← Home

@codemation/core-nodes-gmail

Optional Gmail integration for Codemation. The package is intentionally trigger-first:

22
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cblokland

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-CBDXvswQ.d.cts AI (source-diff): TypeScript declaration file with long union-type lines; not obfuscated code. ai
source-diff obfuscated-file:dist/index-064i2ite.d.ts AI (source-diff): TypeScript declaration file with long union-type lines; not obfuscated code. ai
source-diff obfuscated-file:dist/index-DmtuzKud.d.ts AI (source-diff): Same pattern: bundled .d.ts with long type union lines, not obfuscation. ai
source-diff obfuscated-file:dist/index-_q-Ftahd.d.cts AI (source-diff): Long-line TypeScript declaration file generated by tsdown bundler; not obfuscated code. ai
source-diff obfuscated-file:dist/index-DMY_Vbj1.d.ts AI (source-diff): Same as above — bundled .d.ts declaration file, not obfuscated. ai
source-diff obfuscated-file:dist/index-B8KcDOJP.d.ts AI (source-diff): TypeScript declaration file with long lines from complex type unions; not obfuscated code. ai
source-diff obfuscated-file:dist/index-CkPqhblz.d.cts AI (source-diff): TypeScript declaration file with long lines from complex type unions; not obfuscated code. ai
source-diff obfuscated-file:dist/index-HcsMi90I.d.ts AI (source-diff): Same bundled .d.ts declaration file; long lines are type unions, not obfuscated code. ai
source-diff obfuscated-file:dist/index-yczl4N0d.d.cts AI (source-diff): Long-line TypeScript declaration rollup from tsdown; not obfuscation. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundling all deps into plugin CJS/ESM artifacts via tsdown. ai
source-diff net-exec-file:dist/codemation.plugin.cjs AI (source-diff): Bundled plugin artifact (tsdown/rolldown output) with googleapis/LangChain deps; no actual dropper behavior in samples. ai
source-diff net-exec-file:dist/codemation.plugin.js AI (source-diff): ESM counterpart of the same bundled plugin; standard bundler output, not malware. ai
source-diff obfuscated-file:dist/index-BWOh-rJe.d.cts AI (source-diff): TypeScript declaration file with long union/interface lines; not obfuscated code. ai
source-diff obfuscated-file:dist/index-Bj5kbvLY.d.ts AI (source-diff): TypeScript declaration file with long union/interface lines; not obfuscated code. ai
provenance publisher-changed AI (provenance): Publisher is GitHub Actions with SLSA attestation; CI/CD publishing is the documented workflow for this org. ai
source-diff obfuscated-file:dist/index-J-XYipso.d.ts AI (source-diff): Same pattern: bundled .d.ts declaration file, long lines from type bundling, not obfuscated code. ai
source-diff obfuscated-file:dist/index-BuSfKJYe.d.cts AI (source-diff): Bundled TypeScript declaration file with long lines from rolldown; readable type definitions, not obfuscation. ai
source-diff obfuscated-file:dist/index--gtTN-A2.d.ts AI (source-diff): Same as above — rolldown/tsdown-generated .d.ts with inlined types; stable false positive for this package. ai
source-diff obfuscated-file:dist/index-DRjOEOl6.d.cts AI (source-diff): Bundler-generated TypeScript declaration file; long lines are inlined type definitions, not obfuscated executable code. ai
semgrep semgrep:base64-decode AI (semgrep): Decoding Gmail API message payloads (base64url); legitimate and expected for a Gmail integration package. ai

Versions (showing 22 of 22)

Version Deps Published
0.2.4 4 / 11
0.2.3 4 / 11
0.2.2 3 / 10
0.2.1 3 / 10
0.2.0 3 / 8
0.1.7 2 / 6
0.1.6 2 / 6
0.1.5 2 / 6
0.1.4 2 / 6
0.1.3 2 / 6
0.1.2 2 / 6
0.1.1 2 / 6
0.0.15 2 / 6
0.0.14 2 / 6
0.0.13 2 / 6
0.0.11 2 / 6
0.0.7 2 / 6
0.0.5 2 / 6
0.0.4 2 / 6
0.0.3 2 / 6
0.0.2 2 / 6
0.0.1 2 / 6

v0.2.4

3 findings
HIGH New obfuscated file: dist/index-DRjOEOl6.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index--gtTN-A2.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.3

3 findings
HIGH New obfuscated file: dist/index-BuSfKJYe.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-J-XYipso.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.2

3 findings
HIGH New obfuscated file: dist/index-BuSfKJYe.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-J-XYipso.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.1

3 findings
HIGH New obfuscated file: dist/index-BuSfKJYe.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-J-XYipso.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.7

5 findings
HIGH New file with network + code execution: dist/codemation.plugin.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CBDXvswQ.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/codemation.plugin.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-064i2ite.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.6

5 findings
HIGH New file with network + code execution: dist/codemation.plugin.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-_q-Ftahd.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/codemation.plugin.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DmtuzKud.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.5

5 findings
HIGH New file with network + code execution: dist/codemation.plugin.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-_q-Ftahd.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/codemation.plugin.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DMY_Vbj1.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.4

5 findings
HIGH New file with network + code execution: dist/codemation.plugin.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-_q-Ftahd.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/codemation.plugin.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DMY_Vbj1.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.3

5 findings
HIGH New file with network + code execution: dist/codemation.plugin.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CkPqhblz.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/codemation.plugin.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B8KcDOJP.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.2

5 findings
HIGH New file with network + code execution: dist/codemation.plugin.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-yczl4N0d.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/codemation.plugin.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-HcsMi90I.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

5 findings
HIGH New file with network + code execution: dist/codemation.plugin.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BWOh-rJe.d.cts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/codemation.plugin.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bj5kbvLY.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.15

2 findings
HIGH Publisher changed: cblokland → GitHub Actions (on 2026-04-01) provenance

This version was published by a different npm account than previous versions on 2026-04-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.14

2 findings
HIGH Publisher changed: cblokland → GitHub Actions (on 2026-04-01) provenance

This version was published by a different npm account than previous versions on 2026-04-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.13

2 findings
HIGH Publisher changed: cblokland → GitHub Actions (on 2026-04-01) provenance

This version was published by a different npm account than previous versions on 2026-04-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.11

2 findings
HIGH Publisher changed: cblokland → GitHub Actions (on 2026-04-01) provenance

This version was published by a different npm account than previous versions on 2026-04-01. This could indicate a legitimate maintainer transition or an account compromise.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.