build, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Expected from new vite build output/federation bundling, not injected code. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js AI (source-diff): Vite module-federation bundle output, not obfuscation; no malicious behavior found. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BEoACZXa.js AI (source-diff): Standard Vite module-federation minified bundle; sample shows readable imports and JSDoc, not obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are first-party @baseplate-dev packages or well-known libs (react, zod); consistent with plugin expansion. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DQAPSZRY.js AI (source-diff): Standard Vite module-federation bundle artifact; long lines are minified but readable imports, not obfuscation. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance attestation; legitimate automation change. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom declared as dep for plugin UI; not directly imported in TS sources but used via bundled Vite output. ai
bogus-package bogus-package AI (bogus-package): Plugin package ships static templates; near-empty dist/index.js and minimal README are expected for this package type. ai
phantom-deps phantom-dep:react-hook-form AI (phantom-deps): react-hook-form declared as dep for plugin UI; referenced in config/templates, not directly imported in main TS sources. ai

Versions (showing 12 of 12)

Version Deps Published
1.0.7 10 / 19
0.6.12 12 / 17
0.6.11 12 / 17
0.6.10 12 / 17
0.6.9 12 / 17
0.6.8 12 / 17
0.6.7 12 / 17
0.6.6 12 / 17
0.6.5 12 / 17
0.6.4 12 / 17
0.6.3 12 / 17
0.0.1 0 / 0

v1.0.7

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.12

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DCdCzH5F.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-B7uMHx9t.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-observability__remoteEntry_js-DQBxVdnI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.11

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DCdCzH5F.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-Kz3fjd8u.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-observability__remoteEntry_js-6H3wEJt3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.6

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.5

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.4

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-eZ5JIkIT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.