@baseplate-dev/plugin-storage
Contains the storage plugin for Baseplate
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-Bgatm_CO.js | AI (source-diff): Vite federation shared-chunk bundle, minified not obfuscated; code is readable utility functions. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BIE0JhkL.js | AI (source-diff): Vite federation shared-chunk bundle, minified not obfuscated; code is readable utility functions. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BjxUwg0v.js | AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BBOyihUb.js | AI (source-diff): Vite module-federation bundled vendor chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-Cz7w6p0-.js | AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DBtRvLJ4.js | AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-CFgbyzuE.js | AI (source-diff): Vite federation shared bundle, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-_w8_YGoL.js | AI (source-diff): Vite federation shared bundle, minified build output not obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): First-party monorepo packages published together at same version. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-C5PJp0mV.js | AI (source-diff): Vite federation bundle output, legible library code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BNgvvlOp.js | AI (source-diff): Vite federation bundle output, legible library code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-cDk0zPMo.js | AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DuP9GPQi.js | AI (source-diff): Vite federation bundle chunk, minified build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-storage__remoteEntry_js-Bihir0zY.js | AI (source-diff): Module Federation remoteEntry boilerplate, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-zrcQEBcF.js | AI (source-diff): Bundled Vite/rolldown output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-CJjsSwdt.js | AI (source-diff): Bundled app code via rolldown, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js | AI (source-diff): Standard zod bundle, no actual network+exec malicious behavior found. | ai | |
| source-diff | net-exec-file:dist/web/assets/virtual_mf-REMOTE_ENTRY_ID___mfe_internal__plugin-storage__remoteEntry_js-jOVv-saf.js | AI (source-diff): Module Federation remoteEntry loader; dynamic import is its documented purpose. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.js-Cz4IdpSO.js | AI (source-diff): Bundled vendor code (react) via rolldown/vite MF build, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.js-Bb5hPRQ9.js | AI (source-diff): Bundled vendor code (zod) via rolldown MF build, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-BcH7Nd4r.js | AI (source-diff): Vite module-federation bundle output with accompanying source maps, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-BDZVgPW9.js | AI (source-diff): Vite module-federation bundle output with accompanying source maps, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-By02OXQ9.js | AI (source-diff): Vite module-federation bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-CFoWFSFb.js | AI (source-diff): Vite module-federation bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/project-builder-lib-DzxNNILG.js | AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/__federation_shared_@baseplate-dev/ui-components-DOsExxvL.js | AI (source-diff): Vite module-federation bundled shared chunk, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/web/assets/dist-BIBRfRGG.js | AI (source-diff): Module Federation runtime bundle; network+exec is the MF remote loading mechanism, not malware. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-DXywGM-2.js | AI (source-diff): Large UI component bundle (2.7MB); minified vite output, consistent with @baseplate-dev/ui-components. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_project_mf_2_builder_mf_2_lib__loadShare__.mjs-CD3wS3ze.js | AI (source-diff): Vite preload helper chunk from Module Federation build; standard minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__prebuild__zod__prebuild__-B_ky7z1q.js | AI (source-diff): MF prebuild chunk for zod; minified import map, standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/web/assets/dist-C3Hn-KeL.js | AI (source-diff): Bundled plugin library code via rolldown; long lines from minification of legitimate source. | ai | |
| source-diff | net-exec-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.mjs-DOhhqY0u.js | AI (source-diff): Network+exec pattern is MF module loading (dynamic import + vitePreload); not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__.mjs-DOhhqY0u.js | AI (source-diff): Zod v4 core bundled via rolldown for MF; sample shows legitimate zod source. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare__zod__loadShare__-SxUo9DUh.js | AI (source-diff): MF shared module chunk for zod; minified but recognizable zod exports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/web/assets/_virtual_mf___mfe_internal__plugin_mf_2_storage__loadShare___mf_0_baseplate_mf_2_dev_mf_1_ui_mf_2_components__loadShare__.mjs-XNZtq3nP.js | AI (source-diff): MF shared module loader for @baseplate-dev/ui-components; standard rolldown/vite output. | ai | |
| dependencies | unvetted-dep:@hookform/lenses | AI (dependencies): @hookform/lenses is a legitimate react-hook-form utility; stable dependency for this package. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): react-dom is explicitly declared in package.json dependencies; phantom-dep heuristic is a false positive for this package. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 5.0.1 | 12 / 18 | |
| 5.0.0 | 12 / 18 | |
| 4.0.3 | 12 / 18 | |
| 4.0.2 | 11 / 18 | |
| 4.0.1 | 11 / 18 | |
| 4.0.0 | 11 / 17 | |
| 3.0.4 | 12 / 17 | |
| 3.0.3 | 12 / 17 | |
| 3.0.2 | 12 / 17 | |
| 3.0.1 | 12 / 17 | |
| 3.0.0 | 12 / 17 | |
| 1.0.7 | 12 / 19 | |
| 0.6.12 | 15 / 17 | |
| 0.6.11 | 15 / 17 | |
| 0.6.10 | 15 / 17 | |
| 0.6.9 | 15 / 17 | |
| 0.6.8 | 15 / 17 | |
| 0.6.7 | 15 / 17 | |
| 0.6.6 | 15 / 17 | |
| 0.6.5 | 15 / 17 | |
| 0.6.4 | 14 / 17 | |
| 0.6.3 | 14 / 17 | |
| 0.6.2 | 12 / 18 |
v5.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.12
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.11
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.