← Home

@cartridge/controller

83
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

tarrencevbroodyc7e-steeb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/policies-CIjnh8g_.js AI (source-diff): Bundled/minified Vite output, not obfuscation; consistent across releases. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): tsup bundle output with readable source, not true obfuscation. ai
source-diff source-size-tripled AI (source-diff): Explained by new features/deps, no malicious payload found. ai
source-diff large-new-source-files AI (source-diff): Expected from new session/telegram feature modules and bundler output. ai
source-diff obfuscated-file:dist/controller.cjs AI (source-diff): tsup bundle output, not obfuscation; readable source with comments. ai
source-diff obfuscated-file:dist/session/index.cjs AI (source-diff): tsup bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): tsup bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/provider.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/session/index.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/icon.js AI (source-diff): base64 image data inflates line length, not obfuscated code. ai
source-diff obfuscated-file:dist/controller.js AI (source-diff): tsup bundle output with readable source comments, not obfuscation. ai
source-diff obfuscated-file:dist/telegram/provider.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/session/provider.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/provider-BN3lM6-S.js AI (source-diff): Vite/rollup bundled chunk, not obfuscated. ai
source-diff obfuscated-file:dist/provider-CyO7_h7r.js AI (source-diff): Bundled/minified vite build output. ai
source-diff obfuscated-file:dist/provider-Dr912mPw.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/node/index.js AI (source-diff): Bundled build output, readable ESM source. ai
source-diff obfuscated-file:dist/node/index.cjs AI (source-diff): Bundled tsup/vite output, not obfuscation; matches readable src. ai
semgrep semgrep:base64-decode AI (semgrep): Standard Solana tx deserialization, not payload hiding. ai
source-diff obfuscated-file:dist/icon.d.ts AI (source-diff): Base64 PNG data URI, not code obfuscation. ai
source-diff obfuscated-file:dist/provider-CH2PlazB.js AI (source-diff): Minified vite chunk, not true obfuscation. ai
source-diff obfuscated-file:src/icon.ts AI (source-diff): Same base64 icon asset in source form. ai
phantom-deps phantom-dep:fast-deep-equal AI (phantom-deps): Used via config/build tooling, stable false positive. ai
source-diff obfuscated-file:dist/policies-zfnBVwh-.js AI (source-diff): Bundler-minified output with readable logic, not true obfuscation; matches known package behavior. ai
phantom-deps phantom-dep:query-string AI (phantom-deps): Config-only usage, stable false positive. ai
dependencies unvetted-dep:@cartridge/account-wasm AI (dependencies): Same-org first-party dep, version-pinned to match this package. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party sibling package, not an external supply-chain risk. ai
phantom-deps phantom-dep:base64url AI (phantom-deps): Config-only usage, stable false positive. ai
phantom-deps phantom-dep:@cartridge/account-wasm AI (phantom-deps): Same org scope, config-referenced. ai
source-diff obfuscated-file:dist/policies-C7KnWtOU.js AI (source-diff): Minified bundler output, readable variable/module structure, no malicious behavior. ai
source-diff obfuscated-file:dist/react/index.js AI (source-diff): Minified bundler output (Vite), not true obfuscation; imports are legible. ai
source-diff obfuscated-file:dist/provider-Bsw_spHR.js AI (source-diff): Vite/Rollup minified bundle output; readable code with starknet imports, not obfuscated malware. ai
source-diff obfuscated-file:dist/index-C7KGk-LM.js AI (source-diff): Standard Vite bundle output; sample shows readable, non-malicious code. Long lines are minification artifacts. ai
source-diff obfuscated-file:dist/provider-NKp7_oNj.js AI (source-diff): Standard Vite/Rollup bundle output; readable code with no obfuscation or encoded payloads. ai
source-diff obfuscated-file:dist/provider-DSqqvDee.js AI (source-diff): Standard Vite/Rollup bundle output with hashed filename; readable code, not malicious obfuscation. ai
source-diff obfuscated-file:dist/provider-B8OiOgBt.js AI (source-diff): Standard Vite/Rollup minified bundle output; content is readable and benign for this package. ai
source-diff obfuscated-file:dist/provider-BgBI_LQl.js AI (source-diff): Standard Vite/Rollup minified bundle output; sample shows readable starknet business logic, not obfuscation. ai
source-diff obfuscated-file:dist/provider-bC9cKItb.js AI (source-diff): Standard Vite/Rollup minified bundle; sample shows readable starknet imports, not obfuscation. ai
source-diff obfuscated-file:dist/provider-D-5qL7QC.js AI (source-diff): Standard Vite/Rollup minified bundle output; content is readable and benign for this wallet controller package. ai
source-diff obfuscated-file:dist/provider-PftcmETC.js AI (source-diff): Standard Vite/rollup minified bundle output; readable code with starknet imports, not malicious obfuscation. ai
source-diff obfuscated-file:dist/provider-CN6AecRF.js AI (source-diff): Standard Vite/Rollup minified bundle output; readable code, no actual obfuscation or malicious patterns. ai
source-diff obfuscated-file:dist/provider-DSw1EyU9.js AI (source-diff): Standard Vite/Rollup minified bundle; code is readable and matches package functionality. ai
source-diff obfuscated-file:dist/provider-S-IvFw23.js AI (source-diff): Standard Vite/Rollup minified ESM bundle output; content is readable and matches package functionality. ai
source-diff obfuscated-file:dist/provider-CznCrt4b.js AI (source-diff): Standard Vite/Rollup minified bundle output; readable code with no obfuscation indicators. ai
source-diff obfuscated-file:dist/index-CJNujYxo.js AI (source-diff): Standard Vite/rollup minified bundle output; readable identifiers, no encoding or obfuscation techniques present. ai
source-diff obfuscated-file:dist/provider-BQFas4CN.js AI (source-diff): Standard Vite/Rollup minified bundle output; content is readable and matches expected package functionality. ai
source-diff obfuscated-file:dist/index-BdTFKueB.js AI (source-diff): Standard Vite/rollup minified bundle output; sample shows readable starknet imports and enum patterns, not obfuscation. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publisher with SLSA provenance attestation; legitimate automation pattern. ai
source-diff obfuscated-file:dist/index-CYAUAqql.js AI (source-diff): Standard Vite/Rollup minified bundle output; readable identifiers, no suspicious payloads. ai
source-diff obfuscated-file:dist/provider-s-80NdXp.js AI (source-diff): Standard Vite/rollup minified bundle output; not obfuscated malware. Stable pattern for this package. ai
source-diff obfuscated-file:dist/index-BBfUA93L.js AI (source-diff): Vite/Rollup build output; sample shows readable starknet code, not actual obfuscation. Stable pattern for this package. ai
phantom-deps phantom-dep:@cartridge/utils AI (phantom-deps): Same-org sibling package in monorepo; phantom-dep is a stable false positive for this package. ai
phantom-deps phantom-dep:open AI (phantom-deps): Likely used in Node.js build/config path; phantom-dep heuristic misses config-file imports. ai
phantom-deps phantom-dep:@walletconnect/ethereum-provider AI (phantom-deps): Likely used in browser bundle path; phantom-dep heuristic misses config-file imports. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decode is standard Solana transaction serialization in utils/solana — no obfuscation concern. ai
phantom-deps phantom-dep:@turnkey/sdk-browser AI (phantom-deps): Likely used in browser bundle path; phantom-dep heuristic misses config-file imports. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP is 127.0.0.1 in a test file validating iframe URL security — not a real network call. ai
phantom-deps phantom-dep:cbor-x AI (phantom-deps): Likely used in Node.js build/config path; phantom-dep heuristic misses config-file imports. ai

Versions (showing 83 of 83)

Version Deps Published
0.13.15 14 / 24
0.13.14 14 / 24
0.13.13 14 / 24
0.13.12 13 / 15
0.13.11 13 / 15
0.13.10 13 / 15
0.13.9 14 / 15
0.13.7 14 / 15
0.13.6 14 / 15
0.13.5 14 / 15
0.13.4 13 / 15
0.13.3 13 / 15
0.12.2 13 / 15
0.12.1 13 / 15
0.12.0 13 / 15
0.11.3 13 / 15
0.11.2 13 / 15
0.11.1 13 / 15
0.10.7 13 / 15
0.10.6 13 / 15
0.10.5 13 / 15
0.10.4 13 / 15
0.10.3 13 / 15
0.10.2 13 / 15
0.10.1 13 / 15
0.10.0 13 / 15
0.9.3 9 / 15
0.9.2 9 / 15
0.9.1 9 / 15
0.9.0 9 / 15
0.8.0 9 / 15
0.7.13 10 / 14
0.7.12 6 / 14
0.7.11 6 / 14
0.7.10 6 / 14
0.7.9 6 / 14
0.7.8 7 / 8
0.7.7 7 / 8
0.7.6 7 / 8
0.7.5 7 / 8
0.7.4 7 / 8
0.7.3 7 / 8
0.7.2 7 / 8
0.7.1 7 / 8
0.7.0 7 / 8
0.6.0 8 / 6
0.5.9 9 / 6
0.5.8 9 / 3
0.5.7 9 / 3
0.5.6 9 / 3
0.5.5 9 / 3
0.5.4 10 / 3
0.5.3 10 / 3
0.5.2 10 / 3
0.5.1 9 / 3
0.5.0 10 / 3
0.4.0 7 / 3
0.3.46 7 / 3
0.3.45 7 / 3
0.3.44 7 / 3
0.3.43 6 / 3
0.3.42 6 / 3
0.3.41 6 / 3
0.3.40 6 / 3
0.3.39 6 / 3
0.3.38 6 / 3
0.3.37 6 / 3
0.3.36 6 / 3
0.3.35 6 / 3
0.3.34 6 / 3
0.3.33 6 / 3
0.3.32 6 / 3
0.3.31 6 / 3
0.3.30 6 / 3
0.3.29 6 / 3
0.3.28 6 / 3
0.3.27 6 / 3
0.3.26 6 / 3
0.3.25 6 / 3
0.3.24 6 / 3
0.3.23 6 / 3
0.3.22 6 / 3
0.3.21 6 / 3

v0.13.15

2 findings
HIGH New obfuscated file: dist/policies-CIjnh8g_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.14

2 findings
HIGH New obfuscated file: dist/policies-zfnBVwh-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.13

3 findings
HIGH New obfuscated file: dist/react/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/policies-C7KnWtOU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.12

7 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-BN3lM6-S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2025-04-17, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2025-04-17, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.11

6 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-CyO7_h7r.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.10

6 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-Dr912mPw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.9

6 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-CH2PlazB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.8

4 findings
HIGH New obfuscated file: dist/controller.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.6

9 findings
HIGH New obfuscated file: dist/controller.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/controller.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: broody → tarrencev (on 2025-03-12, known maintainer) provenance

This version was published by a different npm account (tarrencev) than the most recent previously approved version (broody) on 2025-03-12, but tarrencev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2025-03-03, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2025-03-03, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

9 findings
HIGH New obfuscated file: dist/controller.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/telegram/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: broody → tarrencev (on 2024-12-08, known maintainer) provenance

This version was published by a different npm account (tarrencev) than the most recent previously approved version (broody) on 2024-12-08, but tarrencev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.5.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2024-12-06, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2024-12-06, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.5.1

9 findings
HIGH New obfuscated file: dist/controller.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/telegram/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

2 findings
HIGH New obfuscated file: dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: broody → tarrencev (on 2024-10-17, known maintainer) provenance

This version was published by a different npm account (tarrencev) than the most recent previously approved version (broody) on 2024-10-17, but tarrencev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.46

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.44

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2024-09-10, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2024-09-10, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.38

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: broody → tarrencev (on 2024-08-07, known maintainer) provenance

This version was published by a different npm account (tarrencev) than the most recent previously approved version (broody) on 2024-08-07, but tarrencev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.28

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2024-06-19, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2024-06-19, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.27

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: broody → tarrencev (on 2024-06-14, known maintainer) provenance

This version was published by a different npm account (tarrencev) than the most recent previously approved version (broody) on 2024-06-14, but tarrencev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.25

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2024-05-31, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2024-05-31, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.24

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: broody → tarrencev (on 2024-05-28, known maintainer) provenance

This version was published by a different npm account (tarrencev) than the most recent previously approved version (broody) on 2024-05-28, but tarrencev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.22

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2024-05-22, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2024-05-22, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.