← Home

@codingame/monaco-vscode-mermaid-markdown-features-default-extension

3
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

nonofrsamuel.oliviernantoniazzimaximecgcodingame_team

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:resources/extension.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff obfuscated-file:resources/index-editor.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff obfuscated-file:resources/index.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff obfuscated-file:index.js AI (source-diff): Standard minified VS Code extension bundle; expected for this package's build pipeline. ai
source-diff net-exec-file:resources/index-editor.js AI (source-diff): Network calls are VS Code webview fetch patterns; dynamic code execution is standard bundler output, not malware. ai
source-diff net-exec-file:resources/index.js AI (source-diff): Network calls are VS Code webview fetch patterns; dynamic code execution is standard bundler output, not malware. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher with SLSA provenance is a legitimate CI/CD migration, not a compromise. ai

Versions (showing 3 of 3)

Version Deps Published
33.0.9 1 / 0
33.0.7 1 / 0
0.0.1 0 / 0

v33.0.9

8 findings
HIGH Publisher changed: nonofr → GitHub Actions (on 2026-05-26) provenance

This version was published by a different npm account than previous versions on 2026-05-26. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: resources/extension.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: resources/index-editor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: resources/index-editor.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: resources/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: resources/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v33.0.7

8 findings
HIGH Publisher changed: nonofr → GitHub Actions (on 2026-05-23) provenance

This version was published by a different npm account than previous versions on 2026-05-23. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: resources/extension.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: resources/index-editor.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: resources/index-editor.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: resources/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: resources/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.