← Home

@baseplate-dev/plugin-storage

Contains the storage plugin for Baseplate

23
Versions
MPL-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

kingtam2000

Keywords

storageplugins3file-storagetypescriptbaseplatefull-stackcode-generation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Bgatm_CO.js AI (source-diff): Vite federation shared-chunk bundle, minified not obfuscated; code is readable utility functions. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BIE0JhkL.js AI (source-diff): Vite federation shared-chunk bundle, minified not obfuscated; code is readable utility functions. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BjxUwg0v.js AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BBOyihUb.js AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Cz7w6p0-.js AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DBtRvLJ4.js AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CFgbyzuE.js AI (source-diff): Vite federation shared bundle, minified build output not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-_w8_YGoL.js AI (source-diff): Vite federation shared bundle, minified build output not obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): First-party monorepo packages published together at same version. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C5PJp0mV.js AI (source-diff): Vite federation bundle output, legible library code, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BNgvvlOp.js AI (source-diff): Vite federation bundle output, legible library code, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-cDk0zPMo.js AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DuP9GPQi.js AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-storage__remoteEntry_js-Bihir0zY.js AI (source-diff): Module Federation remoteEntry boilerplate, not a dropper. ai
source-diff obfuscated-file:dist/web/assets/dist-zrcQEBcF.js AI (source-diff): Bundled Vite/rolldown output, not true obfuscation. ai
source-diff obfuscated-file:dist/web/assets/dist-CJjsSwdt.js AI (source-diff): Bundled app code via rolldown, minified not obfuscated. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js AI (source-diff): Standard zod bundle, no actual network+exec malicious behavior found. ai
source-diff net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-storage__remoteEntry_js-jOVv-saf.js AI (source-diff): Module Federation remoteEntry loader; dynamic import is its documented purpose. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-Cz4IdpSO.js AI (source-diff): Bundled vendor code (react) via rolldown/vite MF build, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js AI (source-diff): Bundled vendor code (zod) via rolldown MF build, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BcH7Nd4r.js AI (source-diff): Vite module-federation bundle output with accompanying source maps, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BDZVgPW9.js AI (source-diff): Vite module-federation bundle output with accompanying source maps, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-By02OXQ9.js AI (source-diff): Vite module-federation bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CFoWFSFb.js AI (source-diff): Vite module-federation bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DzxNNILG.js AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DOsExxvL.js AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. ai
source-diff net-exec-file:dist/web/assets/dist-BIBRfRGG.js AI (source-diff): Module Federation runtime bundle; network+exec is the MF remote loading mechanism, not malware. ai
source-diff obfuscated-file:dist/web/assets/dist-DXywGM-2.js AI (source-diff): Large UI component bundle (2.7MB); minified vite output, consistent with @baseplate-dev/ui-components. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_project_mf_2_builder_mf_2_lib__loadShare__.mjs-CD3wS3ze.js AI (source-diff): Vite preload helper chunk from Module Federation build; standard minified output, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__prebuild__zod__prebuild__-B_ky7z1q.js AI (source-diff): MF prebuild chunk for zod; minified import map, standard build artifact. ai
source-diff obfuscated-file:dist/web/assets/dist-C3Hn-KeL.js AI (source-diff): Bundled plugin library code via rolldown; long lines from minification of legitimate source. ai
source-diff net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.mjs-DOhhqY0u.js AI (source-diff): Network+exec pattern is MF module loading (dynamic import + vitePreload); not dropper behavior. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.mjs-DOhhqY0u.js AI (source-diff): Zod v4 core bundled via rolldown for MF; sample shows legitimate zod source. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__-SxUo9DUh.js AI (source-diff): MF shared module chunk for zod; minified but recognizable zod exports, not obfuscation. ai
source-diff obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.mjs-XNZtq3nP.js AI (source-diff): MF shared module loader for @baseplate-dev/ui-components; standard rolldown/vite output. ai
dependencies unvetted-dep:@hookform/lenses AI (dependencies): @hookform/lenses is a legitimate react-hook-form utility; stable dependency for this package. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): react-dom is explicitly declared in package.json dependencies; phantom-dep heuristic is a false positive for this package. ai

Versions (showing 23 of 23)

Version Deps Published
5.0.1 12 / 18
5.0.0 12 / 18
4.0.3 12 / 18
4.0.2 11 / 18
4.0.1 11 / 18
4.0.0 11 / 17
3.0.4 12 / 17
3.0.3 12 / 17
3.0.2 12 / 17
3.0.1 12 / 17
3.0.0 12 / 17
1.0.7 12 / 19
0.6.12 15 / 17
0.6.11 15 / 17
0.6.10 15 / 17
0.6.9 15 / 17
0.6.8 15 / 17
0.6.7 15 / 17
0.6.6 15 / 17
0.6.5 15 / 17
0.6.4 14 / 17
0.6.3 14 / 17
0.6.2 12 / 18

v5.0.1

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BNgvvlOp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C5PJp0mV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BNgvvlOp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C5PJp0mV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DzxNNILG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DOsExxvL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BBOyihUb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BjxUwg0v.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BcH7Nd4r.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BDZVgPW9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.0

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-cDk0zPMo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DuP9GPQi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.4

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CFoWFSFb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-By02OXQ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CFoWFSFb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-By02OXQ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.2

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CFoWFSFb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-By02OXQ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.7

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DBtRvLJ4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Cz7w6p0-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.12

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-Cz4IdpSO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-zrcQEBcF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-storage__remoteEntry_js-Bihir0zY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.11

6 findings
HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-Cz4IdpSO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/web/assets/dist-CJjsSwdt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-storage__remoteEntry_js-jOVv-saf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.6

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Bgatm_CO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BIE0JhkL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.5

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Bgatm_CO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BIE0JhkL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.4

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-_w8_YGoL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CFgbyzuE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.3

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DBtRvLJ4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Cz7w6p0-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.2

3 findings
HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BNgvvlOp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C5PJp0mV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.