@bobfrankston/rmfmail
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| vendored-integrity | tampered-vendored-dep:packages/mailx-settings | AI (vendored-integrity): Only package.json version metadata differs; monorepo workspace self-publish pattern. | ai | |
| vendored-integrity | tampered-vendored-dep:packages/mailx-store-web | AI (vendored-integrity): Only package.json version metadata differs; monorepo workspace self-publish pattern. | ai | |
| dependencies | unvetted-dep:quill | AI (dependencies): quill is a well-known open-source rich text editor; bundled as a client-side dep, stable false positive for this package. | ai | |
| semgrep | semgrep:dll-hijacking-commands | AI (semgrep): Rule fired on a comment explaining safe spawn usage, not an actual DLL hijacking invocation. Stable false positive for this package. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Publisher has 337 versions with automated rapid publishing; consistent pattern for this active project. | ai | |
| phantom-deps | phantom-dep:@bobfrankston/mailx-store-web | AI (phantom-deps): Same-org scoped package; phantom-dep heuristic false positive for this package. | ai | |
| source-diff | encoded-string-file:client/android-bootstrap.bundle.js | AI (source-diff): Encoded string is sql-wasm.wasm bundled as base64 via sql.js — standard legitimate pattern. | ai | |
| phantom-deps | phantom-dep:dictionary-en | AI (phantom-deps): Declared but config-only; same-org package pattern, stable false positive. | ai | |
| phantom-deps | phantom-dep:@bobfrankston/rmf-tiny | AI (phantom-deps): Same-org scoped package; phantom-dep heuristic false positive for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Vendored TinyMCE assets and bundle; expected for this email client package. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth from adding TinyMCE and related editor deps; expected. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): rmfmailto.exe is the package's own mailto: handler binary; present across many versions. | ai | |
| source-diff | obfuscated-file:client/android-bootstrap.bundle.js | AI (source-diff): esbuild-style bundle for Android client; standard bundler output pattern. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside bundled Quill editor (quill.js line 2); standard minified library pattern. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/plugins/emoticons/js/emojis.js | AI (source-diff): Standard TinyMCE vendored emoji data file; large minified data is expected. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/oxide-dark/content.inline.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/oxide/content.inline.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5-dark/content.inline.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5/content.inline.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/oxide-dark/content.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/oxide/content.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5-dark/content.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/skins/ui/tinymce-5/content.js | AI (source-diff): Standard TinyMCE vendored skin file; minified CSS-in-JS is expected for this library. | ai | |
| source-diff | obfuscated-file:client/lib/tinymce/plugins/emoticons/js/emojiimages.js | AI (source-diff): Standard TinyMCE vendored emoji data file; large minified data is expected. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall runs a local node script with no network or shell exec; benign setup pattern for this package. | ai | |
| phantom-deps | phantom-dep:@capacitor/android | AI (phantom-deps): Capacitor deps referenced in config only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@capacitor/core | AI (phantom-deps): Capacitor deps referenced in config only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@capacitor/cli | AI (phantom-deps): Capacitor deps referenced in config only; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:quill | AI (phantom-deps): Referenced in config files only; stable false positive for this package. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP is 127.0.0.1 in a console.log message directing users to local UI; not an outbound network request. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 1.2.168 | 27 / 3 | |
| 1.2.161 | 26 / 3 | |
| 1.2.160 | 26 / 3 | |
| 1.2.131 | 26 / 3 | |
| 1.2.115 | 26 / 3 | |
| 1.2.106 | 26 / 3 | |
| 1.2.87 | 26 / 3 | |
| 1.2.16 | 27 / 3 | |
| 1.1.248 | 27 / 3 | |
| 1.1.232 | 27 / 3 | |
| 1.1.186 | 27 / 3 | |
| 1.1.159 | 27 / 3 | |
| 1.1.158 | 27 / 3 | |
| 1.1.156 | 27 / 3 | |
| 1.1.131 | 27 / 3 | |
| 1.1.106 | 27 / 3 | |
| 1.1.86 | 27 / 3 | |
| 1.1.75 | 27 / 3 | |
| 1.1.33 | 27 / 3 | |
| 1.1.32 | 27 / 3 | |
| 1.1.31 | 27 / 3 | |
| 1.0.705 | 27 / 3 | |
| 1.0.692 | 27 / 3 | |
| 1.0.674 | 25 / 3 | |
| 1.0.662 | 25 / 2 | |
| 1.0.542 | 22 / 1 | |
| 1.0.510 | 22 / 1 | |
| 1.0.500 | 20 / 1 | |
| 1.0.499 | 20 / 1 | |
| 1.0.492 | 20 / 1 | |
| 1.0.487 | 20 / 1 | |
| 1.0.486 | 20 / 1 | |
| 1.0.484 | 20 / 1 | |
| 1.0.479 | 20 / 1 | |
| 1.0.476 | 20 / 1 | |
| 1.0.475 | 20 / 1 | |
| 1.0.473 | 20 / 1 | |
| 1.0.472 | 20 / 1 | |
| 1.0.470 | 20 / 1 | |
| 1.0.469 | 21 / 1 |
v1.2.168
3 findingsThe directory `packages/mailx-store-web` byte-matched 75 of 76 file(s) against @bobfrankston/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: packages/mailx-store-web/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @bobfrankston/[email protected] before greenflagging.
The directory `packages/mailx-settings` byte-matched 35 of 43 file(s) against @bobfrankston/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: packages/mailx-settings/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @bobfrankston/[email protected] before greenflagging.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.161
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.160
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.131
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.115
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.106
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.87
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.