← Home

@decocms/mesh

100
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

camudogimenes-decocxfirstdoit

Keywords

mcpmodel-context-protocolaigatewayself-hostedmeshtools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/client/assets/agent-detail-DorbgMCC.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/avatar-CugGqtYT.js AI (source-diff): Radix component bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-B_VwaOIL.js AI (source-diff): Radix component bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-BR4l5LqE.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-BqWyJ8Lf.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-B7exWPCY.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BQq-kgnK.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-IIw3ZuFv.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-Jwerghze.js AI (source-diff): Bundled Recharts chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-Jwerghze.js AI (source-diff): React synthetic event list, no real network+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CH7DXB6D.js AI (source-diff): Vite-bundled React app chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-D59JuXmr.js AI (source-diff): Bundled recharts/React output, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-D59JuXmr.js AI (source-diff): Standard bundled client JS, no dropper/loader behavior present. ai
source-diff obfuscated-file:dist/client/assets/chart-BV6LQupJ.js AI (source-diff): Bundled Recharts/Vite chunk; minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-BV6LQupJ.js AI (source-diff): React event-handler list in bundled chart lib; no real net+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agents-C--6EV5-.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-DPcF2-P-.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-CK4IO4hn.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DidLKXNZ.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-CRmafvjG.js AI (source-diff): Bundled recharts/vite output, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-CRmafvjG.js AI (source-diff): Bundled chart lib with standard React event handlers, no dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/agents-DGWGKRS7.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BhMLiL-f.js AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-CIF9KO_a.js AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-D1gS3bQB.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-CFQZRthi.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-Cv9JkmI-.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-1fpppHI8.js AI (source-diff): Radix UI bundled component chunk. ai
source-diff obfuscated-file:dist/client/assets/avatar-BTrmVIKy.js AI (source-diff): Radix UI bundled component chunk. ai
source-diff net-exec-file:dist/client/assets/chart-AQ18KTyy.js AI (source-diff): Bundled recharts/React chunk; no real net+exec payload, false positive on minified code. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-hb9jXDKm.js AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-Cl8pS3vq.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-By6iC7_M.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CJzFrvTT.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-BxVo2yFR.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-D8cz9rhw.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-CG14BRwH.js AI (source-diff): Bundled React vendor code; event-handler list, no dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/chart-CG14BRwH.js AI (source-diff): Bundled recharts/vendor chunk, standard minified output. ai
source-diff obfuscated-file:dist/client/assets/chart-FVybnDVI.js AI (source-diff): Bundled recharts/React chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-FVybnDVI.js AI (source-diff): React event-handler list in bundled chunk, not a dropper. ai
source-diff obfuscated-file:dist/client/assets/chart-qGX5OGhH.js AI (source-diff): Minified recharts bundle. ai
source-diff net-exec-file:dist/client/assets/chart-qGX5OGhH.js AI (source-diff): React/recharts bundle triggers pattern; no dropper behavior in sample. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-C94NpUEI.js AI (source-diff): Bundled Vite/esbuild frontend chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-O2xYmHiO.js AI (source-diff): Vite-bundled client chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-DyPfMtV-.js AI (source-diff): Vite-bundled client chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/avatar-CV6DueNx.js AI (source-diff): Radix UI wrapper, bundled minified output. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-dWBIY11w.js AI (source-diff): Radix UI wrapper, bundled minified output. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DhHcSPJe.js AI (source-diff): Vite/Rollup bundled client chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-8MAXcTFO.js AI (source-diff): Bundled client chunk from build tool. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-D8xv7ge_.js AI (source-diff): Bundled Radix-based component chunk. ai
source-diff obfuscated-file:dist/client/assets/avatar-BJrEI8Ge.js AI (source-diff): Bundled Radix-based component chunk. ai
source-diff obfuscated-file:dist/client/assets/chart-DYrz9LTc.js AI (source-diff): Bundled recharts/React output, not true obfuscation. ai
source-diff large-new-source-files AI (source-diff): Expected from full client bundle rebuild, not injected code. ai
source-diff net-exec-file:dist/client/assets/chart-DYrz9LTc.js AI (source-diff): False positive: bundled event-handler name list, no real net+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DXZR_qGt.js AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-x67ExPRF.js AI (source-diff): React DOM event constant arrays misidentified as net+exec; no real network/eval combo. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CBK-Qs6u.js AI (source-diff): Vite-bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-Cd7yJ1ON.js AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-BZAY-W0i.js AI (source-diff): Vite-bundled client chunk, not true obfuscation. ai
phantom-deps phantom-dep:kysely-bun-worker AI (phantom-deps): Used via config/ORM wiring, not direct import; common pattern. ai
source-diff obfuscated-file:dist/client/assets/avatar-CWhMuzoF.js AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-BJUWY-WI.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-CCAokYeJ.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
npm-metadata bundled-binaries AI (npm-metadata): Known quickjs WASM sandbox dependency, not an opaque backdoor. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BTlhFSVr.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-CVeQoUS0.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
phantom-deps phantom-dep:nats AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@jitl/quickjs-wasmfile-release-sync AI (phantom-deps): Platform-specific binary package; expected phantom-dep pattern for bundled apps. ai
phantom-deps phantom-dep:@modelcontextprotocol/ext-apps AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:quickjs-emscripten-core AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@electric-sql/pglite AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@clickhouse/client AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:kysely-pglite AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:kysely AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
typosquat typosquat.levenshtein:jest AI (typosquat): @decocms/mesh is a scoped MCP gateway package; name similarity to jest is purely coincidental. ai

Versions (showing 100 of 333)

Version Deps Published
2.44.2 4 / 87
2.44.1 4 / 87
2.44.0 4 / 87
2.43.2 4 / 87
2.43.1 4 / 87
2.43.0 4 / 87
2.42.0 4 / 87
2.41.0 4 / 87
2.40.2 4 / 87
2.40.1 4 / 87
2.40.0 4 / 87
2.39.1 4 / 87
2.39.0 4 / 87
2.38.6 4 / 86
2.38.5 4 / 86
2.38.4 4 / 86
2.38.3 4 / 86
2.38.2 4 / 86
2.38.1 4 / 86
2.38.0 4 / 86
2.37.0 4 / 86
2.36.0 4 / 86
2.35.0 4 / 86
2.34.0 4 / 86
2.33.0 4 / 86
2.32.0 4 / 86
2.31.1 4 / 86
2.31.0 4 / 86
2.30.0 4 / 86
2.29.3 4 / 86
2.29.2 4 / 86
2.29.1 4 / 86
2.29.0 4 / 86
2.28.1 4 / 86
2.28.0 4 / 86
2.27.1 4 / 87
2.27.0 4 / 87
2.26.0 4 / 87
2.25.0 4 / 87
2.24.0 4 / 87
2.23.0 4 / 87
2.22.2 6 / 75
2.22.1 6 / 75
2.22.0 6 / 75
2.21.0 6 / 75
2.20.5 6 / 75
2.20.4 6 / 75
2.20.3 6 / 75
2.20.2 6 / 75
2.20.1 6 / 75
2.20.0 6 / 75
2.19.0 6 / 75
2.18.0 6 / 75
2.17.2 6 / 75
2.17.1 6 / 75
2.17.0 6 / 75
2.16.0 6 / 75
2.15.1 6 / 75
2.15.0 6 / 75
2.14.1 6 / 75
2.14.0 6 / 75
2.13.0 6 / 75
2.12.1 6 / 75
2.12.0 6 / 75
2.11.0 6 / 75
2.10.0 6 / 75
2.9.0 6 / 75
2.8.2 6 / 75
2.8.1 6 / 75
2.8.0 6 / 75
2.7.0 6 / 75
2.6.0 6 / 75
2.5.0 6 / 75
2.4.3 6 / 75
2.4.2 6 / 75
2.4.1 6 / 75
2.4.0 6 / 75
2.3.2 6 / 75
2.3.1 6 / 75
2.3.0 6 / 75
2.2.0 6 / 75
2.1.2 6 / 75
2.1.1 6 / 75
2.1.0 6 / 75
2.0.0 6 / 75
1.13.4 6 / 75
1.13.3 6 / 75
1.13.2 6 / 75
1.13.1 6 / 75
1.13.0 6 / 75
1.12.0 6 / 75
1.11.1 6 / 75
1.11.0 6 / 75
1.10.0 6 / 76
1.9.0 6 / 76
1.8.0 6 / 78
1.7.0 6 / 78
1.6.0 6 / 78
1.5.0 6 / 78
1.4.4 6 / 78
Showing 100 of 333 Next page →

v2.44.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.44.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.44.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.43.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.43.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.43.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.42.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.41.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.40.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.40.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.40.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.39.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.39.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.38.6

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.38.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.38.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.38.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.38.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.38.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.38.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.37.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.36.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.35.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.34.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.33.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.32.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.31.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.31.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.30.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.29.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.29.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.29.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.29.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.28.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.28.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.27.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.27.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.26.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.25.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.24.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.23.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.22.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.22.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.22.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.21.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.20.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.20.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.20.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.20.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.20.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.20.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.19.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.18.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.17.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.17.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.16.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.15.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.15.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.14.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.14.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.13.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.12.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.