← Home

@commercetools-frontend/mc-scripts

Configuration and scripts for developing a MC application

28
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tdeekensemmenkocommercetools-admin

Keywords

javascriptfrontendreacttoolkit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/graphql-requests-c584b284.cjs.prod.js AI (source-diff): Bundled build output (babel/corejs3 requires), not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-95ad4f52.cjs.dev.js AI (source-diff): Bundled build output (babel/corejs3 requires), not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-0b5eaa25.cjs.prod.js AI (source-diff): Bundled/minified rollup output, not true obfuscation; standard build artifact. ai
source-diff obfuscated-file:dist/graphql-requests-70911fc7.cjs.dev.js AI (source-diff): Bundled/minified rollup output, not true obfuscation; standard build artifact. ai
source-diff obfuscated-file:dist/graphql-requests-65332887.cjs.prod.js AI (source-diff): Bundled rollup/babel output, not obfuscation; standard build artifact naming. ai
source-diff obfuscated-file:dist/graphql-requests-8c5aeb2f.cjs.dev.js AI (source-diff): Bundled rollup/babel output, not obfuscation; standard build artifact naming. ai
source-diff obfuscated-file:dist/graphql-requests-eca3d559.cjs.dev.js AI (source-diff): Rollup-bundled dev output, not obfuscation; standard build artifact. ai
source-diff obfuscated-file:dist/graphql-requests-436511ba.cjs.prod.js AI (source-diff): Rollup-bundled prod output, not obfuscation; standard build artifact. ai
source-diff obfuscated-file:dist/graphql-requests-9bff62a9.cjs.prod.js AI (source-diff): Rollup-bundled dist file, not true obfuscation; matches package's own deps. ai
source-diff obfuscated-file:dist/graphql-requests-91522a81.cjs.dev.js AI (source-diff): Rollup-bundled dist file, not true obfuscation; matches package's own deps. ai
source-diff obfuscated-file:dist/graphql-requests-0bfaefaf.cjs.prod.js AI (source-diff): Bundled rollup/babel build output, not obfuscation; standard requires visible. ai
source-diff obfuscated-file:dist/graphql-requests-96bc67f5.cjs.dev.js AI (source-diff): Bundled rollup/babel build output, not obfuscation; standard requires visible. ai
source-diff obfuscated-file:dist/graphql-requests-93fe3301.cjs.prod.js AI (source-diff): Bundled rollup/babel cjs output, not true obfuscation; no malicious code. ai
source-diff obfuscated-file:dist/graphql-requests-48470b8d.cjs.dev.js AI (source-diff): Bundled rollup/babel cjs output, not true obfuscation; no malicious code. ai
source-diff obfuscated-file:dist/graphql-requests-663477fa.cjs.dev.js AI (source-diff): Rollup-bundled CJS output, not true obfuscation; standard build artifact. ai
source-diff large-new-source-files AI (source-diff): Large legitimate feature/dep expansion (vite, sharp, svgr etc), not injected code. ai
source-diff obfuscated-file:dist/graphql-requests-b00291ee.cjs.prod.js AI (source-diff): Rollup-bundled CJS output, not true obfuscation; standard build artifact. ai
source-diff obfuscated-file:dist/graphql-requests-bd7a3fe9.cjs.dev.js AI (source-diff): Standard Rollup CJS dev bundle; same pattern as prod bundle, not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-6ead2029.cjs.prod.js AI (source-diff): Standard Rollup CJS bundle with Babel polyfill imports; long lines are bundled requires, not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-5754c65e.cjs.prod.js AI (source-diff): Standard Rollup CJS prod bundle with readable imports; long lines from bundling, not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-82ecc296.cjs.dev.js AI (source-diff): Standard Rollup CJS dev bundle; same pattern as prod bundle, benign build artifact. ai
source-diff obfuscated-file:dist/graphql-requests-D0rtMo7K.cjs.prod.js AI (source-diff): Standard Rollup CJS prod build artifact with readable imports; long lines from bundled code, not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-BeUd4g3v.cjs.dev.js AI (source-diff): Standard Rollup CJS dev build artifact with readable imports; long lines from bundled code, not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-86c87041.cjs.dev.js AI (source-diff): Standard rollup CJS dev bundle; same pattern as prod bundle. Stable false positive for this package. ai
source-diff obfuscated-file:dist/graphql-requests-4c97fe92.cjs.prod.js AI (source-diff): Standard rollup CJS bundle with readable imports; long lines are from bundling, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:dist/graphql-requests-25e057ed.cjs.dev.js AI (source-diff): Standard Babel CJS build artifact; long lines from bundled polyfill imports, not obfuscation. ai
source-diff obfuscated-file:dist/graphql-requests-eb88492d.cjs.prod.js AI (source-diff): Standard Babel CJS prod build artifact; same pattern as dev variant, not obfuscation. ai
dependencies unvetted-dep:vite-plugin-clean-build AI (dependencies): Build-time Vite plugin with no install scripts or malware indicators; low risk for this established package. ai
dependencies unvetted-dep:@rollup/plugin-graphql AI (dependencies): Official @rollup scoped build plugin; low risk for a build tooling package. ai
dependencies unvetted-dep:@types/svgo AI (dependencies): Type-only package for svgo; no runtime risk, stable for this build tooling package. ai
phantom-deps phantom-dep:babel-plugin-formatjs AI (phantom-deps): Babel plugin loaded by convention in build config. ai
phantom-deps phantom-dep:@emotion/babel-plugin AI (phantom-deps): Babel plugin loaded by convention in build config. ai
phantom-deps phantom-dep:@svgr/babel-preset AI (phantom-deps): Babel preset loaded by convention in build config. ai
phantom-deps phantom-dep:@types/prompts AI (phantom-deps): Type-only package; not directly imported by design. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped; loaded by babel transforms by convention. ai
phantom-deps phantom-dep:browserslist AI (phantom-deps): Referenced in build config files by convention. ai
phantom-deps phantom-dep:json-loader AI (phantom-deps): Webpack loader referenced in config files by convention. ai
phantom-deps phantom-dep:@types/svgo AI (phantom-deps): Type-only package; not directly imported by design. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped babel package; loaded by convention in build tooling. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Scripts package; node-fetch used in CLI utilities by convention. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): Build/scripts tool; prettier referenced in config files by convention. ai
phantom-deps phantom-dep:shelljs AI (phantom-deps): Scripts package; shelljs used in CLI scripts loaded by convention. ai
phantom-deps phantom-dep:moment AI (phantom-deps): Build tool; phantom deps are convention-loaded plugins, not missing imports. ai
phantom-deps phantom-dep:postcss AI (phantom-deps): Build tool; postcss loaded by webpack/rollup config convention. ai
phantom-deps phantom-dep:@commercetools-frontend/application-components AI (phantom-deps): Same-org package; phantom dep heuristic is a false positive here. ai
phantom-deps phantom-dep:@babel/plugin-proposal-do-expressions AI (phantom-deps): Babel plugin loaded by convention in build config. ai
phantom-deps phantom-dep:@types/webpack-bundle-analyzer AI (phantom-deps): Type-only package; not directly imported by design. ai
phantom-deps phantom-dep:babel-plugin-react-compiler AI (phantom-deps): Babel plugin loaded by convention in build config. ai

Versions (showing 28 of 28)

Version Deps Published
27.7.0 77 / 13
27.6.3 77 / 12
27.6.2 77 / 12
27.6.1 77 / 12
27.6.0 77 / 12
27.5.4 77 / 12
27.5.3 77 / 12
27.5.2 77 / 12
27.5.1 77 / 12
27.5.0 77 / 12
27.4.2 77 / 12
27.4.1 77 / 13
27.4.0 77 / 13
27.3.0 77 / 13
27.2.0 77 / 13
27.1.0 77 / 13
27.0.0 77 / 13
26.1.0 77 / 13
26.0.2 77 / 13
26.0.1 77 / 13
26.0.0 77 / 13
25.2.0 77 / 13
25.1.0 76 / 12
25.0.0 76 / 12
24.13.0 76 / 14
24.12.0 76 / 14
24.11.0 76 / 14
24.10.0 76 / 14

v27.7.0

3 findings
HIGH New obfuscated file: dist/graphql-requests-663477fa.cjs.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/graphql-requests-b00291ee.cjs.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v27.6.1

3 findings
HIGH New obfuscated file: dist/graphql-requests-91522a81.cjs.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/graphql-requests-9bff62a9.cjs.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v27.5.4

3 findings
HIGH New obfuscated file: dist/graphql-requests-0b5eaa25.cjs.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/graphql-requests-70911fc7.cjs.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v26.0.2

3 findings
HIGH New obfuscated file: dist/graphql-requests-436511ba.cjs.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/graphql-requests-eca3d559.cjs.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v24.11.0

3 findings
HIGH New obfuscated file: dist/graphql-requests-0bfaefaf.cjs.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/graphql-requests-96bc67f5.cjs.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.