← Home

@bigbinary/neeto-image-uploader-frontend

22
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

neerajdotnamebigbinarybotneetohq

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-IvuywClK.js AI (source-diff): Standard Rollup minified bundle with readable imports and source maps; not obfuscated. ai
source-diff obfuscated-file:dist/index-CSoe203Z.js AI (source-diff): Standard Rollup minified bundle with readable imports and source maps; not obfuscated. ai
source-diff obfuscated-file:dist/useUnsplashApi-D_ekWD8p.js AI (source-diff): Standard Rollup minified bundle with source maps; readable imports and no malicious patterns. ai
source-diff obfuscated-file:dist/useUnsplashApi-CNeNh58q.js AI (source-diff): Standard Rollup minified bundle with source maps; readable imports and no malicious patterns. ai
source-diff obfuscated-file:dist/index-BF9s4sZW.js AI (source-diff): Standard Rollup minified bundle output; consistent with this package's build pattern across all versions. ai
source-diff obfuscated-file:dist/index-DhN-kj31.js AI (source-diff): Standard Rollup CJS bundle output; consistent with this package's build pattern across all versions. ai
source-diff obfuscated-file:dist/index-bQG7L4n2.js AI (source-diff): Standard Rollup minified bundle with source maps; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-DxJCT8T_.js AI (source-diff): Standard Rollup minified bundle with source maps; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-Dduujv9L.js AI (source-diff): Standard Rollup minified bundle with source maps; not obfuscated, consistent with this package's build pattern. ai
source-diff obfuscated-file:dist/index-DuWEAQqg.js AI (source-diff): Standard Rollup minified bundle with source maps; not obfuscated, consistent with this package's build pattern. ai
source-diff obfuscated-file:dist/index-CNh5QhLZ.js AI (source-diff): Standard Rollup minified bundle with readable imports and source maps; not obfuscated. ai
source-diff obfuscated-file:dist/index-BymDrsS4.js AI (source-diff): Standard Rollup minified bundle with readable imports and source maps; not obfuscated. ai
source-diff obfuscated-file:dist/index-BGVHZZys.js AI (source-diff): Standard Rollup minified bundle with readable imports; not obfuscated malware. ai
source-diff obfuscated-file:dist/index-CjVmJmv5.js AI (source-diff): Standard Rollup minified bundle with readable imports; not obfuscated malware. ai
phantom-deps phantom-dep:react-router-nav-prompt AI (phantom-deps): Used as a runtime dep bundled into dist; not directly imported in source but legitimately declared. ai
phantom-deps phantom-dep:babel-plugin-transform-imports AI (phantom-deps): Build-time Babel plugin referenced in config; not imported in source by design. ai
dependencies unvetted-dep:react-router-nav-prompt AI (dependencies): Small, stable React library with no known advisories; consistent use across this package family. ai

Versions (showing 22 of 22)

Version Deps Published
4.0.6 2 / 127
4.0.5 2 / 127
4.0.4 2 / 127
4.0.3 2 / 126
4.0.2 2 / 126
4.0.1 2 / 126
4.0.0 2 / 126
3.0.7 2 / 126
3.0.6 2 / 126
3.0.5 2 / 126
3.0.4 2 / 127
3.0.3 2 / 127
3.0.2 2 / 127
3.0.1 2 / 128
3.0.0 2 / 128
2.3.37 2 / 128
2.3.36 2 / 128
2.3.35 2 / 128
2.3.34 2 / 128
2.3.33 2 / 128
2.3.32 2 / 128
2.3.31 2 / 128

v4.0.6

3 findings
HIGH New obfuscated file: dist/useUnsplashApi-CNeNh58q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/useUnsplashApi-D_ekWD8p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.5

3 findings
HIGH New obfuscated file: dist/useUnsplashApi-CNeNh58q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/useUnsplashApi-D_ekWD8p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.4

3 findings
HIGH New obfuscated file: dist/useUnsplashApi-CNeNh58q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/useUnsplashApi-D_ekWD8p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.0.2

3 findings
HIGH New obfuscated file: dist/index-BGVHZZys.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CjVmJmv5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.1

3 findings
HIGH New obfuscated file: dist/index-BGVHZZys.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CjVmJmv5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.0.0

3 findings
HIGH New obfuscated file: dist/index-BGVHZZys.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CjVmJmv5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.7

3 findings
HIGH New obfuscated file: dist/index-BGVHZZys.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CjVmJmv5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.6

3 findings
HIGH New obfuscated file: dist/index-BF9s4sZW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DhN-kj31.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.5

3 findings
HIGH New obfuscated file: dist/index-BF9s4sZW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DhN-kj31.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.4

3 findings
HIGH New obfuscated file: dist/index-DxJCT8T_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-bQG7L4n2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.3

3 findings
HIGH New obfuscated file: dist/index-Dduujv9L.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-DuWEAQqg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.2

3 findings
HIGH New obfuscated file: dist/index-CSoe203Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-IvuywClK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

3 findings
HIGH New obfuscated file: dist/index-CSoe203Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-IvuywClK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

3 findings
HIGH New obfuscated file: dist/index-BymDrsS4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CNh5QhLZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.