@baseplate-dev/plugin-rate-limit
Contains the rate limiting plugin for Baseplate
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DwukNB6M.js | AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C10hOsxY.js | AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DTGuqAAg.js | AI (source-diff): Vite federation shared-vendor bundle, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New web UI build output for plugin, matches devDeps (vite/react). | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-eZ5JIkIT.js | AI (source-diff): Vite federation shared-vendor bundle, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-rate-limit__remoteEntry_js-Bzgop9wu.js | AI (source-diff): Module Federation remoteEntry helper code, standard preload/import pattern for this plugin's federation architecture. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-yM6V5bRN.js | AI (source-diff): Bundled build output referencing internal utils, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/web/assets/dist-ChLHaafu.js | AI (source-diff): Module-federation runtime bundle, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-D5SGJMcZ.js | AI (source-diff): Vite/module-federation bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.mjs-Cu5-ScS9.js | AI (source-diff): Bundled zod library code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js | AI (source-diff): Vite module-federation shared bundle chunk, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BmG3H7-X.js | AI (source-diff): Vite module-federation shared bundle chunk, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DnsRSA-w.js | AI (source-diff): Vite federation-bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js | AI (source-diff): Vite federation-bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B8hZUfdG.js | AI (source-diff): Vite Module Federation shared-chunk bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Cva-l3cQ.js | AI (source-diff): Vite Module Federation shared-chunk bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-CgzUtb2D.js | AI (source-diff): Minified app bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-BUyS-KhT.js | AI (source-diff): Minified vendor bundle (React) via Vite/rolldown, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js | AI (source-diff): Minified vendor bundle (zod) via Vite/rolldown, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js | AI (source-diff): zod vendor bundle; pattern is bundler code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-rate-limit__remoteEntry_js-DGZq84dK.js | AI (source-diff): Module Federation remote entry runtime, standard for micro-frontend loading. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): All new deps are first-party baseplate packages or well-known UI libs matching plugin's UI feature. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CqXET-2X.js | AI (source-diff): Vite module-federation shared chunk, bundled not obfuscated; maps shipped alongside. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-C4ghWQGL.js | AI (source-diff): Vite module-federation shared chunk, bundled not obfuscated; maps shipped alongside. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BEoACZXa.js | AI (source-diff): Standard Vite module-federation minified bundle; source maps included, consistent with build tooling. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B07HCOxC.js | AI (source-diff): Standard Vite module-federation minified bundle; source maps included, consistent with build tooling. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publisher with SLSA provenance attestation; legitimate automation migration. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-MqpmUdhv.js | AI (source-diff): Standard Vite module-federation minified bundle; readable library code (clsx, tailwind-merge) visible in sample. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DQAPSZRY.js | AI (source-diff): Standard Vite module-federation minified bundle; readable library code visible in sample, not obfuscated malware. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Intentional placeholder stub in a monorepo; no-deps and tiny payload are expected for early 0.0.1 scaffolding releases. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Declared runtime dep used in Vite-bundled output; not a phantom dependency. | ai | |
| phantom-deps | phantom-dep:@baseplate-dev/utils | AI (phantom-deps): Same-org dep declared in dependencies; likely re-exported or used indirectly. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Declared runtime dep used in Vite-bundled output; not a phantom dependency. | ai |
Versions (showing 17 of 17)
| Version | Deps | Published |
|---|---|---|
| 1.0.7 | 9 / 19 | |
| 1.0.1 | 9 / 18 | |
| 1.0.0 | 9 / 18 | |
| 0.6.12 | 11 / 17 | |
| 0.6.11 | 11 / 17 | |
| 0.6.10 | 11 / 17 | |
| 0.6.9 | 11 / 17 | |
| 0.6.8 | 11 / 17 | |
| 0.6.7 | 11 / 17 | |
| 0.6.6 | 11 / 17 | |
| 0.6.5 | 11 / 17 | |
| 0.6.4 | 11 / 17 | |
| 0.6.3 | 11 / 17 | |
| 0.6.2 | 9 / 18 | |
| 0.1.2 | 9 / 18 | |
| 0.1.1 | 9 / 18 | |
| 0.0.1 | 0 / 0 |
v1.0.7
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.0.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v1.0.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.12
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.4
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.6.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.1.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-02-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.1.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-02-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.