@baseplate-dev/plugin-queue
Contains the queue plugin for Baseplate
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-queue__remoteEntry_js-ee2fUE5C.js | AI (source-diff): Module Federation remoteEntry runtime, standard MF loader code. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-C9GOqD0F.js | AI (source-diff): Rolldown-bundled internal utils, minified build output. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CHMXNnFq.js | AI (source-diff): Vite module-federation shared chunk; minified bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DpVrydd-.js | AI (source-diff): Vite module-federation shared chunk; minified bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CW5A2Km3.js | AI (source-diff): Vite module-federation shared bundle, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CkHGMgpZ.js | AI (source-diff): Vite module-federation shared bundle, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-cQ9rsIaT.js | AI (source-diff): Vite federation bundle chunk; minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-TanZLHpg.js | AI (source-diff): Vite federation bundle chunk; minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CjfGU0dv.js | AI (source-diff): Vite module-federation shared bundle, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DOSLyme4.js | AI (source-diff): Vite module-federation shared bundle, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare__zod__loadShare__.js-CJnfyEaU.js | AI (source-diff): Vendored zod bundle chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-CxDLM3JX.js | AI (source-diff): Vite/rolldown module-federation bundle chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-queue__remoteEntry_js-_vlZcAj_.js | AI (source-diff): Module Federation remoteEntry runtime code, standard MF pattern not malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-DMMMVBg9.js | AI (source-diff): Bundled build output from rolldown, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare__zod__loadShare__.js-CJnfyEaU.js | AI (source-diff): Zod library code flagged for generic patterns, no actual dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-7MpcwZj9.js | AI (source-diff): Vite module-federation bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BOi2R1-0.js | AI (source-diff): Vite module-federation bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BTNf8col.js | AI (source-diff): Vite module-federation shared chunk; long lines are bundling, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BIjdESNR.js | AI (source-diff): Vite module-federation shared chunk; long lines are bundling, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DvTB3qFi.js | AI (source-diff): Minified vite-federation shared chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Bd-MB0kB.js | AI (source-diff): Minified vite-federation shared chunk, not true obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected from adding module-federation bundled assets. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Cw1q0m9J.js | AI (source-diff): Vite federation shared bundle, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Ck1bMD0h.js | AI (source-diff): Vite federation shared bundle, minified build output not obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): First-party sibling @baseplate-dev/utils, same monorepo/version. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__prebuild__zod__prebuild__-SKTvqrac.js | AI (source-diff): Prebuild zod share artifact from module-federation; standard minified output. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare__zod__loadShare__.mjs-JzsLkyVQ.js | AI (source-diff): Network+exec pattern is module-federation lazy import machinery, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare__zod__loadShare__.mjs-JzsLkyVQ.js | AI (source-diff): Zod v4 core bundle from module-federation vite plugin; readable source with #region comments. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare__zod__loadShare__-yynxeNOt.js | AI (source-diff): Minified zod share module from module-federation; expected build output. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare___mf_0_tanstack_mf_1_react_mf_2_router__loadShare__.mjs-c9rOnVc6.js | AI (source-diff): Minified @tanstack/react-router bundle from module-federation vite plugin; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare___mf_0_baseplate_mf_2_dev_mf_1_project_mf_2_builder_mf_2_lib__loadShare__.mjs-B3WARY8S.js | AI (source-diff): Standard Vite module-federation build artifact; minified but not obfuscated, readable source comments present. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_queue__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.mjs-C9UZNSRm.js | AI (source-diff): Module-federation share shim for @baseplate-dev/ui-components; expected build output. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-yawol7j7.js | AI (source-diff): Vite-built minified bundle; standard build output for this package. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-BzC6J7fa.js | AI (source-diff): Vite-built minified bundle; standard build output for this package. | ai | |
| source-diff | net-exec-file:dist/web/assets/dist-BmoxLRna.js | AI (source-diff): Module-federation runtime bundle with FEDERATION_DEBUG references; legitimate build artifact. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DCvygsx4.js | AI (source-diff): Vite module-federation minified bundle; long lines are standard minification, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CyM_kQ9X.js | AI (source-diff): Vite module-federation minified bundle; long lines are standard minification, not obfuscation. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Bundled via Vite; declared in dependencies, not directly imported in source but used in build output. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Bundled via Vite; declared in dependencies, not directly imported in source but used in build output. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 3.0.1 | 10 / 18 | |
| 3.0.0 | 10 / 18 | |
| 2.0.3 | 10 / 18 | |
| 2.0.2 | 10 / 18 | |
| 2.0.1 | 10 / 18 | |
| 2.0.0 | 9 / 17 | |
| 1.0.7 | 10 / 19 | |
| 1.0.4 | 9 / 17 | |
| 1.0.3 | 9 / 17 | |
| 1.0.2 | 9 / 17 | |
| 1.0.1 | 9 / 17 | |
| 1.0.0 | 9 / 17 | |
| 0.6.12 | 12 / 17 | |
| 0.6.11 | 12 / 17 | |
| 0.6.10 | 12 / 17 | |
| 0.6.9 | 12 / 17 | |
| 0.6.8 | 12 / 17 | |
| 0.6.7 | 12 / 17 | |
| 0.6.6 | 12 / 17 | |
| 0.6.5 | 12 / 17 | |
| 0.6.3 | 12 / 17 | |
| 0.6.2 | 10 / 18 |
v3.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.12
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.