@cordisjs/plugin-webui
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client-DlZX3-GF.js | AI (source-diff): Standard Vite-minified Vue frontend bundle; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/client-DlZX3-GF.js | AI (source-diff): Network calls are Vue/WebSocket client code; dynamic execution is Vue's render engine. | ai | |
| source-diff | obfuscated-file:dist/client-Dtmqj5mB.js | AI (source-diff): Standard Vite-minified frontend bundle for a WebUI plugin; minification is expected. | ai | |
| source-diff | obfuscated-file:dist/index-DdgkwjXY.js | AI (source-diff): Vite-bundled main entry for the WebUI plugin; minification is expected. | ai | |
| source-diff | net-exec-file:dist/client-Dtmqj5mB.js | AI (source-diff): Network calls and dynamic rendering are normal for a Vue-based WebUI client bundle. | ai | |
| source-diff | obfuscated-file:dist/vue-router-CBHOJdbh.js | AI (source-diff): vue-router minified bundle; standard vendored dependency in a WebUI dist. | ai | |
| source-diff | net-exec-file:dist/index-DdgkwjXY.js | AI (source-diff): WebUI client bundle; fetch/dynamic patterns are inherent to a browser UI plugin. | ai | |
| source-diff | net-exec-file:dist/client-BoqoeUPM.js | AI (source-diff): Network calls and dynamic code are Vue reactivity/rendering internals in a browser UI bundle. | ai | |
| source-diff | obfuscated-file:dist/client-BoqoeUPM.js | AI (source-diff): Standard Vite-minified Vue frontend bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-CQhQ4Hu8.js | AI (source-diff): Vite-bundled WebUI entry point importing @cordisjs/client; standard minification. | ai | |
| source-diff | obfuscated-file:dist/client-Ctv4fA69.js | AI (source-diff): Standard Vite-minified Vue frontend bundle; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/client-Ctv4fA69.js | AI (source-diff): Network calls and dynamic code are Vue reactivity/component patterns in a WebUI frontend bundle. | ai | |
| source-diff | obfuscated-file:dist/element-DId02cTi.js | AI (source-diff): Minified Element Plus component library bundle; expected for this WebUI package. | ai | |
| source-diff | net-exec-file:dist/element-DId02cTi.js | AI (source-diff): Element Plus bundle with Vue patterns; not malicious network+exec. | ai | |
| source-diff | net-exec-file:dist/index-CQhQ4Hu8.js | AI (source-diff): WebSocket client connection in a WebUI plugin is expected behavior, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/client-DOJjlkki.js | AI (source-diff): Standard Vite-minified Vue frontend bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/vue-77ec438a.js | AI (source-diff): Bundled Vue 3.5.34 runtime with license header; standard minification. | ai | |
| source-diff | net-exec-file:dist/index-D0jh_9G7.js | AI (source-diff): Frontend plugin bundle using @cordisjs/client socket; expected behavior. | ai | |
| source-diff | obfuscated-file:dist/index-D0jh_9G7.js | AI (source-diff): Vite-bundled plugin entry point; standard minification. | ai | |
| source-diff | net-exec-file:dist/element-u1gOXjDL.js | AI (source-diff): Element Plus frontend bundle; no malicious network/exec patterns. | ai | |
| source-diff | obfuscated-file:dist/element-u1gOXjDL.js | AI (source-diff): Minified Element Plus UI library bundle; benign. | ai | |
| source-diff | net-exec-file:dist/client-DOJjlkki.js | AI (source-diff): Network calls and dynamic code are Vue reactivity/component patterns in a frontend bundle, not dropper behavior. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 0.8.2 | 7 / 7 | |
| 0.8.1 | 7 / 7 | |
| 0.8.0 | 7 / 7 | |
| 0.7.0 | 6 / 7 | |
| 0.6.5 | 6 / 7 | |
| 0.6.4 | 6 / 7 | |
| 0.6.3 | 6 / 6 | |
| 0.6.2 | 6 / 6 | |
| 0.6.1 | 6 / 6 | |
| 0.6.0 | 6 / 6 | |
| 0.5.2 | 5 / 5 | |
| 0.5.1 | 5 / 5 | |
| 0.5.0 | 5 / 5 | |
| 0.4.3 | 5 / 5 | |
| 0.4.2 | 5 / 5 | |
| 0.4.1 | 5 / 5 | |
| 0.4.0 | 5 / 5 | |
| 0.3.1 | 4 / 4 | |
| 0.3.0 | 4 / 4 | |
| 0.2.6 | 4 / 4 | |
| 0.2.5 | 5 / 7 | |
| 0.2.4 | 6 / 9 | |
| 0.2.3 | 6 / 9 | |
| 0.2.2 | 6 / 9 | |
| 0.2.1 | 6 / 9 | |
| 0.2.0 | 5 / 9 | |
| 0.1.14 | 5 / 9 | |
| 0.1.13 | 5 / 9 | |
| 0.1.12 | 5 / 9 | |
| 0.1.11 | 5 / 8 | |
| 0.1.10 | 5 / 8 | |
| 0.1.9 | 5 / 8 | |
| 0.1.8 | 5 / 8 | |
| 0.1.7 | 5 / 8 | |
| 0.1.6 | 5 / 8 | |
| 0.1.5 | 5 / 8 | |
| 0.1.4 | 5 / 8 | |
| 0.1.3 | 4 / 8 | |
| 0.1.2 | 4 / 8 | |
| 0.1.1 | 4 / 8 | |
| 0.1.0 | 4 / 8 |
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.