← Home

@decocms/mesh

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

camudogimenes-decocxfirstdoit

Keywords

mcpmodel-context-protocolaigatewayself-hostedmeshtools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/client/assets/agent-detail-DorbgMCC.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/avatar-CugGqtYT.js AI (source-diff): Radix component bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-B_VwaOIL.js AI (source-diff): Radix component bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-BR4l5LqE.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-BqWyJ8Lf.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-B7exWPCY.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BQq-kgnK.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-IIw3ZuFv.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-Jwerghze.js AI (source-diff): Bundled Recharts chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-Jwerghze.js AI (source-diff): React synthetic event list, no real network+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CH7DXB6D.js AI (source-diff): Vite-bundled React app chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-D59JuXmr.js AI (source-diff): Bundled recharts/React output, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-D59JuXmr.js AI (source-diff): Standard bundled client JS, no dropper/loader behavior present. ai
source-diff obfuscated-file:dist/client/assets/chart-BV6LQupJ.js AI (source-diff): Bundled Recharts/Vite chunk; minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-BV6LQupJ.js AI (source-diff): React event-handler list in bundled chart lib; no real net+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agents-C--6EV5-.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-DPcF2-P-.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-CK4IO4hn.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DidLKXNZ.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-CRmafvjG.js AI (source-diff): Bundled recharts/vite output, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-CRmafvjG.js AI (source-diff): Bundled chart lib with standard React event handlers, no dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/agents-DGWGKRS7.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BhMLiL-f.js AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-CIF9KO_a.js AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-D1gS3bQB.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-CFQZRthi.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-Cv9JkmI-.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-1fpppHI8.js AI (source-diff): Radix UI bundled component chunk. ai
source-diff obfuscated-file:dist/client/assets/avatar-BTrmVIKy.js AI (source-diff): Radix UI bundled component chunk. ai
source-diff net-exec-file:dist/client/assets/chart-AQ18KTyy.js AI (source-diff): Bundled recharts/React chunk; no real net+exec payload, false positive on minified code. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-hb9jXDKm.js AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-Cl8pS3vq.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-By6iC7_M.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CJzFrvTT.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-BxVo2yFR.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-D8cz9rhw.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-CG14BRwH.js AI (source-diff): Bundled React vendor code; event-handler list, no dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/chart-CG14BRwH.js AI (source-diff): Bundled recharts/vendor chunk, standard minified output. ai
source-diff obfuscated-file:dist/client/assets/chart-FVybnDVI.js AI (source-diff): Bundled recharts/React chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-FVybnDVI.js AI (source-diff): React event-handler list in bundled chunk, not a dropper. ai
source-diff obfuscated-file:dist/client/assets/chart-qGX5OGhH.js AI (source-diff): Minified recharts bundle. ai
source-diff net-exec-file:dist/client/assets/chart-qGX5OGhH.js AI (source-diff): React/recharts bundle triggers pattern; no dropper behavior in sample. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-C94NpUEI.js AI (source-diff): Bundled Vite/esbuild frontend chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-O2xYmHiO.js AI (source-diff): Vite-bundled client chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-DyPfMtV-.js AI (source-diff): Vite-bundled client chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/avatar-CV6DueNx.js AI (source-diff): Radix UI wrapper, bundled minified output. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-dWBIY11w.js AI (source-diff): Radix UI wrapper, bundled minified output. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DhHcSPJe.js AI (source-diff): Vite/Rollup bundled client chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-8MAXcTFO.js AI (source-diff): Bundled client chunk from build tool. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-D8xv7ge_.js AI (source-diff): Bundled Radix-based component chunk. ai
source-diff obfuscated-file:dist/client/assets/avatar-BJrEI8Ge.js AI (source-diff): Bundled Radix-based component chunk. ai
source-diff obfuscated-file:dist/client/assets/chart-DYrz9LTc.js AI (source-diff): Bundled recharts/React output, not true obfuscation. ai
source-diff large-new-source-files AI (source-diff): Expected from full client bundle rebuild, not injected code. ai
source-diff net-exec-file:dist/client/assets/chart-DYrz9LTc.js AI (source-diff): False positive: bundled event-handler name list, no real net+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DXZR_qGt.js AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-x67ExPRF.js AI (source-diff): React DOM event constant arrays misidentified as net+exec; no real network/eval combo. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CBK-Qs6u.js AI (source-diff): Vite-bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-Cd7yJ1ON.js AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-BZAY-W0i.js AI (source-diff): Vite-bundled client chunk, not true obfuscation. ai
phantom-deps phantom-dep:kysely-bun-worker AI (phantom-deps): Used via config/ORM wiring, not direct import; common pattern. ai
source-diff obfuscated-file:dist/client/assets/avatar-CWhMuzoF.js AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-BJUWY-WI.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-CCAokYeJ.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
npm-metadata bundled-binaries AI (npm-metadata): Known quickjs WASM sandbox dependency, not an opaque backdoor. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BTlhFSVr.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-CVeQoUS0.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
phantom-deps phantom-dep:nats AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@jitl/quickjs-wasmfile-release-sync AI (phantom-deps): Platform-specific binary package; expected phantom-dep pattern for bundled apps. ai
phantom-deps phantom-dep:@modelcontextprotocol/ext-apps AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:quickjs-emscripten-core AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@electric-sql/pglite AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@clickhouse/client AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:kysely-pglite AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:kysely AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
typosquat typosquat.levenshtein:jest AI (typosquat): @decocms/mesh is a scoped MCP gateway package; name similarity to jest is purely coincidental. ai

Versions (showing 100 of 333)

Version Deps Published
2.156.0 10 / 95
2.155.1 10 / 95
2.155.0 10 / 95
2.153.0 11 / 95
2.152.1 8 / 95
2.152.0 8 / 95
2.151.1 8 / 95
2.151.0 8 / 95
2.150.0 7 / 95
2.149.0 7 / 95
2.148.0 7 / 95
2.147.0 7 / 95
2.146.0 7 / 95
2.145.0 7 / 95
2.144.0 7 / 95
2.143.4 7 / 95
2.143.3 7 / 95
2.143.2 7 / 95
2.143.1 8 / 95
2.143.0 8 / 95
2.142.0 8 / 95
2.141.0 8 / 95
2.140.0 8 / 95
2.139.5 7 / 95
2.139.4 7 / 95
2.139.3 7 / 95
2.139.2 7 / 95
2.139.1 7 / 95
2.139.0 7 / 95
2.138.0 7 / 95
2.137.3 7 / 95
2.137.2 7 / 95
2.137.1 7 / 95
2.137.0 7 / 95
2.136.1 7 / 95
2.136.0 7 / 95
2.135.1 7 / 95
2.135.0 7 / 95
2.134.0 7 / 95
2.133.2 7 / 95
2.133.1 7 / 95
2.133.0 7 / 96
2.132.0 7 / 96
2.131.3 7 / 96
2.131.2 7 / 96
2.131.1 7 / 96
2.131.0 7 / 96
2.130.1 7 / 96
2.130.0 7 / 96
2.129.0 7 / 96
2.128.3 7 / 96
2.128.2 7 / 96
2.128.1 7 / 96
2.128.0 7 / 96
2.127.1 7 / 96
2.127.0 7 / 96
2.126.0 7 / 96
2.125.3 6 / 96
2.125.2 6 / 96
2.125.1 6 / 96
2.125.0 6 / 96
2.124.0 6 / 96
2.123.5 6 / 96
2.123.4 6 / 96
2.123.3 6 / 96
2.123.2 6 / 96
2.123.1 6 / 96
2.123.0 6 / 96
2.122.1 6 / 96
2.122.0 6 / 96
2.121.0 6 / 96
2.120.1 6 / 96
2.120.0 6 / 96
2.119.0 6 / 96
2.118.0 6 / 96
2.117.0 6 / 96
2.116.0 6 / 96
2.115.0 6 / 96
2.114.5 6 / 96
2.114.4 6 / 96
2.114.3 6 / 96
2.114.2 6 / 96
2.114.1 6 / 95
2.114.0 6 / 94
2.113.1 6 / 94
2.113.0 6 / 94
2.112.2 6 / 94
2.112.1 6 / 94
2.112.0 6 / 94
2.111.1 6 / 94
2.111.0 6 / 94
2.110.0 5 / 94
2.109.1 5 / 94
2.109.0 5 / 94
2.108.3 5 / 94
2.108.2 5 / 94
2.108.1 5 / 94
2.108.0 5 / 94
2.107.0 5 / 94
2.106.0 5 / 94
Showing 100 of 333 Next page →

v2.155.1

21 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-yGB2heMj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-BJ8TZ41D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-DJJZZtVq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-SF62e4EI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-FVybnDVI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-FVybnDVI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-CfJ2-S9n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-Cj8DJ1Tt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-DL63WcRT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-DUlD9HhB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-DjhK7eH9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-D8pVuFu_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-CT7EZh6E.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-BiSbr8ff.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-B4yExTx9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-aeGUvSo9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/context-D2hF1RoZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-BX8pcMIY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-Cm2BX8aZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.155.0

21 findings
HIGH New obfuscated file: dist/client/assets/agent-detail-CH7DXB6D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-s8vQsuhF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-4uvZEEFx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-D_GwJ74E.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-Jwerghze.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-Jwerghze.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-DTMpeVSV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-CzYeKxf3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-Coo-60zD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-BrrpLl8S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-ukh1uFNi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-BesVTSVA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-BKj-3sVK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-yqsLq0sT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-D87n3ynC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-uA8MqaDa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/context-3GupwOmI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-DM74wNIS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog--yM2xUAQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-JzMC3sNX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.153.0

21 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-hb9jXDKm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-CM-VcqDb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-4jw0h4Sv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-DSqVRmvZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-AQ18KTyy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-AQ18KTyy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-DXRHnDhE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-u_Mz_vzy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-C5dv9QAh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-DSlYXc2o.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-BXFlxpVt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-YFNQCDzs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-DgTPAhV4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-BGXvR2Zh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-bCZOaMcx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-49X4knDz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-Cb9M9BjO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-DuWSdCnB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-CKiUmV-s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.152.1

20 findings
HIGH New obfuscated file: dist/client/assets/agent-detail-Bt6Azfh9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-BrvdxbUL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-D3IoKbnw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-C5pEejQp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-D59JuXmr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-D59JuXmr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-BibPHeVL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-CskEEZ0C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-DXDI4Pqz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-D8y20kff.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-D1xh30zX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-BwJ9eHmK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-BNyqyXZh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-7T93Wntl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-DN_8mPK4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-C8x6xdCH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-CEpJEOsI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-11Nxq3TT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-CvhXGDVT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.152.0

21 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-D8cz9rhw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-C_DSW8kG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-D-yRc-sh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-iXUY-hHJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-CG14BRwH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-CG14BRwH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-C7OdytyL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-DIYQSdX7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-BPpyZWox.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-CL3jDyD5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-l5pJfiz_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-U_b5p-aM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-Di1XkB5w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-BV7RBs_B.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-C3KCrFj5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-CFJWEoxl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-Czjxuu-U.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-syGnfUPl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-CycgJM5k.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.151.1

20 findings
HIGH New obfuscated file: dist/client/assets/agent-detail-Co4y6a1G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-FIt3Ac6F.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-Zq9orW8e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-9KvRRBX6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-CRmafvjG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-CRmafvjG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-FLtHs3YV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-DhmOdWcq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-DGEXVUbQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-DpSOlF1j.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-BO8BVgsb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-CJXXy5PK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-BlmrYBit.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-Bqw7rc3v.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-0I9cLimB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-CaRr2gjb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-azAQ8dj4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-B7YufxPl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-Dgcx4Bwk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.151.0

21 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-DQANuv6I.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-BOJt_67e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-KpumxplV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-DxvbNnH0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-BV6LQupJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-BV6LQupJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-DaeqT0eQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-B_s3XfJc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-Ds4dVeXn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-C-Llz5o3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-S2X1Y8C4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-CiDPNzME.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-I2Ye1bi5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-5qu4zCHt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-BXfenktA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-BQGnrd4y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-Bfe-2xP9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-BJEpRKVk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-PzQOo_bB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.150.0

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-DidLKXNZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-C--6EV5-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-CK4IO4hn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-DPcF2-P-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.149.0

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-O2xYmHiO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-DyPfMtV-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-dWBIY11w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-CV6DueNx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.148.0

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-DorbgMCC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-BR4l5LqE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-B_VwaOIL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-CugGqtYT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.147.0

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-IIw3ZuFv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-BqWyJ8Lf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-BQq-kgnK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-B7exWPCY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.146.0

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-DhHcSPJe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-8MAXcTFO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-D8xv7ge_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-BJrEI8Ge.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.145.0

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-D1gS3bQB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-DGWGKRS7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-BhMLiL-f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-CIF9KO_a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.144.0

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-CBK-Qs6u.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-BZAY-W0i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-Cd7yJ1ON.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-CWhMuzoF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.143.4

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-Cv9JkmI-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-CFQZRthi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-1fpppHI8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-BTrmVIKy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.143.3

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-CJzFrvTT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-Cl8pS3vq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-By6iC7_M.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-BxVo2yFR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.143.2

6 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-BJUWY-WI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-CVeQoUS0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-BTlhFSVr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-CCAokYeJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.143.1

21 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

HIGH New obfuscated file: dist/client/assets/agent-detail-DXZR_qGt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-CoBEE1b4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-DTGC-5sm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-DO7d4g3_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-x67ExPRF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-x67ExPRF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-Mur41Y8Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-IU63nB1Q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-DMQps0Xz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-CA3-oRhp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-BL8Crm9G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-jsZDQrk4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-a4XyqB7I.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-Cwt8gzIm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-Dk9KXuQE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-C1OjjVmy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-DtOvoqkD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-BnKjupoh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-DkcO9qf7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.143.0

20 findings
HIGH New obfuscated file: dist/client/assets/agent-detail-C94NpUEI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-BSKLOaMu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-DaXpWdw0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-Ci3kAkCl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-qGX5OGhH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-qGX5OGhH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-CxJfsyMO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-DVcCqR3z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-BxbTqYSq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-Bh2VOYGp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-COmJ-B8Q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-B1HOWPFt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-CpLI2s8J.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-C_SdT5ck.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-DeEqc0GM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-Bbw6jN_V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-V-msF1Jz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-DaBc1e0V.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-CROdw5xZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.142.0

20 findings
HIGH New obfuscated file: dist/client/assets/agent-detail-ean34cyZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/agents-avEyjtsq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/alert-dialog-DXvhyacf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/avatar-DGDgNwX-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/chart-DYrz9LTc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/chart-DYrz9LTc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/client/assets/collapsible-Dz6kdDQx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-detail-CBGjxXPP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-display-button-CXc-TgEJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-tab-BlE4CTwD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/collection-table-wrapper-eN4uWzLn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/command-BzF9LDzy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connect-B1CrEofK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connection-detail-B-ICGeJ4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/connections-BuggzhbD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/constants-CRvMLa9p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-organization-dialog-DIZjTiis.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/create-project-dialog-Dut0dyR9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/danger-zone-_BODcOmd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.141.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.140.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.139.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.139.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.139.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.139.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.139.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.139.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.138.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.137.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.137.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.137.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.137.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.136.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.136.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.135.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.135.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.134.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.133.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.133.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.133.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.132.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.131.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.130.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.130.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.129.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.128.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.128.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.128.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.128.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.127.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.127.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.126.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.125.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.125.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.125.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.125.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.124.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.123.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.123.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.123.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.123.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.123.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.123.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.122.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.122.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.121.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.120.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.120.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.119.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.118.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.117.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.116.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.115.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.114.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.114.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.114.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.114.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.114.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.114.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.113.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.113.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.112.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.112.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.112.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.111.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.111.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.110.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.109.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.109.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.108.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.108.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.108.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.108.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.107.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.106.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.