← Home

@chainlink/cl-search-frontend

This package provides a search component that integrates with Algolia indexes.

4
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

npmserviceaccount-cllsecure.thanhsecure.ericzsecure.javiersecure.andrewnotoriousenigmasecure_handersonm4us

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/webflow-import.mjs AI (source-diff): Bundled build output, not malicious. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): Bundled Vite/React build output, not true obfuscation. ai
source-diff net-exec-file:dist/index.js AI (source-diff): Bundled UI code; network+eval patterns come from React/bundler internals. ai
source-diff obfuscated-file:dist/webflow-import.js AI (source-diff): Bundled build output for webflow entrypoint. ai
source-diff net-exec-file:dist/webflow-import.js AI (source-diff): Bundled build output, not dropper/loader. ai
source-diff obfuscated-file:dist/index.mjs AI (source-diff): Bundled ESM build output. ai
source-diff net-exec-file:dist/index.mjs AI (source-diff): Bundled ESM build output. ai
source-diff obfuscated-file:dist/webflow-import.mjs AI (source-diff): Bundled ESM build output for webflow entrypoint. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Chainlink org routinely publishes 0.0.0 placeholder versions for namespace reservation; not a malware indicator here. ai
bogus-package bogus-package AI (bogus-package): Placeholder publish by a known Chainlink service account; empty payload and missing metadata are expected for namespace reservation. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Declared dependency; used in markdown sanitization pipeline. ai
phantom-deps phantom-dep:remark-gfm AI (phantom-deps): Declared dependency; used in markdown processing pipeline. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Declared dependency; core markdown rendering library. ai
phantom-deps phantom-dep:rehype-sanitize AI (phantom-deps): Declared dependency; used in markdown sanitization pipeline. ai
phantom-deps phantom-dep:rehype-prism-plus AI (phantom-deps): Declared dependency; used for syntax highlighting in markdown. ai
phantom-deps phantom-dep:hast-util-sanitize AI (phantom-deps): Declared dependency; used in markdown sanitization pipeline. ai

Versions (showing 4 of 4)

Version Deps Published
0.13.2 7 / 16
0.13.1 7 / 16
0.12.1 9 / 16
0.0.0 0 / 0

v0.13.1

10 findings
HIGH Publisher changed: npmserviceaccount-cll → GitHub Actions (on 2026-03-02) provenance

This version was published by a different npm account than previous versions on 2026-03-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/webflow-import.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/webflow-import.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/webflow-import.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/webflow-import.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.1

10 findings
HIGH Publisher changed: npmserviceaccount-cll → GitHub Actions (on 2025-11-18) provenance

This version was published by a different npm account than previous versions on 2025-11-18. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/webflow-import.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/webflow-import.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/webflow-import.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/webflow-import.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.