← Home

@baseplate-dev/plugin-rate-limit

Contains the rate limiting plugin for Baseplate

17
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kingtam2000

Keywords

baseplatecode-generationfull-stackpluginrate-limitrate-limitingtypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DwukNB6M.js AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C10hOsxY.js AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DTGuqAAg.js AI (source-diff): Vite federation shared-vendor bundle, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): New web UI build output for plugin, matches devDeps (vite/react). ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-eZ5JIkIT.js AI (source-diff): Vite federation shared-vendor bundle, not obfuscation. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-rate-limit__remoteEntry_js-Bzgop9wu.js AI (source-diff): Module Federation remoteEntry helper code, standard preload/import pattern for this plugin's federation architecture. ai
source-diff obfuscated-file:dist/web/assets/dist-yM6V5bRN.js AI (source-diff): Bundled build output referencing internal utils, minified not obfuscated. ai
source-diff net-exec-file:dist/web/assets/dist-ChLHaafu.js AI (source-diff): Module-federation runtime bundle, no malicious network/exec behavior. ai
source-diff obfuscated-file:dist/web/assets/dist-D5SGJMcZ.js AI (source-diff): Vite/module-federation bundled output, not true obfuscation. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.mjs-Cu5-ScS9.js AI (source-diff): Bundled zod library code, not a dropper. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js AI (source-diff): Vite module-federation shared bundle chunk, not obfuscated malware. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BmG3H7-X.js AI (source-diff): Vite module-federation shared bundle chunk, not obfuscated malware. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DnsRSA-w.js AI (source-diff): Vite federation-bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js AI (source-diff): Vite federation-bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B8hZUfdG.js AI (source-diff): Vite Module Federation shared-chunk bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Cva-l3cQ.js AI (source-diff): Vite Module Federation shared-chunk bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/dist-CgzUtb2D.js AI (source-diff): Minified app bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-BUyS-KhT.js AI (source-diff): Minified vendor bundle (React) via Vite/rolldown, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js AI (source-diff): Minified vendor bundle (zod) via Vite/rolldown, not obfuscation. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js AI (source-diff): zod vendor bundle; pattern is bundler code, not a dropper. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-rate-limit__remoteEntry_js-DGZq84dK.js AI (source-diff): Module Federation remote entry runtime, standard for micro-frontend loading. ai
publish-pattern new-deps-added AI (publish-pattern): All new deps are first-party baseplate packages or well-known UI libs matching plugin's UI feature. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CqXET-2X.js AI (source-diff): Vite module-federation shared chunk, bundled not obfuscated; maps shipped alongside. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-C4ghWQGL.js AI (source-diff): Vite module-federation shared chunk, bundled not obfuscated; maps shipped alongside. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BEoACZXa.js AI (source-diff): Standard Vite module-federation minified bundle; source maps included, consistent with build tooling. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B07HCOxC.js AI (source-diff): Standard Vite module-federation minified bundle; source maps included, consistent with build tooling. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publisher with SLSA provenance attestation; legitimate automation migration. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-MqpmUdhv.js AI (source-diff): Standard Vite module-federation minified bundle; readable library code (clsx, tailwind-merge) visible in sample. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DQAPSZRY.js AI (source-diff): Standard Vite module-federation minified bundle; readable library code visible in sample, not obfuscated malware. ai
bogus-package bogus-package AI (bogus-package): Intentional placeholder stub in a monorepo; no-deps and tiny payload are expected for early 0.0.1 scaffolding releases. ai
phantom-deps phantom-dep:react-hook-form AI (phantom-deps): Declared runtime dep used in Vite-bundled output; not a phantom dependency. ai
phantom-deps phantom-dep:@baseplate-dev/utils AI (phantom-deps): Same-org dep declared in dependencies; likely re-exported or used indirectly. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Declared runtime dep used in Vite-bundled output; not a phantom dependency. ai

Versions (showing 17 of 17)

Version Deps Published
1.0.7 9 / 19
1.0.1 9 / 18
1.0.0 9 / 18
0.6.12 11 / 17
0.6.11 11 / 17
0.6.10 11 / 17
0.6.9 11 / 17
0.6.8 11 / 17
0.6.7 11 / 17
0.6.6 11 / 17
0.6.5 11 / 17
0.6.4 11 / 17
0.6.3 11 / 17
0.6.2 9 / 18
0.1.2 9 / 18
0.1.1 9 / 18
0.0.1 0 / 0

v1.0.7

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DnsRSA-w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.1

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Cva-l3cQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B8hZUfdG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.0

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Cva-l3cQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B8hZUfdG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.12

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-BUyS-KhT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-CgzUtb2D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-rate-limit__remoteEntry_js-DGZq84dK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.11

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-BUyS-KhT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_rate_mf_2_limit__loadShare__zod__loadShare__.js-CvzaKfyV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-yM6V5bRN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-rate-limit__remoteEntry_js-Bzgop9wu.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.6

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BmG3H7-X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-24, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-24, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.5

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DvJeDMnL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BmG3H7-X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.4

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-eZ5JIkIT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DTGuqAAg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.3

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DIqmjKSb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DnsRSA-w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.2

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Cva-l3cQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-B8hZUfdG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-03-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-03-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.1.2

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DwukNB6M.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C10hOsxY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-02-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-02-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.1.1

4 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-C4ghWQGL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CqXET-2X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: kingtam2000 → GitHub Actions (on 2026-02-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (kingtam2000) on 2026-02-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.