@baseplate-dev/plugin-queue
Contains the queue plugin for Baseplate
3
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
kingtam2000
Keywords
queuepluginfull-stacktypescriptbaseplatecode-generation
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CyM_kQ9X.js | AI (source-diff): Vite module-federation minified bundle; long lines are standard minification, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DCvygsx4.js | AI (source-diff): Vite module-federation minified bundle; long lines are standard minification, not obfuscation. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Bundled via Vite; declared in dependencies, not directly imported in source but used in build output. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Bundled via Vite; declared in dependencies, not directly imported in source but used in build output. | ai |
v0.6.8
3 findings
HIGH
New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CyM_kQ9X.js
source-diff
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
HIGH
New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DCvygsx4.js
source-diff
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.7
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.