@bull-board/ui
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/static/js/main.2abbe84b73.js | AI (source-diff): rspack minified bundle output, not obfuscation; regenerated each release. | ai | |
| source-diff | net-exec-file:dist/static/js/async/632.d25c94d9c9.js | AI (source-diff): Bundled vendor code (decimal.js); no hostile network destination. | ai | |
| source-diff | net-exec-file:dist/static/js/main.2abbe84b73.js | AI (source-diff): Bundler chunk-loading runtime, not net+exec dropper; benign for this build tool. | ai | |
| source-diff | net-exec-file:dist/static/js/main.0cf84dd99b.js | AI (source-diff): i18n http-backend + React runtime in bundled main chunk; benign for this UI. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.0cf84dd99b.js | AI (source-diff): rspack-bundled UI output; minified not obfuscated, recurs every release. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.f55b94a6cc.js | AI (source-diff): Minified rspack bundle output, not obfuscation; stable for this build tool. | ai | |
| source-diff | net-exec-file:dist/static/js/main.f55b94a6cc.js | AI (source-diff): Fetch/eval patterns are inside bundled React/vendor chunks; benign. | ai | |
| source-diff | net-exec-file:dist/static/js/main.ef251c97cd.js | AI (source-diff): rspack bundle chunk-loader; network+dynamic-code are standard webpack-style runtime, not a dropper. | ai | |
| source-diff | net-exec-file:dist/static/js/main.804da558.js | AI (source-diff): fetch/dynamic patterns are normal in bundled React UI; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.804da558.js | AI (source-diff): rsbuild-minified UI bundle; long lines are build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/static/js/main.3f070b71.js | AI (source-diff): fetch+dynamic-import patterns are normal in a bundled React SPA, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.3f070b71.js | AI (source-diff): Minified rsbuild output for the UI package; expected on every release. | ai | |
| source-diff | net-exec-file:dist/static/js/main.e0387b32ce.js | AI (source-diff): Dynamic-import + fetch inside bundled React app entry; benign for a dashboard UI. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.e0387b32ce.js | AI (source-diff): rspack bundled build output, minified not obfuscated; stable for this package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/67465.72d4d78f.js | AI (source-diff): Webpack-bundled React UI chunk; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/static/js/main.03ef87a2.js | AI (source-diff): React UI bundle with axios HTTP client; normal for a dashboard UI package. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.03ef87a2.js | AI (source-diff): Webpack-bundled main entry; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/82384.e5b8aa9f.js | AI (source-diff): Webpack-bundled React UI chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/66030.baa9f0df.js | AI (source-diff): Webpack-bundled React UI chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.25c43af3.js | AI (source-diff): Standard rsbuild bundle of React UI; CSS-module hashes and date-fns locale maps, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/static/js/main.25c43af3.js | AI (source-diff): Bundled React app with axios HTTP calls and dynamic imports; normal for a dashboard UI. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/135.8acec210e6.js | AI (source-diff): Standard rspack minified UI bundle chunk; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/977.aac3ea9649.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/926.0fbac7e274.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/906.01e54249a2.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/865.b6e87e02d0.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/857.99229283ec.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/837.f5f4cf1102.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/833.e08c6d7001.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/832.9eaee4b202.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | net-exec-file:dist/static/js/async/661.2520a6fcce.js | AI (source-diff): False positive; bundled UI code with fetch/eval patterns from dependencies. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/661.2520a6fcce.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/648.b066483072.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/469.0d0c4c7d60.js | AI (source-diff): Standard rspack async chunk. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/445.79830dc420.js | AI (source-diff): JSON theme data chunk; no executable logic. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/415.3e5a2b2e0a.js | AI (source-diff): Minified UI component chunk with JSON schema data. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/384.8909864bc5.js | AI (source-diff): Bundled prop-types/react-paginate chunk; standard. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/343.803ace31e2.js | AI (source-diff): Minified React component chunk; standard bundle output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/30.d2a74db8bb.js | AI (source-diff): JSON theme data chunk; no executable logic. | ai | |
| source-diff | net-exec-file:dist/static/js/async/172.39f5f97cdc.js | AI (source-diff): False positive on bundled math library; no real net+exec pattern. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/172.39f5f97cdc.js | AI (source-diff): Minified Decimal.js library chunk; expected in UI bundle. | ai | |
| source-diff | net-exec-file:dist/static/js/main.3aa3f1b0b9.js | AI (source-diff): Bundled React app with axios HTTP calls and eval-like patterns from codemirror; not malicious. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.3aa3f1b0b9.js | AI (source-diff): Minified React UI bundle; expected for a dashboard UI package shipping built assets. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/61479.866d9060.js | AI (source-diff): Webpack-bundled React UI chunk; standard minified output for this UI package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/29662.607b2218.js | AI (source-diff): Webpack-bundled React UI chunk; standard minified output for this UI package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/42279.76a8888a.js | AI (source-diff): Webpack-bundled React UI chunk; standard minified output for this UI package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/99902.1d8fda97.js | AI (source-diff): Webpack-bundled React UI chunk; standard minified output for this UI package. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.52ccd466.js | AI (source-diff): Webpack-bundled main entry; standard minified output for this UI package. | ai | |
| source-diff | net-exec-file:dist/static/js/main.52ccd466.js | AI (source-diff): False positive on bundled UI code with fetch calls and webpack dynamic imports. | ai | |
| source-diff | net-exec-file:dist/static/js/main.f00fcf89.js | AI (source-diff): Bundled axios (network) + webpack dynamic imports (eval); normal for a React SPA bundle. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.f00fcf89.js | AI (source-diff): Main webpack bundle for UI app; minification is standard build output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/48554.36521f48.js | AI (source-diff): Standard webpack chunk with CSS module hashes and SVG icons for bull-board UI. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA provenance; legitimate automation. | ai | |
| source-diff | net-exec-file:dist/static/js/main.11111ccd.js | AI (source-diff): Webpack bundle includes axios (network) and dynamic imports (exec); normal for SPA. | ai | |
| source-diff | obfuscated-file:dist/static/js/6693.08bd576a.js | AI (source-diff): Webpack chunk bundling aria-hidden and date-fns; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/51227.14e53878.js | AI (source-diff): Webpack chunk bundling Decimal.js library; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/59308.18840707.js | AI (source-diff): Webpack chunk for queue metrics React component; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.11111ccd.js | AI (source-diff): Main webpack entry bundle for bull-board UI; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/lib-axios.575029bf.js | AI (source-diff): Webpack chunk bundling axios library; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/79721.ec356cdf.js | AI (source-diff): Webpack chunk bundling prop-types and react-paginate; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/11153.03304bed.js | AI (source-diff): Webpack-minified CodeMirror chunk; expected for UI package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/13410.436fbd27.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/12700.61b82ee1.js | AI (source-diff): Webpack-bundled locale chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/12506.4df1bf8a.js | AI (source-diff): Webpack-bundled locale chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/12347.0e10ff40.js | AI (source-diff): Webpack-bundled locale chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/11272.b03de1a0.js | AI (source-diff): Webpack-bundled locale chunk (Tamil); standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/11153.2127688b.js | AI (source-diff): Webpack-bundled CodeMirror/UI chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/1074.f5737cfe.js | AI (source-diff): Webpack-bundled locale chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/10518.e5ba10f5.js | AI (source-diff): Webpack-bundled date-fns locale chunks; standard for a UI package shipping pre-built assets. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/12106.6b21c0cf.js | AI (source-diff): Webpack-bundled locale chunk (Latvian); standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/19367.41cb624f.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/18707.63c3608e.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/18582.6d29734d.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/17597.ded69ad6.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/17553.2939fda7.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/16752.3bde98cb.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/1531.caf4684b.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/15283.50a0ae59.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/15114.4d20ed6a.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/14939.01eb94e4.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/14302.e411a392.js | AI (source-diff): Webpack-bundled chunk; standard minified output. | ai | |
| source-diff | net-exec-file:dist/static/js/main.f9b83451.js | AI (source-diff): Browser bundle with axios/fetch and webpack require; expected for a dashboard UI. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/10518.b0a21f0d.js | AI (source-diff): Standard webpack-minified bundle of date-fns; expected for a UI package shipping built assets. | ai | |
| source-diff | net-exec-file:dist/static/js/async/51125.8b45fd61.js | AI (source-diff): Fetch polyfill + webpack dynamic imports in browser bundle; not server-side malware. | ai | |
| source-diff | obfuscated-file:dist/static/js/main.f9b83451.js | AI (source-diff): Webpack-minified main entry with CSS module hashes; standard build output. | ai | |
| source-diff | obfuscated-file:dist/static/js/lib-react.719eb9c0.js | AI (source-diff): Minified React bundle; expected for a UI package. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/90409.1795e0fb.js | AI (source-diff): Webpack-minified chunk containing fetch polyfill; standard build output. | ai | |
| source-diff | obfuscated-file:dist/static/js/6693.47be15e9.js | AI (source-diff): Webpack-minified chunk (aria-hidden, date-fns locale); standard build output. | ai | |
| source-diff | obfuscated-file:dist/static/js/async/51125.8b45fd61.js | AI (source-diff): Webpack-minified chunk with LICENSE.txt; standard build output. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @bull-board/ui package; Levenshtein match against short names is a false positive. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @bull-board/ui package; Levenshtein match against short names is a false positive. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @bull-board/ui package; Levenshtein match against short names is a false positive. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @bull-board/ui package; Levenshtein match against short names is a false positive. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped @bull-board/ui package; Levenshtein match against short names is a false positive. | ai |
Versions (showing 38 of 38)
| Version | Deps | Published |
|---|---|---|
| 8.3.0 | 1 / 47 | |
| 8.2.0 | 1 / 48 | |
| 8.1.2 | 1 / 47 | |
| 8.1.1 | 1 / 47 | |
| 8.1.0 | 1 / 38 | |
| 8.0.2 | 1 / 38 | |
| 8.0.1 | 1 / 38 | |
| 8.0.0 | 1 / 38 | |
| 7.2.1 | 1 / 37 | |
| 7.2.0 | 1 / 41 | |
| 7.1.5 | 1 / 40 | |
| 7.1.3 | 1 / 40 | |
| 7.0.0 | 1 / 40 | |
| 6.21.3 | 1 / 40 | |
| 6.21.2 | 1 / 40 | |
| 6.21.1 | 1 / 39 | |
| 6.21.0 | 1 / 39 | |
| 6.20.7 | 1 / 39 | |
| 6.20.6 | 1 / 39 | |
| 6.20.5 | 1 / 39 | |
| 6.20.4 | 1 / 39 | |
| 6.20.3 | 1 / 39 | |
| 6.20.2 | 1 / 39 | |
| 6.20.1 | 1 / 39 | |
| 6.20.0 | 1 / 39 | |
| 6.19.0 | 1 / 39 | |
| 6.18.3 | 1 / 39 | |
| 6.18.2 | 1 / 39 | |
| 6.18.1 | 1 / 39 | |
| 6.18.0 | 1 / 39 | |
| 6.17.0 | 1 / 39 | |
| 6.16.4 | 1 / 38 | |
| 6.16.2 | 1 / 38 | |
| 6.16.1 | 1 / 38 | |
| 6.16.0 | 1 / 38 | |
| 6.15.0 | 1 / 38 | |
| 6.14.2 | 1 / 38 | |
| 6.14.1 | 1 / 38 |
v8.3.0
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.2.0
19 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.1.2
19 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.1.1
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.1.0
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v8.0.2
23 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.1.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.20.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.20.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.18.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.