← Home

@baseplate-dev/plugin-payments

Payment processing plugins for Baseplate (Stripe)

11
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kingtam2000

Keywords

baseplatecode-generationfull-stackpaymentspluginstripetypescriptwebhooks

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/web/assets/dist-CKYaQn14.js AI (source-diff): Vite/rolldown bundle output. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-payments__remoteEntry_js-D0gzD6VG.js AI (source-diff): MF remoteEntry loader boilerplate, not malicious. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-payments__remoteEntry_js-4nxeX_OQ.js AI (source-diff): Module Federation remote-entry loader, standard MF runtime pattern. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DWlGENAf.js AI (source-diff): Bundled React/lib source via rolldown, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare__zod__loadShare__.js-D4xDXbmy.js AI (source-diff): Bundled zod library source, not obfuscation. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare__zod__loadShare__.js-D4xDXbmy.js AI (source-diff): Zod bundle chunk; no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/web/assets/dist-BjodyUpg.js AI (source-diff): Rolldown-bundled internal utils, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DAsehJpV.js AI (source-diff): Vite federation shared-chunk bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BrCwHHsT.js AI (source-diff): Vite federation shared-chunk bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CpPboU37.js AI (source-diff): Vite/module-federation bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-dybzUInJ.js AI (source-diff): Vite/module-federation bundled chunk, minified not obfuscated. ai
publish-pattern new-deps-added AI (publish-pattern): First-party @baseplate-dev packages plus standard react/form ecosystem libs. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DBTaQBo3.js AI (source-diff): Vite/module-federation bundled shared chunk, not true obfuscation. ai
source-diff large-new-source-files AI (source-diff): Expected growth from new web UI bundle build output. ai
bogus-package bogus-package AI (bogus-package): Intentional monorepo placeholder; sparse metadata is expected for early-stage scaffold packages in this org. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is a declared runtime dep; phantom-dep false positive for this UI plugin package. ai

Versions (showing 11 of 11)

Version Deps Published
1.0.7 11 / 19
0.6.12 13 / 17
0.6.11 13 / 17
0.6.9 13 / 17
0.6.8 13 / 17
0.6.7 13 / 17
0.6.6 13 / 17
0.6.5 13 / 17
0.6.4 13 / 17
0.6.3 13 / 17
0.0.1 0 / 0

v1.0.7

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DBTaQBo3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.12

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DWlGENAf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare__zod__loadShare__.js-D4xDXbmy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare__zod__loadShare__.js-D4xDXbmy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-BjodyUpg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-payments__remoteEntry_js-4nxeX_OQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.11

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-DWlGENAf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare__zod__loadShare__.js-D4xDXbmy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_payments__loadShare__zod__loadShare__.js-D4xDXbmy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-CKYaQn14.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-payments__remoteEntry_js-D0gzD6VG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.6

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DAsehJpV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BrCwHHsT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.5

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DAsehJpV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BrCwHHsT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.4

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-dybzUInJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CpPboU37.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DBTaQBo3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.