← Home

@bobfrankston/rmfmail

40
Versions
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

bobfrankston

Keywords

emailimapsmtpmail-clientwebview

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
vendored-integrity tampered-vendored-dep:packages/mailx-settings AI (vendored-integrity): Only package.json version metadata differs; monorepo workspace self-publish pattern. ai
vendored-integrity tampered-vendored-dep:packages/mailx-store-web AI (vendored-integrity): Only package.json version metadata differs; monorepo workspace self-publish pattern. ai
dependencies unvetted-dep:quill AI (dependencies): quill is a well-known open-source rich text editor; bundled as a client-side dep, stable false positive for this package. ai
semgrep semgrep:dll-hijacking-commands AI (semgrep): Rule fired on a comment explaining safe spawn usage, not an actual DLL hijacking invocation. Stable false positive for this package. ai
publish-pattern rapid-publish AI (publish-pattern): Publisher has 337 versions with automated rapid publishing; consistent pattern for this active project. ai
phantom-deps phantom-dep:@bobfrankston/mailx-store-web AI (phantom-deps): Same-org scoped package; phantom-dep heuristic false positive for this package. ai
source-diff encoded-string-file:client/android-bootstrap.bundle.js AI (source-diff): Encoded string is sql-wasm.wasm bundled as base64 via sql.js — standard legitimate pattern. ai
phantom-deps phantom-dep:dictionary-en AI (phantom-deps): Declared but config-only; same-org package pattern, stable false positive. ai
phantom-deps phantom-dep:@bobfrankston/rmf-tiny AI (phantom-deps): Same-org scoped package; phantom-dep heuristic false positive for this package. ai
source-diff large-new-source-files AI (source-diff): Vendored TinyMCE assets and bundle; expected for this email client package. ai
source-diff source-size-tripled AI (source-diff): Growth from adding TinyMCE and related editor deps; expected. ai
npm-metadata bundled-binaries AI (npm-metadata): rmfmailto.exe is the package's own mailto: handler binary; present across many versions. ai
source-diff obfuscated-file:client/android-bootstrap.bundle.js AI (source-diff): esbuild-style bundle for Android client; standard bundler output pattern. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside bundled Quill editor (quill.js line 2); standard minified library pattern. ai
source-diff obfuscated-file:client/lib/tinymce/plugins/emoticons/js/emojis.js AI (source-diff): Standard TinyMCE vendored emoji data file; large minified data is expected. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/oxide-dark/content.inline.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/oxide/content.inline.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5-dark/content.inline.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5/content.inline.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/oxide-dark/content.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/oxide/content.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5-dark/content.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5/content.js AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. ai
source-diff obfuscated-file:client/lib/tinymce/plugins/emoticons/js/emojiimages.js AI (source-diff): Standard TinyMCE vendored emoji data file; large minified data is expected. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall runs a local node script with no network or shell exec; benign setup pattern for this package. ai
phantom-deps phantom-dep:@capacitor/android AI (phantom-deps): Capacitor deps referenced in config only; stable false positive for this package. ai
phantom-deps phantom-dep:@capacitor/core AI (phantom-deps): Capacitor deps referenced in config only; stable false positive for this package. ai
phantom-deps phantom-dep:@capacitor/cli AI (phantom-deps): Capacitor deps referenced in config only; stable false positive for this package. ai
phantom-deps phantom-dep:quill AI (phantom-deps): Referenced in config files only; stable false positive for this package. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP is 127.0.0.1 in a console.log message directing users to local UI; not an outbound network request. ai

Versions (showing 40 of 40)

Version Deps Published
1.2.168 27 / 3
1.2.161 26 / 3
1.2.160 26 / 3
1.2.131 26 / 3
1.2.115 26 / 3
1.2.106 26 / 3
1.2.87 26 / 3
1.2.16 27 / 3
1.1.248 27 / 3
1.1.232 27 / 3
1.1.186 27 / 3
1.1.159 27 / 3
1.1.158 27 / 3
1.1.156 27 / 3
1.1.131 27 / 3
1.1.106 27 / 3
1.1.86 27 / 3
1.1.75 27 / 3
1.1.33 27 / 3
1.1.32 27 / 3
1.1.31 27 / 3
1.0.705 27 / 3
1.0.692 27 / 3
1.0.674 25 / 3
1.0.662 25 / 2
1.0.542 22 / 1
1.0.510 22 / 1
1.0.500 20 / 1
1.0.499 20 / 1
1.0.492 20 / 1
1.0.487 20 / 1
1.0.486 20 / 1
1.0.484 20 / 1
1.0.479 20 / 1
1.0.476 20 / 1
1.0.475 20 / 1
1.0.473 20 / 1
1.0.472 20 / 1
1.0.470 20 / 1
1.0.469 21 / 1

v1.2.168

3 findings
HIGH Modified vendored dependency: packages/mailx-store-web (1 file(s)) vendored-integrity

The directory `packages/mailx-store-web` byte-matched 75 of 76 file(s) against @bobfrankston/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: packages/mailx-store-web/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @bobfrankston/[email protected] before greenflagging.

HIGH Modified vendored dependency: packages/mailx-settings (1 file(s)) vendored-integrity

The directory `packages/mailx-settings` byte-matched 35 of 43 file(s) against @bobfrankston/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: packages/mailx-settings/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @bobfrankston/[email protected] before greenflagging.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.161

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.160

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.131

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.115

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.106

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.87

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.