@botfabrik/engine-webclient
Webclient for Botfabriks Bot Engine
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/assets/index-CxHubEDR.js | AI (source-diff): Vite-bundled frontend asset; long lines are minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-CxHubEDR.js | AI (source-diff): Browser webclient bundle; fetch + dynamic module loading is expected behavior for this package. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-DauCjPQ8.js | AI (source-diff): Browser fetch + dynamic module loading in a webclient bundle is normal; no hostile destination or dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DauCjPQ8.js | AI (source-diff): Standard Vite/esbuild minified bundle output; not true obfuscation. Expected artifact for a webclient package. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-Dwmr7EiL.js | AI (source-diff): Network+exec pattern is standard browser bundle behavior (fetch for modulepreload); no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Dwmr7EiL.js | AI (source-diff): Minified Vite/esbuild browser bundle; no true obfuscation signatures present. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-TmZ0K7Wr.js | AI (source-diff): Standard Vite/esbuild frontend bundle with source map; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-TmZ0K7Wr.js | AI (source-diff): Network calls and dynamic patterns are normal in a bundled webclient SPA; no hostile destination or dropper behavior. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-B23oVAYe.js | AI (source-diff): Network calls are browser fetch for modulepreload; no dropper/loader behavior in the sample. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-B23oVAYe.js | AI (source-diff): Standard Vite/esbuild minified bundle output; no true obfuscation signatures present. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DR0rhLK_.js | AI (source-diff): Standard Vite-bundled React client asset; minified but not obfuscated. Stable pattern for this package. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-DR0rhLK_.js | AI (source-diff): Network calls and dynamic code in a browser bundle are normal React/Vite output; no dropper behavior present. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BFYEgcht.js | AI (source-diff): Vite-bundled React frontend output; minification is expected for this webclient package. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-BFYEgcht.js | AI (source-diff): Network calls and dynamic execution are normal browser-side React app behavior; no exfil or dropper pattern present. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-qmz848Sp.js | AI (source-diff): Standard Vite-bundled React client asset; long lines are minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-qmz848Sp.js | AI (source-diff): Network calls are browser fetch() for modulepreload; dynamic execution is React scheduler — normal bundled client code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Dgye-P8u.js | AI (source-diff): Vite-bundled client asset; long lines are minified build output, not obfuscation. Stable pattern for this webclient package. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-Dgye-P8u.js | AI (source-diff): Network calls (fetch) in a browser webclient bundle are expected; no dropper behavior present. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-iPU9jlP1.js | AI (source-diff): Network calls and dynamic patterns are standard React/Vite bundle behavior, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-iPU9jlP1.js | AI (source-diff): Vite-bundled React client asset; minified build output, not obfuscation. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Package has 582 versions with frequent releases; rapid publish is consistent with automated CI pipeline, not malicious activity. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-BhKwcsbz.js | AI (source-diff): Network calls are browser fetch() for modulepreload in a webclient UI bundle; no hostile destination or dynamic code execution. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BhKwcsbz.js | AI (source-diff): Standard Vite/esbuild minified bundle output; no true obfuscation (_0x arrays, eval/atob, packer) present. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): uuid is explicitly declared in package.json dependencies; phantom-dep heuristic fires incorrectly here. | ai | |
| source-diff | net-exec-file:dist/client/assets/index-kLumE_Is.js | AI (source-diff): Network calls (fetch for modulepreload) and dynamic module loading are standard in bundled SPA code; not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-kLumE_Is.js | AI (source-diff): Vite-bundled frontend asset; minification is expected for this webclient package across all versions. | ai | |
| dependencies | unvetted-dep:@botfabrik/engine-domain | AI (dependencies): Internal sibling package from the same @botfabrik org; versioned in lockstep with this package. | ai | |
| dependencies | unvetted-dep:@botfabrik/engine-transcript-export | AI (dependencies): Internal sibling package from the same @botfabrik org; versioned in lockstep with this package. | ai | |
| dependencies | unvetted-dep:@botfabrik/engine-utils | AI (dependencies): Internal sibling package from the same @botfabrik org; versioned in lockstep with this package. | ai | |
| phantom-deps | phantom-dep:@types/cors | AI (phantom-deps): @types/cors is a TypeScript type package; not imported at runtime by convention. | ai | |
| provenance | no-provenance | AI (provenance): Long-established package with 535 versions; lack of provenance is consistent across all prior releases. | ai |
Versions (showing 50 of 50)
| Version | Deps | Published |
|---|---|---|
| 4.132.2 | 13 / 8 | |
| 4.126.2 | 13 / 8 | |
| 4.123.7 | 13 / 8 | |
| 4.122.1 | 13 / 8 | |
| 4.120.2 | 13 / 8 | |
| 4.117.2 | 13 / 8 | |
| 4.116.11 | 13 / 8 | |
| 4.116.10 | 13 / 8 | |
| 4.116.8 | 13 / 8 | |
| 4.116.7 | 13 / 8 | |
| 4.116.5 | 13 / 8 | |
| 4.116.4 | 13 / 8 | |
| 4.116.3 | 13 / 8 | |
| 4.116.2 | 13 / 8 | |
| 4.116.1 | 13 / 8 | |
| 4.116.0 | 13 / 8 | |
| 4.115.18 | 13 / 8 | |
| 4.115.16 | 13 / 8 | |
| 4.115.15 | 13 / 8 | |
| 4.115.11 | 13 / 8 | |
| 4.115.9 | 13 / 8 | |
| 4.115.8 | 13 / 8 | |
| 4.115.7 | 13 / 8 | |
| 4.115.5 | 13 / 8 | |
| 4.113.1 | 13 / 8 | |
| 4.110.4 | 13 / 8 | |
| 4.110.2 | 13 / 8 | |
| 4.108.1 | 9 / 7 | |
| 4.108.0 | 9 / 7 | |
| 4.106.0 | 9 / 7 | |
| 4.105.0 | 9 / 7 | |
| 4.104.23 | 9 / 7 | |
| 4.104.19 | 9 / 7 | |
| 4.104.3 | 10 / 8 | |
| 4.103.3 | 10 / 8 | |
| 4.102.0 | 10 / 10 | |
| 4.101.2 | 10 / 10 | |
| 4.101.0 | 10 / 10 | |
| 4.100.9 | 10 / 10 | |
| 4.99.10 | 10 / 10 | |
| 4.99.0 | 11 / 10 | |
| 4.96.9 | 7 / 9 | |
| 4.96.6 | 7 / 9 | |
| 4.96.1 | 7 / 9 | |
| 4.94.1 | 7 / 9 | |
| 4.93.0 | 8 / 10 | |
| 4.92.2 | 8 / 10 | |
| 4.89.0 | 7 / 9 | |
| 4.86.3 | 9 / 8 | |
| 4.86.1 | 9 / 8 |
v4.120.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.116.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.115.15
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.113.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.110.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.110.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.108.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.108.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.104.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.