@baseplate-dev/plugin-observability
Observability plugins for Baseplate (Sentry error monitoring, performance tracking)
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-eZ5JIkIT.js | AI (source-diff): Vite module-federation shared chunk, bundled not obfuscated. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.mjs-C_3Afnrc.js | AI (source-diff): Bundled zod/module-federation loader, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-CCdoP-r3.js | AI (source-diff): Vite/module-federation bundled output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js | AI (source-diff): Vite module-federation bundle chunk, not obfuscation; readable imports/exports. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-Kz3fjd8u.js | AI (source-diff): Bundled app code via rolldown/vite, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-observability__remoteEntry_js-6H3wEJt3.js | AI (source-diff): Standard Module Federation remoteEntry bootstrap, matches package's plugin architecture. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js | AI (source-diff): Zod library code, no actual network+exec dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare__zod__loadShare__.js-Bt0N5IPl.js | AI (source-diff): Bundled zod vendor chunk, minified build output. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-observability__remoteEntry_js-DQBxVdnI.js | AI (source-diff): Module Federation remoteEntry runtime, standard microfrontend loading, not malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-B7uMHx9t.js | AI (source-diff): Bundled app code from Vite build, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_observability__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DCdCzH5F.js | AI (source-diff): Bundled react/zod vendor chunk from Vite/Module Federation build, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected from new vite build output/federation bundling, not injected code. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js | AI (source-diff): Vite module-federation bundle output, not obfuscation; no malicious behavior found. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BEoACZXa.js | AI (source-diff): Standard Vite module-federation minified bundle; sample shows readable imports and JSDoc, not obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are first-party @baseplate-dev packages or well-known libs (react, zod); consistent with plugin expansion. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DQAPSZRY.js | AI (source-diff): Standard Vite module-federation bundle artifact; long lines are minified but readable imports, not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance attestation; legitimate automation change. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom declared as dep for plugin UI; not directly imported in TS sources but used via bundled Vite output. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Plugin package ships static templates; near-empty dist/index.js and minimal README are expected for this package type. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): react-hook-form declared as dep for plugin UI; referenced in config/templates, not directly imported in main TS sources. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 1.0.7 | 10 / 19 | |
| 0.6.12 | 12 / 17 | |
| 0.6.11 | 12 / 17 | |
| 0.6.10 | 12 / 17 | |
| 0.6.9 | 12 / 17 | |
| 0.6.8 | 12 / 17 | |
| 0.6.7 | 12 / 17 | |
| 0.6.6 | 12 / 17 | |
| 0.6.5 | 12 / 17 | |
| 0.6.4 | 12 / 17 | |
| 0.6.3 | 12 / 17 | |
| 0.0.1 | 0 / 0 |
v1.0.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.12
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.