@commercetools-frontend/mc-scripts
Configuration and scripts for developing a MC application
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/graphql-requests-c584b284.cjs.prod.js | AI (source-diff): Bundled build output (babel/corejs3 requires), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-95ad4f52.cjs.dev.js | AI (source-diff): Bundled build output (babel/corejs3 requires), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-0b5eaa25.cjs.prod.js | AI (source-diff): Bundled/minified rollup output, not true obfuscation; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-70911fc7.cjs.dev.js | AI (source-diff): Bundled/minified rollup output, not true obfuscation; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-65332887.cjs.prod.js | AI (source-diff): Bundled rollup/babel output, not obfuscation; standard build artifact naming. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-8c5aeb2f.cjs.dev.js | AI (source-diff): Bundled rollup/babel output, not obfuscation; standard build artifact naming. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-eca3d559.cjs.dev.js | AI (source-diff): Rollup-bundled dev output, not obfuscation; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-436511ba.cjs.prod.js | AI (source-diff): Rollup-bundled prod output, not obfuscation; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-9bff62a9.cjs.prod.js | AI (source-diff): Rollup-bundled dist file, not true obfuscation; matches package's own deps. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-91522a81.cjs.dev.js | AI (source-diff): Rollup-bundled dist file, not true obfuscation; matches package's own deps. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-0bfaefaf.cjs.prod.js | AI (source-diff): Bundled rollup/babel build output, not obfuscation; standard requires visible. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-96bc67f5.cjs.dev.js | AI (source-diff): Bundled rollup/babel build output, not obfuscation; standard requires visible. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-93fe3301.cjs.prod.js | AI (source-diff): Bundled rollup/babel cjs output, not true obfuscation; no malicious code. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-48470b8d.cjs.dev.js | AI (source-diff): Bundled rollup/babel cjs output, not true obfuscation; no malicious code. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-663477fa.cjs.dev.js | AI (source-diff): Rollup-bundled CJS output, not true obfuscation; standard build artifact. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large legitimate feature/dep expansion (vite, sharp, svgr etc), not injected code. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-b00291ee.cjs.prod.js | AI (source-diff): Rollup-bundled CJS output, not true obfuscation; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-bd7a3fe9.cjs.dev.js | AI (source-diff): Standard Rollup CJS dev bundle; same pattern as prod bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-6ead2029.cjs.prod.js | AI (source-diff): Standard Rollup CJS bundle with Babel polyfill imports; long lines are bundled requires, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-5754c65e.cjs.prod.js | AI (source-diff): Standard Rollup CJS prod bundle with readable imports; long lines from bundling, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-82ecc296.cjs.dev.js | AI (source-diff): Standard Rollup CJS dev bundle; same pattern as prod bundle, benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-D0rtMo7K.cjs.prod.js | AI (source-diff): Standard Rollup CJS prod build artifact with readable imports; long lines from bundled code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-BeUd4g3v.cjs.dev.js | AI (source-diff): Standard Rollup CJS dev build artifact with readable imports; long lines from bundled code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-86c87041.cjs.dev.js | AI (source-diff): Standard rollup CJS dev bundle; same pattern as prod bundle. Stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-4c97fe92.cjs.prod.js | AI (source-diff): Standard rollup CJS bundle with readable imports; long lines are from bundling, not obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-25e057ed.cjs.dev.js | AI (source-diff): Standard Babel CJS build artifact; long lines from bundled polyfill imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/graphql-requests-eb88492d.cjs.prod.js | AI (source-diff): Standard Babel CJS prod build artifact; same pattern as dev variant, not obfuscation. | ai | |
| dependencies | unvetted-dep:vite-plugin-clean-build | AI (dependencies): Build-time Vite plugin with no install scripts or malware indicators; low risk for this established package. | ai | |
| dependencies | unvetted-dep:@rollup/plugin-graphql | AI (dependencies): Official @rollup scoped build plugin; low risk for a build tooling package. | ai | |
| dependencies | unvetted-dep:@types/svgo | AI (dependencies): Type-only package for svgo; no runtime risk, stable for this build tooling package. | ai | |
| phantom-deps | phantom-dep:babel-plugin-formatjs | AI (phantom-deps): Babel plugin loaded by convention in build config. | ai | |
| phantom-deps | phantom-dep:@emotion/babel-plugin | AI (phantom-deps): Babel plugin loaded by convention in build config. | ai | |
| phantom-deps | phantom-dep:@svgr/babel-preset | AI (phantom-deps): Babel preset loaded by convention in build config. | ai | |
| phantom-deps | phantom-dep:@types/prompts | AI (phantom-deps): Type-only package; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped; loaded by babel transforms by convention. | ai | |
| phantom-deps | phantom-dep:browserslist | AI (phantom-deps): Referenced in build config files by convention. | ai | |
| phantom-deps | phantom-dep:json-loader | AI (phantom-deps): Webpack loader referenced in config files by convention. | ai | |
| phantom-deps | phantom-dep:@types/svgo | AI (phantom-deps): Type-only package; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped babel package; loaded by convention in build tooling. | ai | |
| phantom-deps | phantom-dep:node-fetch | AI (phantom-deps): Scripts package; node-fetch used in CLI utilities by convention. | ai | |
| phantom-deps | phantom-dep:prettier | AI (phantom-deps): Build/scripts tool; prettier referenced in config files by convention. | ai | |
| phantom-deps | phantom-dep:shelljs | AI (phantom-deps): Scripts package; shelljs used in CLI scripts loaded by convention. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Build tool; phantom deps are convention-loaded plugins, not missing imports. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Build tool; postcss loaded by webpack/rollup config convention. | ai | |
| phantom-deps | phantom-dep:@commercetools-frontend/application-components | AI (phantom-deps): Same-org package; phantom dep heuristic is a false positive here. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-proposal-do-expressions | AI (phantom-deps): Babel plugin loaded by convention in build config. | ai | |
| phantom-deps | phantom-dep:@types/webpack-bundle-analyzer | AI (phantom-deps): Type-only package; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:babel-plugin-react-compiler | AI (phantom-deps): Babel plugin loaded by convention in build config. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 27.7.0 | 77 / 13 | |
| 27.6.3 | 77 / 12 | |
| 27.6.2 | 77 / 12 | |
| 27.6.1 | 77 / 12 | |
| 27.6.0 | 77 / 12 | |
| 27.5.4 | 77 / 12 | |
| 27.5.3 | 77 / 12 | |
| 27.5.2 | 77 / 12 | |
| 27.5.1 | 77 / 12 | |
| 27.5.0 | 77 / 12 | |
| 27.4.2 | 77 / 12 | |
| 27.4.1 | 77 / 13 | |
| 27.4.0 | 77 / 13 | |
| 27.3.0 | 77 / 13 | |
| 27.2.0 | 77 / 13 | |
| 27.1.0 | 77 / 13 | |
| 27.0.0 | 77 / 13 | |
| 26.1.0 | 77 / 13 | |
| 26.0.2 | 77 / 13 | |
| 26.0.1 | 77 / 13 | |
| 26.0.0 | 77 / 13 | |
| 25.2.0 | 77 / 13 | |
| 25.1.0 | 76 / 12 | |
| 25.0.0 | 76 / 12 | |
| 24.13.0 | 76 / 14 | |
| 24.12.0 | 76 / 14 | |
| 24.11.0 | 76 / 14 | |
| 24.10.0 | 76 / 14 |
v27.7.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v27.6.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v27.5.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v26.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v24.11.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.