@contentful/live-preview
Preview SDK for both the field tagging connection + live content updates
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/src-CazfDf20.cjs | AI (source-diff): Bundled SDK output; net+exec are library primitives, no hostile target. | ai | |
| source-diff | net-exec-file:dist/src-gOMxjmYt.js | AI (source-diff): Rolldown ESM bundle of the same SDK; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/src-CazfDf20.cjs | AI (source-diff): Rolldown minified bundle, not obfuscation; content-source-maps zero-width encoding is expected. | ai | |
| source-diff | obfuscated-file:dist/src-VbuEYWL_.cjs | AI (source-diff): Bundled vite/rolldown output for content-source-maps; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/src-e13kLMf5.js | AI (source-diff): Bundle artifact of first-party SDK; no hostile net+exec behavior. | ai | |
| source-diff | net-exec-file:dist/src-VbuEYWL_.cjs | AI (source-diff): Bundle artifact of first-party SDK; no hostile net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/index-y_tTfYG2.cjs | AI (source-diff): Vite-bundled content-source-maps encoding; benign build output for this SDK. | ai | |
| source-diff | net-exec-file:dist/index-C5Din3Pu.js | AI (source-diff): Bundled SDK code, no hostile fetch/exec target; matches stated live-preview function. | ai | |
| source-diff | net-exec-file:dist/index-y_tTfYG2.cjs | AI (source-diff): Bundled SDK code, no hostile fetch/exec target; matches stated live-preview function. | ai | |
| source-diff | net-exec-file:dist/index-CGky0iBz.js | AI (source-diff): Same benign minified SDK code; no fetched-payload execution. | ai | |
| source-diff | net-exec-file:dist/index-BR1-7WxZ.cjs | AI (source-diff): Encode/decode + URL parsing in minified SDK output; no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-BR1-7WxZ.cjs | AI (source-diff): Minified bundle of Contentful's Unicode edit-tag encoding, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-C9sCzSmY.cjs | AI (source-diff): Bundled SDK build output; no dropper behavior, benign encoder logic. | ai | |
| source-diff | obfuscated-file:dist/index-C9sCzSmY.cjs | AI (source-diff): Minified bundle of Contentful invisible-char edit-info encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BSy_7kqK.js | AI (source-diff): Same bundled SDK, ESM variant; benign. | ai | |
| source-diff | net-exec-file:dist/index-DSzvrru9.cjs | AI (source-diff): Unicode-codepoint encode/decode + URL parsing flagged as net+exec; benign SDK logic. | ai | |
| source-diff | net-exec-file:dist/index-CL7aPN3X.js | AI (source-diff): Same benign encode/decode logic in ESM build variant. | ai | |
| source-diff | obfuscated-file:dist/index-DSzvrru9.cjs | AI (source-diff): Minified build output of invisible-char edit-info encoding, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-Dig1r0E4.js | AI (source-diff): Bundled SDK; encoding logic, no dropper behavior/hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-V_-n4X9G.cjs | AI (source-diff): Minified bundle output of edit-tag Unicode encoder; not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-V_-n4X9G.cjs | AI (source-diff): Bundled SDK; encoding logic, no dropper behavior/hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-ClETh9GB.cjs | AI (source-diff): Minified bundler output of documented Unicode edit-info encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-r02ppj-U.js | AI (source-diff): Same live-preview bundle logic; benign network/parse patterns. | ai | |
| source-diff | net-exec-file:dist/index-ClETh9GB.cjs | AI (source-diff): URL/JSON parsing in bundle, no fetched-code execution or exfil target. | ai | |
| source-diff | obfuscated-file:dist/index-Bnfxvhih.cjs | AI (source-diff): Minified build output implementing Contentful's invisible-char content tagging; stable per release. | ai | |
| source-diff | net-exec-file:dist/index-Bnfxvhih.cjs | AI (source-diff): Encoding/decoding SDK logic in bundled dist, no hostile fetch+exec destination. | ai | |
| source-diff | net-exec-file:dist/index-BC4rIK6w.js | AI (source-diff): Same SDK encoding logic in ESM bundle; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/index-BJ6b29Wf.cjs | AI (source-diff): Minified bundle output implementing documented zero-width edit-tag encoding; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Z8B07jlJ.js | AI (source-diff): Same bundled SDK output, ESM variant; benign live-preview encoding. | ai | |
| source-diff | net-exec-file:dist/index-BJ6b29Wf.cjs | AI (source-diff): Bundled SDK code; no hostile fetch/exec target, encoding logic only. | ai | |
| source-diff | net-exec-file:dist/index-BcdXI32C.cjs | AI (source-diff): Bundled build output for official Contentful SDK; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/index-BsEw_DeU.js | AI (source-diff): Same bundled SDK logic, ESM variant; benign. | ai | |
| source-diff | obfuscated-file:dist/index-BcdXI32C.cjs | AI (source-diff): Bundled minified SDK output; invisible-char encoding is core live-preview function, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src-Dy2rqqUZ.cjs | AI (source-diff): Content-source metadata encoder, not a dropper; benign SDK feature. | ai | |
| source-diff | obfuscated-file:dist/src-Dy2rqqUZ.cjs | AI (source-diff): Minified rolldown bundle of the SDK's zero-width codepoint encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src-BNMF2B9A.js | AI (source-diff): Readable rolldown-bundled SDK output; same encoder logic, no hostile target. | ai | |
| source-diff | net-exec-file:dist/index-BXf_ZeeV.cjs | AI (source-diff): Minified SDK bundle; net+eval heuristic false positive on official Contentful build output. | ai | |
| source-diff | net-exec-file:dist/index-RrXZ97Pr.js | AI (source-diff): Same minified SDK bundle; benign build output from official org. | ai | |
| source-diff | obfuscated-file:dist/index-BXf_ZeeV.cjs | AI (source-diff): Bundled dist; zero-width Unicode content-source-map encoder, not obfuscated payload. | ai | |
| source-diff | net-exec-file:dist/index-BcE3i9XZ.cjs | AI (source-diff): Long-line heuristic on legit bundled encoder; no real dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-3u4eKz-s.js | AI (source-diff): Same encoder in JS build output; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/index-BcE3i9XZ.cjs | AI (source-diff): Minified bundle of documented invisible-char content-source-map encoder, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BdQ-t5j7.cjs | AI (source-diff): Minified SDK bundle; no fetched-binary exec or exfil destination. | ai | |
| source-diff | net-exec-file:dist/index-DVTW8xJk.js | AI (source-diff): Minified SDK bundle; benign build output. | ai | |
| source-diff | obfuscated-file:dist/index-BdQ-t5j7.cjs | AI (source-diff): Vite-bundled content-source-maps unicode encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src-C7cXhlOc.cjs | AI (source-diff): Bundled SDK; content-tagging codec, no hostile fetch/exec destination. | ai | |
| source-diff | net-exec-file:dist/src-DpXJbZnK.js | AI (source-diff): Bundled SDK; content-tagging codec, no hostile fetch/exec destination. | ai | |
| source-diff | obfuscated-file:dist/src-C7cXhlOc.cjs | AI (source-diff): Rolldown-bundled minified output of official SDK; long lines are build artifact, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-ByITfjmi.cjs | AI (source-diff): Bundled SDK output; net+exec heuristic misfires on legit live-preview code. | ai | |
| source-diff | net-exec-file:dist/index-Bb-hmh7b.js | AI (source-diff): Same bundled SDK; benign network/postMessage usage for live preview. | ai | |
| source-diff | obfuscated-file:dist/index-ByITfjmi.cjs | AI (source-diff): Unicode zero-width edit-info encoder from @contentful/content-source-maps; bundled dist, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Cc8lUfSx.cjs | AI (source-diff): Bundled SDK dist; encoder/URL-parse pattern, no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-CWfya0MQ.js | AI (source-diff): Same bundled encoder logic in ESM twin; benign. | ai | |
| source-diff | obfuscated-file:dist/index-Cc8lUfSx.cjs | AI (source-diff): Content-source-maps invisible-char encoder; long lines are bundled Vite output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-jFZSkMpB.cjs | AI (source-diff): Bundled SDK output; no hostile fetch/exec target, first-party Contentful preview logic. | ai | |
| source-diff | obfuscated-file:dist/index-jFZSkMpB.cjs | AI (source-diff): Zero-width-char edit-tag encoder in bundled dist; recurring build artifact for this SDK. | ai | |
| source-diff | net-exec-file:dist/index-DONIKAeF.js | AI (source-diff): Same bundled first-party live-preview code; benign network+JSON logic. | ai | |
| source-diff | obfuscated-file:dist/index-BcOK2j59.cjs | AI (source-diff): Unicode-codepoint content-tagging encoder in bundled dist; false-positive for this SDK's core function. | ai | |
| source-diff | net-exec-file:dist/index-BcOK2j59.cjs | AI (source-diff): Bundled SDK output; net+exec heuristic misfires on live-preview encoder, no hostile target. | ai | |
| source-diff | net-exec-file:dist/index-Cu3sKETn.js | AI (source-diff): Same bundled encoder in ESM variant; benign build artifact. | ai | |
| source-diff | net-exec-file:dist/index-Ca8gh4ji.js | AI (source-diff): Bundled SDK code; net+exec heuristic on official Contentful dist bundle. | ai | |
| source-diff | net-exec-file:dist/index-FNA3PyQV.cjs | AI (source-diff): Bundled SDK code; net+exec heuristic on official Contentful dist bundle. | ai | |
| source-diff | obfuscated-file:dist/index-FNA3PyQV.cjs | AI (source-diff): Minified bundle output; zero-width-char edit-tag encoding, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CxHJ3uPI.cjs | AI (source-diff): Minified build output of Contentful's zero-width-char content-source-map encoder, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-1ElyYUDu.js | AI (source-diff): Same bundled encoder, ESM variant; benign first-party SDK code. | ai | |
| source-diff | net-exec-file:dist/index-CxHJ3uPI.cjs | AI (source-diff): Bundled SDK output; net+exec heuristic on legit live-preview encoder, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-C8Wl5Q9a.cjs | AI (source-diff): Minified bundle of Contentful's Unicode edit-info encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-C8Wl5Q9a.cjs | AI (source-diff): Minified SDK bundle; codepoint encode/decode, no fetched-code execution. | ai | |
| source-diff | net-exec-file:dist/index-BGDSxxFC.js | AI (source-diff): Same SDK bundle, ESM variant; benign live-preview encoding logic. | ai | |
| source-diff | net-exec-file:dist/index-CL1SAhuh.js | AI (source-diff): Same bundled ESM output as cjs sibling; legitimate SDK behavior. | ai | |
| source-diff | net-exec-file:dist/index-jkJnb17V.cjs | AI (source-diff): Bundled SDK; net+exec heuristic on legit content-source-map/live-update code. | ai | |
| source-diff | obfuscated-file:dist/index-jkJnb17V.cjs | AI (source-diff): Invisible-Unicode content-source-map encoder, minified build output; benign for this SDK. | ai | |
| source-diff | net-exec-file:dist/index-D7yy0vxo.js | AI (source-diff): ESM sibling of same bundled build output; benign. | ai | |
| source-diff | net-exec-file:dist/index-l7NjQcXz.cjs | AI (source-diff): Bundled SDK build; no dropper behavior, encode/decode helpers only. | ai | |
| source-diff | obfuscated-file:dist/index-l7NjQcXz.cjs | AI (source-diff): Vite build output of content-source-maps encoder; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/src-C9hMpwLR.cjs | AI (source-diff): Minified rolldown output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/src-CaS_Z6p_.js | AI (source-diff): Same rolldown bundle, .js variant; build artifact. | ai | |
| source-diff | net-exec-file:dist/src-C9hMpwLR.cjs | AI (source-diff): Rolldown bundle output for live-preview encoding feature; not a dropper. | ai | |
| source-diff | net-exec-file:dist/index-uwm6IWYN.cjs | AI (source-diff): Bundled SDK build; net+decode is legit source-map fetch/parse. | ai | |
| source-diff | net-exec-file:dist/index-C17nSolv.js | AI (source-diff): Same bundled SDK logic in ESM output; benign. | ai | |
| source-diff | obfuscated-file:dist/index-uwm6IWYN.cjs | AI (source-diff): Minified Vite bundle of content-source-maps encoder, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BBFPdhH0.cjs | AI (source-diff): Bundled SDK output; no hostile fetch/exec, first-party live-preview logic. | ai | |
| source-diff | obfuscated-file:dist/index-BBFPdhH0.cjs | AI (source-diff): Minified bundle of Contentful's Unicode edit-info encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-xXJl9JUq.js | AI (source-diff): Same bundled SDK code, benign build artifact. | ai | |
| source-diff | net-exec-file:dist/index-CVRmqoLq.cjs | AI (source-diff): Minified bundle heuristic FP; no hostile network target in legit Contentful SDK. | ai | |
| source-diff | obfuscated-file:dist/index-CVRmqoLq.cjs | AI (source-diff): Bundled/minified SDK build output, not obfuscation; regenerated each release. | ai | |
| source-diff | net-exec-file:dist/index-D4vH9yNi.js | AI (source-diff): Same bundled build FP across ESM/CJS outputs. | ai | |
| source-diff | obfuscated-file:dist/index-bmsQ42uB.cjs | AI (source-diff): Bundled dist with Unicode edit-info encoding tables; benign minified SDK output. | ai | |
| source-diff | net-exec-file:dist/index-bmsQ42uB.cjs | AI (source-diff): Net+exec heuristic on bundled SDK; no hostile destination, standard live-preview encoding logic. | ai | |
| source-diff | net-exec-file:dist/index-BWwcdB3_.js | AI (source-diff): Same bundled SDK code in ESM form; benign build output. | ai | |
| source-diff | net-exec-file:dist/index-DBm-yZjK.cjs | AI (source-diff): Zero-width encode/decode logic, no fetched-payload execution; false positive in minified SDK dist. | ai | |
| source-diff | obfuscated-file:dist/index-DBm-yZjK.cjs | AI (source-diff): Minified dist of the live-preview Unicode edit-info encoder; benign build output. | ai | |
| source-diff | net-exec-file:dist/index-D41C7B6Q.js | AI (source-diff): Same encoder in ESM dist; no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-Btv3iL1F.js | AI (source-diff): Same bundled SDK content in unminified form; benign. | ai | |
| source-diff | net-exec-file:dist/index-By3Rqgs3.cjs | AI (source-diff): Bundled SDK output; no fetched-binary execution, benign codepoint/JSON logic. | ai | |
| source-diff | obfuscated-file:dist/index-By3Rqgs3.cjs | AI (source-diff): Minified bundle of Contentful's zero-width-char edit-info encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CAESNJuv.cjs | AI (source-diff): Codepoint-encoding logic in vite bundle; no fetched-binary execution or exfil. | ai | |
| source-diff | net-exec-file:dist/index-CChN__FL.js | AI (source-diff): Same encoder logic in ESM bundle; benign. | ai | |
| source-diff | obfuscated-file:dist/index-CAESNJuv.cjs | AI (source-diff): Bundled content-source-maps invisible-Unicode encoder; benign minified build output. | ai | |
| source-diff | obfuscated-file:dist/index-BgJYYYwy.cjs | AI (source-diff): Bundled invisible-char encoder for live-preview edit info; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BgJYYYwy.cjs | AI (source-diff): SDK bundle; no dropper behavior, benign encode/decode + fetch. | ai | |
| source-diff | net-exec-file:dist/index-CCtUt9Tt.js | AI (source-diff): Same SDK bundle content; benign live-preview networking. | ai | |
| source-diff | obfuscated-file:dist/index-CzzyreLd.cjs | AI (source-diff): Bundled dist implementing content-source-maps invisible-char encoding; long lines are minified build output. | ai | |
| source-diff | net-exec-file:dist/index-CzzyreLd.cjs | AI (source-diff): Bundled SDK dist; no dropper behavior, matches stated live-preview function. | ai | |
| source-diff | net-exec-file:dist/index-D-6iR_jP.js | AI (source-diff): ESM twin of same bundled dist; benign SDK build output. | ai | |
| source-diff | net-exec-file:dist/index-CKnNtMVx.js | AI (source-diff): Bundled first-party live-preview code; no hostile net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/index-BBQr5qrL.cjs | AI (source-diff): Vite bundle output of content-source-maps Unicode encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BBQr5qrL.cjs | AI (source-diff): Bundled first-party live-preview code; no hostile net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/index-55xaTOC0.cjs | AI (source-diff): Vite-bundled content-source-maps Unicode encoder; benign build output. | ai | |
| source-diff | net-exec-file:dist/index-55xaTOC0.cjs | AI (source-diff): Bundled SDK output; no fetched-binary/inline-eval behavior in sample. | ai | |
| source-diff | net-exec-file:dist/index-BiG5czIX.js | AI (source-diff): Bundled SDK output; same encoder logic, benign. | ai | |
| source-diff | net-exec-file:dist/index-BWioMUj8.js | AI (source-diff): Same SDK codec bundle, ESM variant; benign. | ai | |
| source-diff | net-exec-file:dist/index-DjhlJY6b.cjs | AI (source-diff): Encode/decode + fetch is the SDK's live-preview core; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/index-DjhlJY6b.cjs | AI (source-diff): Vite-bundled content-source-maps codec (invisible-char encoding), not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-CkU3FxlH.js | AI (source-diff): Vite bundle output; benign content-source-maps codec. | ai | |
| source-diff | obfuscated-file:dist/index-DNJKuG9c.cjs | AI (source-diff): Minified vite build, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DNJKuG9c.cjs | AI (source-diff): Vite bundle output; encoding logic, no fetched-code execution. | ai | |
| source-diff | net-exec-file:dist/index-Cwoaqxkt.js | AI (source-diff): Bundled build output; no dropper behavior, benign for this package. | ai | |
| source-diff | net-exec-file:dist/index-CLlmqir1.cjs | AI (source-diff): Bundled build output; no dropper behavior, benign for this package. | ai | |
| source-diff | obfuscated-file:dist/index-CLlmqir1.cjs | AI (source-diff): Vite-minified dist of the source-maps encoder; recurs every release. | ai | |
| source-diff | net-exec-file:dist/index-BJjjK8VY.js | AI (source-diff): Same bundled SDK output in ESM form; benign encoder logic. | ai | |
| source-diff | net-exec-file:dist/index-BZ8d8cOE.cjs | AI (source-diff): Bundled SDK output; codepoint/URL logic misreads as net+exec, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/index-BZ8d8cOE.cjs | AI (source-diff): Vite-bundled dist for content-source-maps zero-width encoder; minified, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-CRqler0W.cjs | AI (source-diff): Minified Vite output of content-source-maps Unicode encoder, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CRqler0W.cjs | AI (source-diff): Encoder/decoder logic; no dropper behavior, benign build artifact. | ai | |
| source-diff | net-exec-file:dist/index-BH_OaR7W.js | AI (source-diff): Same encoder logic in ESM build output; benign. | ai | |
| source-diff | obfuscated-file:dist/index-C2Z6VW0_.cjs | AI (source-diff): Minified bundle output of official Contentful SDK; not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-C2Z6VW0_.cjs | AI (source-diff): Bundler heuristic FP on legit SDK dist; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/index-CWmP-2HO.js | AI (source-diff): Bundler heuristic FP on legit SDK dist; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/index-vbrZWNn8.js | AI (source-diff): Same bundled SDK logic in ESM output; benign. | ai | |
| source-diff | net-exec-file:dist/index-CFutq1Xd.cjs | AI (source-diff): Minified SDK bundle; codepoint encode/decode, no hostile fetch+exec. | ai | |
| source-diff | obfuscated-file:dist/index-CFutq1Xd.cjs | AI (source-diff): Vite-minified build output; content-source-map Unicode encoding, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-incI5N0z.js | AI (source-diff): Same source-maps encoder in ESM bundle; no fetched-code execution. | ai | |
| source-diff | net-exec-file:dist/index-VAB_rHFi.cjs | AI (source-diff): JSON.parse of decoded edit-info, not code exec; benign SDK encoder in bundled output. | ai | |
| source-diff | obfuscated-file:dist/index-VAB_rHFi.cjs | AI (source-diff): Vite-bundled content-source-maps invisible-char encoder; long lines are minification, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DYPyK3-e.cjs | AI (source-diff): Bundled SDK; encode/decode logic, no fetched-binary execution or hostile endpoint. | ai | |
| source-diff | net-exec-file:dist/index-D9IzsERL.js | AI (source-diff): ESM sibling of same bundled SDK output; benign. | ai | |
| source-diff | obfuscated-file:dist/index-DYPyK3-e.cjs | AI (source-diff): Vite build output; long lines from Unicode codepoint tables for content-source-maps encoding, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DGlupfJI.js | AI (source-diff): Same bundled SDK logic in ESM output; benign. | ai | |
| source-diff | net-exec-file:dist/index-BnLyXVi4.cjs | AI (source-diff): Bundled SDK code; no fetched-code execution, just codepoint encode/decode. | ai | |
| source-diff | obfuscated-file:dist/index-BnLyXVi4.cjs | AI (source-diff): Minified Vite bundle of source-maps Unicode encoder; benign build output. | ai | |
| source-diff | obfuscated-file:dist/index-CsORnv_K.cjs | AI (source-diff): Minified dist output of Contentful's zero-width encoding logic, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-C7uBYwmL.js | AI (source-diff): Same benign encoding logic in unminified build variant. | ai | |
| source-diff | net-exec-file:dist/index-CsORnv_K.cjs | AI (source-diff): Codepoint encoding/JSON.parse pattern, no fetched-binary exec; benign SDK code. | ai | |
| source-diff | net-exec-file:dist/index-DCK6fjIR.cjs | AI (source-diff): Bundled SDK; net+JSON.parse patterns, no dropper/loader behavior. | ai | |
| source-diff | net-exec-file:dist/index-D9gxuvRN.js | AI (source-diff): Same bundled SDK output; benign live-preview functionality. | ai | |
| source-diff | obfuscated-file:dist/index-DCK6fjIR.cjs | AI (source-diff): Bundled dist implementing Contentful's zero-width-char edit-info encoding; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-C8Q2UOzz.cjs | AI (source-diff): Bundled SDK output; net+exec heuristic on legit live-preview messaging code. | ai | |
| source-diff | net-exec-file:dist/index-CGT_r_Uh.js | AI (source-diff): Bundled SDK output; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-C8Q2UOzz.cjs | AI (source-diff): Minified vite bundle; Unicode-codepoint tables are the SDK's source-map encoding, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CFI3n_kp.cjs | AI (source-diff): Bundled SDK output; no dropper behavior, just codepoint encode/decode logic. | ai | |
| source-diff | net-exec-file:dist/index-6a60Bhmi.js | AI (source-diff): Same bundled SDK source, unminified ESM variant; benign. | ai | |
| source-diff | obfuscated-file:dist/index-CFI3n_kp.cjs | AI (source-diff): Minified bundle of Unicode edit-info encoder; false-positive long-line trigger. | ai | |
| source-diff | net-exec-file:dist/index-BYZWrixv.cjs | AI (source-diff): URL parsing + JSON decode in bundled SDK, no fetched-code execution. | ai | |
| source-diff | net-exec-file:dist/index-Bw-_OeWY.js | AI (source-diff): Same benign encoder, ESM build output of official SDK. | ai | |
| source-diff | obfuscated-file:dist/index-BYZWrixv.cjs | AI (source-diff): Vite-bundled content-source-maps invisible-char encoder; minified, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-JyAyuKLS.js | AI (source-diff): Bundled SDK output; no hostile fetch/exec target, stable FP. | ai | |
| source-diff | obfuscated-file:dist/index-DJTHLeG4.cjs | AI (source-diff): Invisible-char content-source-map encoder; minified vite output, benign for this package. | ai | |
| source-diff | net-exec-file:dist/index-DJTHLeG4.cjs | AI (source-diff): Bundled SDK output; no hostile fetch/exec target, stable FP. | ai | |
| source-diff | net-exec-file:dist/index-kjD1sBMe.js | AI (source-diff): Build-bundle heuristic false positive in minified dist. | ai | |
| source-diff | obfuscated-file:dist/index-DahRa9SD.cjs | AI (source-diff): Vite-minified dist output of the SDK's encoding logic; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DahRa9SD.cjs | AI (source-diff): Build-bundle heuristic false positive in minified dist. | ai | |
| source-diff | obfuscated-file:dist/index-CPUcM0Va.cjs | AI (source-diff): Bundled dist; long lines are Contentful's Unicode edit-info encoder, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CPUcM0Va.cjs | AI (source-diff): Minified bundle; URL/decode heuristics misfire on legit SDK encoding logic. | ai | |
| source-diff | net-exec-file:dist/index-DxAnX9OZ.js | AI (source-diff): Same bundled SDK output; no fetched-binary exec, benign. | ai | |
| source-diff | net-exec-file:dist/index-CqF6bdnZ.js | AI (source-diff): Minified SDK bundle; live-preview needs network calls, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-D_fGxCsx.cjs | AI (source-diff): Vite-bundled minified output implementing content-source-map encoding; benign build artifact. | ai | |
| source-diff | net-exec-file:dist/index-D_fGxCsx.cjs | AI (source-diff): Minified SDK bundle; no fetched-binary exec or exfil target, expected build output. | ai | |
| source-diff | obfuscated-file:dist/index-CQcAUn0s.cjs | AI (source-diff): Minified Vite bundle output, not obfuscation; benign build artifact for this SDK. | ai | |
| source-diff | net-exec-file:dist/index-BrCbu6Ek.js | AI (source-diff): Bundled ESM build output; same benign SDK logic. | ai | |
| source-diff | net-exec-file:dist/index-CQcAUn0s.cjs | AI (source-diff): Bundled build output; content-source-map encoding, no hostile fetch/exec target. | ai | |
| source-diff | obfuscated-file:dist/index-CFy3VtL5.cjs | AI (source-diff): Minified vite output of content-source-maps codepoint encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Br2Z3Job.js | AI (source-diff): Bundled SDK build; encoding logic, no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-CFy3VtL5.cjs | AI (source-diff): Bundled SDK build; encoding logic, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-DjrB8Q1r.cjs | AI (source-diff): Vite-minified dist output; encoder uses zero-width Unicode tables, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DchkmM45.js | AI (source-diff): ESM twin of the cjs build output; same benign SDK logic. | ai | |
| source-diff | net-exec-file:dist/index-DjrB8Q1r.cjs | AI (source-diff): Minified build of live-preview SDK; net+URL parsing is normal SDK function, no fetched-code execution. | ai | |
| source-diff | net-exec-file:dist/index-vHo10KOP.js | AI (source-diff): Same bundled SDK content in ESM form; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-CGsLI5ED.cjs | AI (source-diff): Minified Vite bundle output, not obfuscation; standard for this build pipeline. | ai | |
| source-diff | net-exec-file:dist/index-CGsLI5ED.cjs | AI (source-diff): Bundled SDK code; unicode edit-info encoding, no hostile fetch/exec destination. | ai | |
| source-diff | obfuscated-file:dist/index-D0tGS6-9.cjs | AI (source-diff): Vite-bundled minified output; zero-width encoding is documented content-source-maps feature. | ai | |
| source-diff | net-exec-file:dist/index-DTAeTYjK.js | AI (source-diff): Build bundle for first-party SDK; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/index-D0tGS6-9.cjs | AI (source-diff): Build bundle for first-party SDK; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/index-BRM1evsg.js | AI (source-diff): Same bundled SDK build; benign encoder, no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-DbHtArXe.cjs | AI (source-diff): Bundled SDK code; encoder logic, no fetched-payload execution. | ai | |
| source-diff | obfuscated-file:dist/index-DbHtArXe.cjs | AI (source-diff): Vite-bundled minified output of content-source-maps encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src-D9U4PMO2.cjs | AI (source-diff): Content-source-map Unicode encoding + bundle runtime; no hostile fetch/exec target. | ai | |
| source-diff | obfuscated-file:dist/src-D9U4PMO2.cjs | AI (source-diff): Rolldown-bundled minified output; long lines are build artifact, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src-DxKlL-rp.js | AI (source-diff): Same rolldown build output; benign SDK functionality. | ai | |
| source-diff | obfuscated-file:dist/index-DPa35cVv.cjs | AI (source-diff): Invisible-Unicode content-source-maps encoder in Vite bundle output; stable feature of this SDK. | ai | |
| source-diff | net-exec-file:dist/index-DPa35cVv.cjs | AI (source-diff): Unicode encode/decode round-trip, not net+exec dropper; bundled build artifact. | ai | |
| source-diff | net-exec-file:dist/index-DIczhOoz.js | AI (source-diff): Same encoder logic in ESM bundle; benign build output. | ai | |
| source-diff | net-exec-file:dist/index-DOONljbN.js | AI (source-diff): Bundled SDK output; same heuristic on ESM build, benign. | ai | |
| source-diff | net-exec-file:dist/index-WfjujYGF.cjs | AI (source-diff): Bundled SDK output; net+eval heuristic on minified live-preview code, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-WfjujYGF.cjs | AI (source-diff): Vite-bundled minified output implementing zero-width Unicode encoder; benign for this SDK. | ai | |
| source-diff | obfuscated-file:dist/index-B_KvkeRr.cjs | AI (source-diff): Vite-bundled minified dist for official Contentful SDK; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DamoDgBk.js | AI (source-diff): Bundled SDK build output; same benign encoder logic. | ai | |
| source-diff | net-exec-file:dist/index-B_KvkeRr.cjs | AI (source-diff): Bundled SDK build output; unicode-encoding logic, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-Bkc6mCY-.cjs | AI (source-diff): Vite-bundled dist; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Bkc6mCY-.cjs | AI (source-diff): Bundled SDK build; encoding/URL logic, no malicious fetch-exec. | ai | |
| source-diff | net-exec-file:dist/index-DJiGEKYp.js | AI (source-diff): Bundled SDK build; encoding/URL logic, no malicious fetch-exec. | ai | |
| source-diff | obfuscated-file:dist/index-jnO_t1cS.cjs | AI (source-diff): Vite-minified dist of the invisible-unicode encoder; benign build output. | ai | |
| source-diff | net-exec-file:dist/index-BtEraJDq.js | AI (source-diff): Minified SDK bundle, no dropper behavior; stable build artifact. | ai | |
| source-diff | net-exec-file:dist/index-jnO_t1cS.cjs | AI (source-diff): Minified SDK bundle, no dropper behavior; stable build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-DHSZd87r.cjs | AI (source-diff): Vite build output of Contentful content-source-maps codec; long lines are minified, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/index-DHSZd87r.cjs | AI (source-diff): Encoder/JSON.parse logic misfires net-exec heuristic; benign SDK code. | ai | |
| source-diff | net-exec-file:dist/index-BIOiMqgB.js | AI (source-diff): Same SDK bundle, ESM variant; benign. | ai | |
| source-diff | obfuscated-file:dist/index-PRKMEC9g.cjs | AI (source-diff): Vite-bundled dist output; long lines are minification, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CQPxCeNq.js | AI (source-diff): Same bundled SDK source-map encoding; benign build artifact. | ai | |
| source-diff | net-exec-file:dist/index-PRKMEC9g.cjs | AI (source-diff): Bundled SDK; encoding/URL-parse logic, no fetched-binary execution. | ai | |
| source-diff | obfuscated-file:dist/index-CJoIxScS.cjs | AI (source-diff): Zero-width Unicode edit-info encoder from content-source-maps, not obfuscation; bundled dist output. | ai | |
| source-diff | net-exec-file:dist/index-ff-Ac6Z7.js | AI (source-diff): Same bundled SDK code as .cjs; benign for this package. | ai | |
| source-diff | net-exec-file:dist/index-CJoIxScS.cjs | AI (source-diff): Bundled SDK dist; net+parse are the live-preview fetch/encode paths, no fetched-binary exec. | ai | |
| source-diff | net-exec-file:dist/index-DOW5gga0.js | AI (source-diff): Bundled first-party SDK; same encoder logic, no exfil target. | ai | |
| source-diff | obfuscated-file:dist/index-21SNnixq.cjs | AI (source-diff): Minified build output; zero-width-codepoint edit-info encoder is core SDK function. | ai | |
| source-diff | net-exec-file:dist/index-21SNnixq.cjs | AI (source-diff): Net+exec heuristic on bundled first-party SDK; no hostile destination in sample. | ai | |
| source-diff | net-exec-file:dist/index-Dhg_FUK6.cjs | AI (source-diff): Encoder/URL parsing in Vite bundle, no fetched-binary exec; false positive for this package. | ai | |
| source-diff | net-exec-file:dist/index-D-TlChK0.js | AI (source-diff): Same encoder logic in ESM dist bundle; benign build output. | ai | |
| source-diff | obfuscated-file:dist/index-Dhg_FUK6.cjs | AI (source-diff): Invisible-Unicode source-maps encoder in bundled dist; benign build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/index-DuGfCK7B.cjs | AI (source-diff): Vite-bundled dist; invisible-char source-map encoding, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CcU-PVh0.js | AI (source-diff): Bundled build output of legit SDK; no hostile fetch+exec. | ai | |
| source-diff | net-exec-file:dist/index-DuGfCK7B.cjs | AI (source-diff): Bundled build output of legit SDK; no hostile fetch+exec. | ai | |
| source-diff | net-exec-file:dist/index-DVicdrJv.cjs | AI (source-diff): Bundled build; URL/dynamic patterns are the SDK's benign source-map logic. | ai | |
| source-diff | obfuscated-file:dist/index-DVicdrJv.cjs | AI (source-diff): Minified vite build output; unicode encoding is the source-maps feature, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CzUiJVZs.js | AI (source-diff): Same bundled SDK output, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-2lsIzeme.cjs | AI (source-diff): Vite-bundled dist output; long lines are minification, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-D8MrX8ez.js | AI (source-diff): Bundled SDK build output; benign URL parsing + JSON encoding. | ai | |
| source-diff | net-exec-file:dist/index-2lsIzeme.cjs | AI (source-diff): Bundled SDK; URL/encode logic, no fetched-code execution. | ai | |
| source-diff | obfuscated-file:dist/index-o4M5dVAP.cjs | AI (source-diff): Vite-bundled minified output; invisible-Unicode encoding is the SDK's content-source-maps feature. | ai | |
| source-diff | net-exec-file:dist/index-o4M5dVAP.cjs | AI (source-diff): Bundled SDK output; URL/regex parsing not dropper behavior, no fetched-binary exec. | ai | |
| source-diff | net-exec-file:dist/index-D2R9i9P7.js | AI (source-diff): Same bundled SDK output as CJS twin; benign for this package. | ai | |
| source-diff | net-exec-file:dist/index-CHsPjn18.js | AI (source-diff): Same minified SDK bundle as .cjs; benign build output. | ai | |
| source-diff | obfuscated-file:dist/index-BiHDZgVT.cjs | AI (source-diff): Vite-minified dist build output, not obfuscation; regenerated each release. | ai | |
| source-diff | net-exec-file:dist/index-BiHDZgVT.cjs | AI (source-diff): Minified SDK bundle; zero-width-char encoder tables, no malicious network+exec behavior. | ai | |
| source-diff | net-exec-file:dist/index-DzZfHxgU.cjs | AI (source-diff): Bundled SDK; net+exec patterns are normal live-preview build output. | ai | |
| source-diff | net-exec-file:dist/index-BBVabXHn.js | AI (source-diff): Bundled SDK; net+exec patterns are normal live-preview build output. | ai | |
| source-diff | obfuscated-file:dist/index-DzZfHxgU.cjs | AI (source-diff): Vite-bundled dist; long lines are minified codec, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DqNFIc9P.js | AI (source-diff): Bundled SDK code; benign encoding logic, not remote code execution. | ai | |
| source-diff | net-exec-file:dist/index-CPOjLBZc.cjs | AI (source-diff): Bundled SDK code; URL/JSON parsing not fetch+eval dropper. | ai | |
| source-diff | obfuscated-file:dist/index-CPOjLBZc.cjs | AI (source-diff): Minified vite build output; content-source-map char encoding, no obfuscation payload. | ai | |
| source-diff | net-exec-file:dist/index--w29-VoG.js | AI (source-diff): Same bundled SDK output; benign network+eval false positive. | ai | |
| source-diff | obfuscated-file:dist/index-CaRNoz-h.cjs | AI (source-diff): Vite-bundled minified dist output; per-build hashed filenames recur every release. | ai | |
| source-diff | net-exec-file:dist/index-CaRNoz-h.cjs | AI (source-diff): SDK live-update fetch + minified bundle; benign for this package. | ai | |
| source-diff | obfuscated-file:dist/index-CYPwm4cp.cjs | AI (source-diff): Vite-bundled dist output of official Contentful SDK; minified, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/index-CYPwm4cp.cjs | AI (source-diff): Bundled SDK build; net+exec heuristic on minified vendor code, no hostile target. | ai | |
| source-diff | net-exec-file:dist/index-Cu3MQRv6.js | AI (source-diff): Same bundled SDK output, ESM variant; benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-BXGAUPnI.cjs | AI (source-diff): Vite build output; unicode encoding is the SDK's documented content-source-maps feature. | ai | |
| source-diff | net-exec-file:dist/index-BXGAUPnI.cjs | AI (source-diff): Bundled SDK dist; no hostile fetch/exec target, benign preview-SDK code. | ai | |
| source-diff | net-exec-file:dist/index-C5OFgc49.js | AI (source-diff): Bundled SDK dist; no hostile fetch/exec target, benign preview-SDK code. | ai | |
| source-diff | obfuscated-file:dist/index-BTGK0QIv.cjs | AI (source-diff): Vite-minified dist; long lines are build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BTGK0QIv.cjs | AI (source-diff): Minified SDK bundle; codepoint encoding is content-source-maps feature, no hostile net target. | ai | |
| source-diff | net-exec-file:dist/index-B7CZzeKh.js | AI (source-diff): Same minified SDK bundle; benign source-maps encoding logic. | ai | |
| source-diff | obfuscated-file:dist/index-CihlSKQp.cjs | AI (source-diff): Vite-minified dist output of official Contentful SDK; long lines are build artifact. | ai | |
| source-diff | net-exec-file:dist/index-DVEO208b.js | AI (source-diff): Minified bundle; encoding tables are content-source-maps, no hostile network/exec target. | ai | |
| source-diff | net-exec-file:dist/index-CihlSKQp.cjs | AI (source-diff): Minified bundle; encoding tables are content-source-maps, no hostile network/exec target. | ai | |
| source-diff | net-exec-file:dist/index-1VdKaGiK.js | AI (source-diff): Same bundled SDK logic in ESM form; benign. | ai | |
| source-diff | obfuscated-file:dist/index-h-4JlUBz.cjs | AI (source-diff): Vite-minified build output of content-source-maps encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-h-4JlUBz.cjs | AI (source-diff): Bundled SDK code; URL/JSON.parse are encoding helpers, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-CiphPJIY.cjs | AI (source-diff): Minified vite bundle of the source-maps encoder, not obfuscation; stable build output. | ai | |
| source-diff | net-exec-file:dist/index-CiphPJIY.cjs | AI (source-diff): Bundled SDK encoding logic; no hostile fetch/exec target. | ai | |
| source-diff | net-exec-file:dist/index-r54_vu7f.js | AI (source-diff): Same bundled SDK output, ESM variant; benign. | ai | |
| source-diff | net-exec-file:dist/index-UxfOQw7J.js | AI (source-diff): Same bundled SDK code; benign encode/decode logic. | ai | |
| source-diff | net-exec-file:dist/index-DBF-Q4u3.cjs | AI (source-diff): Build output; URL/JSON handling triggers heuristic, no fetched-code execution. | ai | |
| source-diff | obfuscated-file:dist/index-DBF-Q4u3.cjs | AI (source-diff): Vite-bundled minified output of the SDK's unicode source-map encoder; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-VfQMCowF.js | AI (source-diff): Bundled ESM SDK output; benign live-preview networking. | ai | |
| source-diff | net-exec-file:dist/index-Co7Fd_cL.cjs | AI (source-diff): Bundled SDK output; net+exec pattern-match on build bundle, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/index-Co7Fd_cL.cjs | AI (source-diff): Minified vite output implementing zero-width content-source-map encoding; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CItojYns.js | AI (source-diff): Bundled SDK output; benign build artifact from official publisher. | ai | |
| source-diff | obfuscated-file:dist/index-Dt2KLugV.cjs | AI (source-diff): Zero-width-codepoint edit-info encoder, core live-preview feature; minified dist, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Dt2KLugV.cjs | AI (source-diff): Bundled SDK output; no hostile fetch/exec destination in a first-party Contentful package. | ai | |
| source-diff | net-exec-file:dist/index-DT8Q_2SQ.js | AI (source-diff): Same first-party SDK bundle; no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-B2kLB0KB.cjs | AI (source-diff): Minified bundle of Contentful zero-width edit-info encoder; long lines are build output. | ai | |
| source-diff | net-exec-file:dist/index-B2kLB0KB.cjs | AI (source-diff): Heuristic misfire on encode/decode logic; no fetched-payload execution. | ai | |
| source-diff | net-exec-file:dist/index-DuyuNEnF.js | AI (source-diff): Same bundled SDK output; network+parse, not code drop. | ai | |
| source-diff | net-exec-file:dist/index-BKCe-T5V.cjs | AI (source-diff): Bundled SDK fetch + JSON decode; no fetched-binary execution. Benign for this package. | ai | |
| source-diff | obfuscated-file:dist/index-BKCe-T5V.cjs | AI (source-diff): Minified bundle output of live-preview SDK; unicode encoding is documented inspector feature, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-BmcbBbOf.cjs | AI (source-diff): Bundled zero-width-char encoding for inspector edit-info; not obfuscation, stable for this SDK. | ai | |
| source-diff | net-exec-file:dist/index-CM-lZf9g.js | AI (source-diff): Same benign bundled SDK code, ESM variant. | ai | |
| source-diff | net-exec-file:dist/index-BmcbBbOf.cjs | AI (source-diff): SDK build output; net+JSON.parse pattern, no fetched-binary exec. | ai | |
| source-diff | net-exec-file:dist/index-Bg-XidIL.cjs | AI (source-diff): URL parsing + JSON codec, no fetched-code execution; legit SDK build output. | ai | |
| source-diff | net-exec-file:dist/index-C1RgK1xT.js | AI (source-diff): Same benign edit-info codec in ESM dist; no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-Bg-XidIL.cjs | AI (source-diff): Contentful invisible-char edit-encoding in bundled dist; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CNgtbTCn.cjs | AI (source-diff): SDK bundle; codepoint tables trip net/exec heuristic, no real dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-Bu4KD0rP.js | AI (source-diff): Same benign SDK bundle output as the cjs variant. | ai | |
| source-diff | obfuscated-file:dist/index-CNgtbTCn.cjs | AI (source-diff): Minified bundle of Contentful zero-width encoding logic, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-BgQyFZeN.cjs | AI (source-diff): Bundled build; unicode-encoding for source maps, no hostile net/exec target. | ai | |
| source-diff | net-exec-file:dist/index-mpy6K7D9.js | AI (source-diff): Same bundled build output, benign SDK logic. | ai | |
| source-diff | obfuscated-file:dist/index-BgQyFZeN.cjs | AI (source-diff): Minified vite build output; readable JS logic, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-BO1Y-a0e.cjs | AI (source-diff): Vite build output, not obfuscation; official Contentful SDK dist. | ai | |
| source-diff | net-exec-file:dist/index-2NJWBdxg.js | AI (source-diff): Minified bundle of SDK preview logic; no hostile net/exec target. | ai | |
| source-diff | net-exec-file:dist/index-BO1Y-a0e.cjs | AI (source-diff): Minified bundle of SDK preview logic; no hostile net/exec target. | ai | |
| source-diff | net-exec-file:dist/index-O4mo4Att.js | AI (source-diff): Same minified SDK bundle; benign network+decode for live preview. | ai | |
| source-diff | net-exec-file:dist/index-DUOHoIJ7.cjs | AI (source-diff): Minified SDK bundle; no hostile fetched destination, content-source-maps encoding logic. | ai | |
| source-diff | obfuscated-file:dist/index-DUOHoIJ7.cjs | AI (source-diff): Vite-minified dist output; long lines are build artifact, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-Doe9SN_6.cjs | AI (source-diff): Bundled content-source-maps invisible-char encoder, not obfuscated payload; minified build output. | ai | |
| source-diff | net-exec-file:dist/index-CyUSsFZT.js | AI (source-diff): Same encoding logic in ESM variant; build output, not malware. | ai | |
| source-diff | net-exec-file:dist/index-Doe9SN_6.cjs | AI (source-diff): Codepoint encode/decode + JSON.parse, no fetched-binary exec; benign SDK feature. | ai | |
| source-diff | obfuscated-file:dist/index-CpgJ20sf.cjs | AI (source-diff): Minified Vite output of content-source-maps unicode encoder, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CpgJ20sf.cjs | AI (source-diff): Codepoint encode/decode logic, no fetched-binary exec; bundled SDK dist. | ai | |
| source-diff | net-exec-file:dist/index-C_TBFqeP.js | AI (source-diff): Same bundled SDK dist; benign source-map encoding. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publish for official Contentful package. | ai | |
| source-diff | net-exec-file:dist/index-DOTA3foM.js | AI (source-diff): Bundled SDK build output; benign content-source-maps codec. | ai | |
| source-diff | net-exec-file:dist/index-BQlezUIC.cjs | AI (source-diff): Bundled SDK build output; no hostile fetch/exec target present. | ai | |
| source-diff | obfuscated-file:dist/index-BQlezUIC.cjs | AI (source-diff): Vite-bundled dist implementing content-source-maps unicode encoding; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-gLc9iu1D.cjs | AI (source-diff): Vite-bundled minified dist output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-76hH1uuh.js | AI (source-diff): Minified build output; benign encoding logic. | ai | |
| source-diff | net-exec-file:dist/index-gLc9iu1D.cjs | AI (source-diff): Minified build output; content-source-maps encoding logic, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-DBoLcxQt.cjs | AI (source-diff): Vite-bundled dist; long lines are minification plus SDK's unicode edit-tag encoding, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-DBoLcxQt.cjs | AI (source-diff): Minified SDK bundle; no hostile fetch/exec destination in a well-known Contentful package. | ai | |
| source-diff | net-exec-file:dist/index-BI1JEOp6.js | AI (source-diff): Minified SDK bundle; benign network/exec patterns in official package. | ai | |
| source-diff | net-exec-file:dist/index-BQECtOLI.js | AI (source-diff): Same minified bundle; benign preview SDK build output. | ai | |
| source-diff | obfuscated-file:dist/index-Dvpc8HAP.cjs | AI (source-diff): Vite-minified build output of content-source-maps encoder, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Dvpc8HAP.cjs | AI (source-diff): Heuristic misfire on minified bundle; no dropper behavior in this SDK. | ai | |
| source-diff | net-exec-file:dist/index-h9k30EFp.js | AI (source-diff): Minified bundle of Contentful SDK; no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-CXg9wjEU.cjs | AI (source-diff): Minified bundle of Contentful SDK; no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-CXg9wjEU.cjs | AI (source-diff): vite build output; unicode-encoding for content-source-maps, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-SKEPZj9o.cjs | AI (source-diff): Minified vite build output of documented content-source-map encoding; stable for this package. | ai | |
| source-diff | net-exec-file:dist/src-BV4mhU9H.js | AI (source-diff): ESM bundle counterpart; same rolldown output, no malicious payload. | ai | |
| source-diff | net-exec-file:dist/src-7Oe7qYiM.cjs | AI (source-diff): Bundle includes live-preview SDK networking; no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/src-7Oe7qYiM.cjs | AI (source-diff): Rolldown CJS bundle output; minification is expected for this package. | ai | |
| source-diff | net-exec-file:dist/src-BVzLNsbv.cjs | AI (source-diff): Bundled SDK with fetch calls and dynamic requires; expected for a live-preview SDK. | ai | |
| source-diff | net-exec-file:dist/src-Dd1bV8rx.js | AI (source-diff): ESM counterpart of the CJS bundle; same legitimate SDK code. | ai | |
| source-diff | obfuscated-file:dist/src-BVzLNsbv.cjs | AI (source-diff): Minified CJS bundle from rolldown; standard for this package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/src-CwJyHRfo.cjs | AI (source-diff): CJS bundle minified by rolldown; standard build output for this package. | ai | |
| source-diff | net-exec-file:dist/src-CTjB7PIV.js | AI (source-diff): ESM bundle counterpart; same rolldown output with network + dynamic patterns from SDK logic. | ai | |
| source-diff | net-exec-file:dist/src-CwJyHRfo.cjs | AI (source-diff): Bundled SDK with network calls (fetch for CMS) and dynamic require shims; not malicious. | ai | |
| source-diff | net-exec-file:dist/src-DmYUaDf4.js | AI (source-diff): ESM bundle counterpart; same benign bundled code as CJS variant. | ai | |
| source-diff | net-exec-file:dist/src-BAzzj2P1.cjs | AI (source-diff): Bundled CJS output; network+exec pattern is from bundled dependencies, not malware. | ai | |
| source-diff | obfuscated-file:dist/src-BAzzj2P1.cjs | AI (source-diff): Minified CJS bundle from rolldown; stega encoding is part of live-preview tagging feature. | ai | |
| source-diff | obfuscated-file:dist/src-gyVL5-Kj.cjs | AI (source-diff): Minified rolldown bundle output; standard for this package's build pipeline. | ai | |
| source-diff | net-exec-file:dist/src-w-hF_slJ.js | AI (source-diff): ESM bundle counterpart; same legitimate live-preview network calls. | ai | |
| source-diff | net-exec-file:dist/src-gyVL5-Kj.cjs | AI (source-diff): Bundle contains fetch/WebSocket for live preview SDK functionality, not malware. | ai | |
| phantom-deps | phantom-dep:flatted | AI (phantom-deps): Monorepo SDK; declared deps used transitively or in config, not a real phantom risk. | ai | |
| phantom-deps | phantom-dep:@contentful/rich-text-types | AI (phantom-deps): Same-org peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lodash.isequal | AI (phantom-deps): Same pattern — declared peer/config dep in Contentful SDK monorepo. | ai | |
| phantom-deps | phantom-dep:graphql-tag | AI (phantom-deps): Same pattern — declared peer/config dep in Contentful SDK monorepo. | ai | |
| phantom-deps | phantom-dep:json-pointer | AI (phantom-deps): Same pattern — declared peer/config dep in Contentful SDK monorepo. | ai |
Versions (showing 51 of 124)
| Version | Deps | Published |
|---|---|---|
| 4.10.12 | 6 / 14 | |
| 4.10.11 | 6 / 14 | |
| 4.10.10 | 6 / 14 | |
| 4.10.9 | 6 / 14 | |
| 4.10.8 | 6 / 14 | |
| 4.10.7 | 6 / 14 | |
| 4.10.6 | 6 / 14 | |
| 4.10.5 | 6 / 14 | |
| 4.10.4 | 6 / 14 | |
| 4.10.3 | 6 / 14 | |
| 4.10.2 | 6 / 14 | |
| 4.10.1 | 6 / 14 | |
| 4.10.0 | 6 / 14 | |
| 4.9.13 | 6 / 14 | |
| 4.9.12 | 6 / 14 | |
| 4.9.11 | 6 / 14 | |
| 4.9.10 | 6 / 14 | |
| 4.9.9 | 6 / 14 | |
| 4.9.8 | 6 / 14 | |
| 4.9.7 | 6 / 14 | |
| 4.9.6 | 6 / 14 | |
| 4.9.5 | 6 / 14 | |
| 4.9.4 | 6 / 14 | |
| 4.9.3 | 6 / 14 | |
| 4.9.2 | 6 / 14 | |
| 4.9.1 | 6 / 14 | |
| 4.9.0 | 6 / 14 | |
| 4.8.4 | 6 / 14 | |
| 4.8.3 | 6 / 14 | |
| 4.8.2 | 6 / 14 | |
| 4.7.0 | 6 / 14 | |
| 4.6.58 | 6 / 14 | |
| 4.6.57 | 6 / 14 | |
| 4.6.56 | 6 / 14 | |
| 4.6.55 | 6 / 14 | |
| 4.6.54 | 6 / 14 | |
| 4.6.53 | 6 / 14 | |
| 4.6.52 | 6 / 14 | |
| 4.6.51 | 6 / 14 | |
| 4.6.50 | 6 / 14 | |
| 4.6.49 | 6 / 14 | |
| 4.6.48 | 6 / 14 | |
| 4.6.47 | 6 / 14 | |
| 4.6.46 | 6 / 14 | |
| 4.6.45 | 6 / 14 | |
| 4.6.44 | 6 / 14 | |
| 4.6.43 | 6 / 14 | |
| 4.6.42 | 6 / 14 | |
| 4.6.41 | 6 / 14 | |
| 4.6.40 | 6 / 14 | |
| 4.6.39 | 6 / 14 |
v4.10.12
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.11
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.10
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.10.9
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.11
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.10
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.9
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.7
5 findingsThis version was published by a different npm account than previous versions on 2026-03-02. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.6
5 findingsThis version was published by a different npm account than previous versions on 2026-02-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.5
5 findingsThis version was published by a different npm account than previous versions on 2026-02-19. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.4
5 findingsThis version was published by a different npm account than previous versions on 2026-02-16. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.3
5 findingsThis version was published by a different npm account than previous versions on 2026-02-09. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.2
5 findingsThis version was published by a different npm account than previous versions on 2026-02-02. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.1
5 findingsThis version was published by a different npm account than previous versions on 2026-01-26. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.9.0
5 findingsThis version was published by a different npm account than previous versions on 2025-12-17. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.8.4
5 findingsThis version was published by a different npm account than previous versions on 2025-12-15. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.8.3
5 findingsThis version was published by a different npm account than previous versions on 2025-12-08. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.8.2
5 findingsThis version was published by a different npm account than previous versions on 2025-12-05. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.7.0
5 findingsThis version was published by a different npm account than previous versions on 2025-11-24. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.58
5 findingsThis version was published by a different npm account than previous versions on 2025-11-24. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.57
5 findingsThis version was published by a different npm account than previous versions on 2025-11-17. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.56
5 findingsThis version was published by a different npm account than previous versions on 2025-11-10. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.55
5 findingsThis version was published by a different npm account than previous versions on 2025-11-10. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.6.54
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.