@bigbinary/neeto-commons-frontend
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/cjs/lodash-D5cnLa2T.js | AI (source-diff): Standard lodash 4.17.23 CJS bundle in dist output; canonical MIT-licensed library, not malware. | ai | |
| source-diff | net-exec-file:dist/lodash-DUiF2pG-.js | AI (source-diff): Standard lodash 4.17.23 bundle in dist output; canonical MIT-licensed library, not malware. | ai | |
| source-diff | net-exec-file:dist/lodash-DLwQ1MG1.js | AI (source-diff): Canonical lodash 4.17.23 bundled into dist; dynamic code execution is lodash's template/Function internals, not malware. | ai | |
| source-diff | net-exec-file:dist/cjs/lodash-Cj5Dn9eh.js | AI (source-diff): CJS variant of the same lodash 4.17.23 bundle; same false-positive rationale. | ai | |
| source-diff | net-exec-file:dist/lodash-BE1wh9Io.js | AI (source-diff): Bundled lodash 4.17.23 with canonical MIT header; not malware. | ai | |
| source-diff | net-exec-file:dist/cjs/lodash-CAzW54WT.js | AI (source-diff): CJS variant of bundled lodash 4.17.23; same false-positive pattern. | ai | |
| semgrep | semgrep:silent-process-exec-var | AI (semgrep): Same bundle-analyzer browser-open pattern; not a reverse shell or miner. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require in ESLint config helper to load user config files; documented plugin-loader pattern. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Reads process.env to create esbuild define mappings (webpack-style); standard build-tool pattern, not exfiltration. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used only for bundle-analyzer open and execSync in build config utilities; stable false positive for this package. | ai | |
| semgrep | semgrep:silent-process-exec | AI (semgrep): Opens bundle analyzer HTML report in browser via platform open/start command; benign build-tool pattern stable across versions. | ai |
Versions (showing 12 of 112)
| Version | Deps | Published |
|---|---|---|
| 4.12.3 | 0 / 125 | |
| 4.12.2 | 0 / 125 | |
| 4.12.1 | 0 / 125 | |
| 4.12.0 | 0 / 125 | |
| 4.10.2 | 0 / 125 | |
| 4.10.0 | 0 / 125 | |
| 4.8.12 | 0 / 125 | |
| 4.8.10 | 0 / 125 | |
| 4.8.8 | 0 / 125 | |
| 4.8.6 | 0 / 125 | |
| 4.8.4 | 0 / 125 | |
| 4.8.2 | 0 / 125 |
v4.12.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.12.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.12.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.10.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.8.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.