← Home

@blackbelt-technology/pi-dashboard-web

14
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mbotondmrbencerobertcsakanynorbert.herczeg

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/assets/mermaid.core-C-8kcS7y.js AI (source-diff): Bundled third-party mermaid library, minified build output not obfuscation. ai
phantom-deps phantom-dep:katex AI (phantom-deps): Used indirectly via rehype-katex/remark-math config, standard for markdown rendering stack. ai
source-diff net-exec-file:dist/assets/index-D2KWXuoq.js AI (source-diff): Main SPA bundle; fetch+eval-like patterns expected in React/vite app bundle, not a dropper. ai
source-diff net-exec-file:dist/assets/index-D5AFvJEm.js AI (source-diff): Bundled build artifact; network+eval patterns are from bundled libs, not malicious behavior. ai
source-diff obfuscated-file:dist/assets/index-D5AFvJEm.js AI (source-diff): Bundled vite/mermaid build output, not true obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): katex/remark-math/rehype-katex are legitimate markdown rendering deps matching package.json. ai
source-diff net-exec-file:dist/assets/syntax-D8l2PtGN.js AI (source-diff): Bundled syntax-highlighting chunk, not malicious. ai
phantom-deps phantom-dep:@git-diff-view/lowlight AI (phantom-deps): Frontend bundler resolves config-referenced deps indirectly; stable pattern for this package. ai
phantom-deps phantom-dep:@git-diff-view/react AI (phantom-deps): Frontend bundler resolves config-referenced deps indirectly; stable pattern for this package. ai
phantom-deps phantom-dep:@xterm/addon-attach AI (phantom-deps): Frontend bundler resolves config-referenced deps indirectly; stable pattern for this package. ai
phantom-deps phantom-dep:@git-diff-view/file AI (phantom-deps): Frontend bundler resolves config-referenced deps indirectly; stable pattern for this package. ai
phantom-deps phantom-dep:@blackbelt-technology/pi-dashboard-shared AI (phantom-deps): Same-org scoped dep; normal for monorepo structure; stable for this package. ai
phantom-deps phantom-dep:react-syntax-highlighter AI (phantom-deps): Frontend bundler resolves config-referenced deps indirectly; stable pattern for this package. ai
source-diff net-exec-file:dist/assets/index-eMKR6SK5.js AI (source-diff): Main app bundle; network+exec pattern is normal for a fetch-using SPA bundle. ai
source-diff obfuscated-file:dist/assets/mermaid.core-C2yG7wk7.js AI (source-diff): Mermaid core bundle, minified vendor code not true obfuscation. ai
source-diff net-exec-file:dist/assets/syntax-DUYo-Sh_.js AI (source-diff): Syntax-highlighting vendor bundle, false positive pattern match. ai
source-diff net-exec-file:dist/assets/cytoscape.esm-D_LviqZs.js AI (source-diff): Cytoscape vendor bundle used by mermaid diagrams, not a dropper. ai
phantom-deps phantom-dep:monaco-editor AI (phantom-deps): Used via @monaco-editor/react wrapper, present in dist bundle. ai
source-diff bulk-obfuscated-files:dist AI (source-diff): Vite/esbuild bundled output for monaco/pdfjs/mermaid deps, not true obfuscation. ai
source-diff bulk-net-exec-files:dist AI (source-diff): Bundled worker/vendor chunks (pdf.worker, monaco) contain benign fetch/eval patterns from bundlers. ai
phantom-deps phantom-dep:yaml AI (phantom-deps): Bundled web client; deps used via config/dynamic import not static analysis. ai
phantom-deps phantom-dep:pdfjs-dist AI (phantom-deps): Used in PDF viewer feature, present in dist bundle. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:wouter AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:qrcode AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:react AI (phantom-deps): Vite-bundled React app; deps consumed via build bundle, not direct ESM imports. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Vite-bundled React app; deps consumed via build bundle, not direct ESM imports. ai
phantom-deps phantom-dep:ansi-to-react AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@dnd-kit/core AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@xterm/xterm AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:remark-gfm AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:rehype-raw AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@mdi/react AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:mermaid AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:fuse.js AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@mdi/js AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@dnd-kit/utilities AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@git-diff-view/core AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@dnd-kit/sortable AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai
phantom-deps phantom-dep:@xterm/addon-fit AI (phantom-deps): Vite-bundled app; dependency consumed in bundle. ai

Versions (showing 14 of 14)

Version Deps Published
0.6.1 40 / 13
0.6.0 40 / 13
0.5.4 34 / 12
0.5.3 31 / 12
0.5.2 31 / 12
0.5.1 31 / 12
0.5.0 31 / 12
0.4.6 28 / 12
0.4.5 27 / 12
0.4.4 26 / 12
0.4.3 26 / 12
0.4.2 26 / 12
0.4.1 26 / 12
0.3.0 26 / 12

v0.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.