@cubejs-client/playground
<p align="center"><a href="https://cube.dev"><img src="https://i.imgur.com/zYHXm4o.png" alt="Cube.js" width="300px"></a></p>
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:public/vizard/assets/index-C388WnHl.js | AI (source-diff): Same Vite-minified bundle copied to public/; not obfuscated malware. | ai | |
| source-diff | net-exec-file:build/assets/index-D2YbzWux.js | AI (source-diff): fetch() in bundle is module-preload polyfill; no dropper/loader pattern present. | ai | |
| source-diff | obfuscated-file:build/assets/index-D2YbzWux.js | AI (source-diff): Vite production bundle containing React; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:build/vizard/assets/index-C388WnHl.js | AI (source-diff): Standard Vite-minified React SPA bundle; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:build/assets/index-BHMORpvF.js | AI (source-diff): Standard Vite-bundled React app output; minification is expected for this playground package. | ai | |
| source-diff | net-exec-file:build/assets/index-BHMORpvF.js | AI (source-diff): Network calls and dynamic code in a browser-targeted React bundle are normal; no malware indicators in the sample. | ai | |
| dependencies | unvetted-dep:flexsearch | AI (dependencies): flexsearch is a legitimate open-source search library; stable dependency for this package. | ai | |
| source-diff | net-exec-file:build/assets/index-D6_ZO5b0.js | AI (source-diff): Network calls and dynamic code in a browser SPA bundle are expected; no dropper pattern in the sample. | ai | |
| source-diff | obfuscated-file:build/assets/index-D6_ZO5b0.js | AI (source-diff): Standard Vite-minified SPA bundle; content is React production boilerplate, not obfuscated malware. | ai | |
| source-diff | net-exec-file:build/assets/index-Cq-vQO9J.js | AI (source-diff): Network calls and dynamic code in a browser bundle are normal React app patterns, not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/assets/index-Cq-vQO9J.js | AI (source-diff): Standard Vite-bundled frontend build artifact for the Cube.js playground; minification is expected. | ai | |
| source-diff | net-exec-file:build/assets/index-BR9mlzFM.js | AI (source-diff): Network calls and dynamic code in bundled React app are normal; no exfiltration pattern visible in sample. | ai | |
| source-diff | obfuscated-file:build/assets/index-BR9mlzFM.js | AI (source-diff): Vite-bundled frontend asset; minification is expected for this playground UI package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in a bundled antd/pagination CSS-in-JS file; not an evasion technique. | ai | |
| source-diff | net-exec-file:build/assets/index-DnbPXUAR.js | AI (source-diff): Network calls and dynamic code in bundled frontend JS are normal for a React playground app; no malware indicators in sample. | ai | |
| source-diff | obfuscated-file:build/assets/index-DnbPXUAR.js | AI (source-diff): Standard Vite-bundled frontend build artifact; minification is expected for this playground package. | ai | |
| source-diff | obfuscated-file:build/assets/index-Dp9g9mH4.js | AI (source-diff): Standard Vite-bundled React SPA output; minification is expected for this playground package. | ai | |
| source-diff | net-exec-file:build/assets/index-Dp9g9mH4.js | AI (source-diff): Network calls and dynamic execution are normal in a bundled browser SPA; no dropper pattern present. | ai | |
| phantom-deps | phantom-dep:graphql-ws | AI (phantom-deps): Used via dynamic import or config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-is | AI (phantom-deps): Peer/transitive usage pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:moment | AI (phantom-deps): Likely used transitively or in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:less | AI (phantom-deps): Build-time CSS tooling; phantom-dep false positive for this package. | ai | |
| semgrep | semgrep:toplevel-fetch | AI (semgrep): Fetch is gated on a specific pathname (/playground/live-preview/start) and only calls window.close(); benign UI lifecycle code. | ai | |
| phantom-deps | phantom-dep:vite-plugin-environment | AI (phantom-deps): Vite config usage; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:recursive-readdir | AI (phantom-deps): Build script usage; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:customize-cra | AI (phantom-deps): Build config usage; stable false positive for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 1.6.60 | 32 / 29 | |
| 1.6.59 | 32 / 29 | |
| 1.6.58 | 32 / 29 | |
| 1.6.57 | 32 / 29 | |
| 1.6.56 | 32 / 29 | |
| 1.6.55 | 32 / 29 | |
| 1.6.54 | 32 / 29 | |
| 1.6.53 | 32 / 29 | |
| 1.6.52 | 32 / 29 | |
| 1.6.51 | 32 / 29 | |
| 1.6.50 | 32 / 29 | |
| 1.6.49 | 32 / 29 | |
| 1.6.48 | 32 / 29 | |
| 1.6.47 | 32 / 29 | |
| 1.6.46 | 32 / 29 | |
| 1.6.45 | 32 / 29 | |
| 1.6.42 | 32 / 29 | |
| 1.6.41 | 32 / 29 | |
| 1.6.40 | 32 / 29 | |
| 1.6.39 | 32 / 29 | |
| 1.6.38 | 32 / 29 | |
| 1.6.37 | 32 / 29 | |
| 1.6.36 | 32 / 29 | |
| 1.6.35 | 32 / 29 | |
| 1.6.34 | 32 / 29 | |
| 1.6.33 | 32 / 29 | |
| 1.6.32 | 33 / 30 | |
| 1.5.3 | 33 / 30 | |
| 1.5.2 | 33 / 30 | |
| 1.4.3 | 33 / 30 | |
| 1.4.2 | 33 / 30 | |
| 1.4.1 | 33 / 30 |
v1.6.60
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.59
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.58
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.57
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (statsbot) on 2025-12-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.