@decocms/mesh
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/assets/agent-detail-DorbgMCC.js | AI (source-diff): Vite bundle chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-CugGqtYT.js | AI (source-diff): Radix component bundle, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-B_VwaOIL.js | AI (source-diff): Radix component bundle, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-BR4l5LqE.js | AI (source-diff): Vite bundle chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-BqWyJ8Lf.js | AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-B7exWPCY.js | AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-BQq-kgnK.js | AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-IIw3ZuFv.js | AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-Jwerghze.js | AI (source-diff): Bundled Recharts chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-Jwerghze.js | AI (source-diff): React synthetic event list, no real network+exec payload. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-CH7DXB6D.js | AI (source-diff): Vite-bundled React app chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-D59JuXmr.js | AI (source-diff): Bundled recharts/React output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-D59JuXmr.js | AI (source-diff): Standard bundled client JS, no dropper/loader behavior present. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-BV6LQupJ.js | AI (source-diff): Bundled Recharts/Vite chunk; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-BV6LQupJ.js | AI (source-diff): React event-handler list in bundled chart lib; no real net+exec payload. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-C--6EV5-.js | AI (source-diff): Vite bundled client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-DPcF2-P-.js | AI (source-diff): Vite bundled client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-CK4IO4hn.js | AI (source-diff): Vite bundled client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-DidLKXNZ.js | AI (source-diff): Vite bundled client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-CRmafvjG.js | AI (source-diff): Bundled recharts/vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-CRmafvjG.js | AI (source-diff): Bundled chart lib with standard React event handlers, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-DGWGKRS7.js | AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-BhMLiL-f.js | AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-CIF9KO_a.js | AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-D1gS3bQB.js | AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-CFQZRthi.js | AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-Cv9JkmI-.js | AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-1fpppHI8.js | AI (source-diff): Radix UI bundled component chunk. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-BTrmVIKy.js | AI (source-diff): Radix UI bundled component chunk. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-AQ18KTyy.js | AI (source-diff): Bundled recharts/React chunk; no real net+exec payload, false positive on minified code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-hb9jXDKm.js | AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-Cl8pS3vq.js | AI (source-diff): Vite/esbuild bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-By6iC7_M.js | AI (source-diff): Vite/esbuild bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-CJzFrvTT.js | AI (source-diff): Vite/esbuild bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-BxVo2yFR.js | AI (source-diff): Vite/esbuild bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-D8cz9rhw.js | AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-CG14BRwH.js | AI (source-diff): Bundled React vendor code; event-handler list, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-CG14BRwH.js | AI (source-diff): Bundled recharts/vendor chunk, standard minified output. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-FVybnDVI.js | AI (source-diff): Bundled recharts/React chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-FVybnDVI.js | AI (source-diff): React event-handler list in bundled chunk, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-qGX5OGhH.js | AI (source-diff): Minified recharts bundle. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-qGX5OGhH.js | AI (source-diff): React/recharts bundle triggers pattern; no dropper behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-C94NpUEI.js | AI (source-diff): Bundled Vite/esbuild frontend chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-O2xYmHiO.js | AI (source-diff): Vite-bundled client chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-DyPfMtV-.js | AI (source-diff): Vite-bundled client chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-CV6DueNx.js | AI (source-diff): Radix UI wrapper, bundled minified output. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-dWBIY11w.js | AI (source-diff): Radix UI wrapper, bundled minified output. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-DhHcSPJe.js | AI (source-diff): Vite/Rollup bundled client chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-8MAXcTFO.js | AI (source-diff): Bundled client chunk from build tool. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-D8xv7ge_.js | AI (source-diff): Bundled Radix-based component chunk. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-BJrEI8Ge.js | AI (source-diff): Bundled Radix-based component chunk. | ai | |
| source-diff | obfuscated-file:dist/client/assets/chart-DYrz9LTc.js | AI (source-diff): Bundled recharts/React output, not true obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected from full client bundle rebuild, not injected code. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-DYrz9LTc.js | AI (source-diff): False positive: bundled event-handler name list, no real net+exec payload. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-DXZR_qGt.js | AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/assets/chart-x67ExPRF.js | AI (source-diff): React DOM event constant arrays misidentified as net+exec; no real network/eval combo. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-CBK-Qs6u.js | AI (source-diff): Vite-bundled client chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-Cd7yJ1ON.js | AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-BZAY-W0i.js | AI (source-diff): Vite-bundled client chunk, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:kysely-bun-worker | AI (phantom-deps): Used via config/ORM wiring, not direct import; common pattern. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-CWhMuzoF.js | AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agent-detail-BJUWY-WI.js | AI (source-diff): Vite-bundled client JS, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/avatar-CCAokYeJ.js | AI (source-diff): Vite-bundled client JS, not true obfuscation. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Known quickjs WASM sandbox dependency, not an opaque backdoor. | ai | |
| source-diff | obfuscated-file:dist/client/assets/alert-dialog-BTlhFSVr.js | AI (source-diff): Vite-bundled client JS, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/agents-CVeQoUS0.js | AI (source-diff): Vite-bundled client JS, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:nats | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:@jitl/quickjs-wasmfile-release-sync | AI (phantom-deps): Platform-specific binary package; expected phantom-dep pattern for bundled apps. | ai | |
| phantom-deps | phantom-dep:@modelcontextprotocol/ext-apps | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:quickjs-emscripten-core | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:@electric-sql/pglite | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/core | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:@clickhouse/client | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:kysely-pglite | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| phantom-deps | phantom-dep:kysely | AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. | ai | |
| typosquat | typosquat.levenshtein:jest | AI (typosquat): @decocms/mesh is a scoped MCP gateway package; name similarity to jest is purely coincidental. | ai |
Versions (showing 100 of 333)
| Version | Deps | Published |
|---|---|---|
| 2.105.0 | 5 / 94 | |
| 2.104.0 | 5 / 94 | |
| 2.103.0 | 5 / 94 | |
| 2.102.0 | 5 / 94 | |
| 2.101.0 | 5 / 94 | |
| 2.100.0 | 5 / 94 | |
| 2.99.0 | 5 / 94 | |
| 2.98.0 | 5 / 94 | |
| 2.97.3 | 5 / 94 | |
| 2.97.2 | 5 / 94 | |
| 2.97.1 | 5 / 94 | |
| 2.97.0 | 5 / 94 | |
| 2.96.3 | 5 / 93 | |
| 2.96.2 | 5 / 93 | |
| 2.96.1 | 5 / 93 | |
| 2.96.0 | 5 / 93 | |
| 2.95.0 | 4 / 91 | |
| 2.94.0 | 4 / 91 | |
| 2.93.0 | 4 / 91 | |
| 2.92.0 | 4 / 91 | |
| 2.91.0 | 4 / 91 | |
| 2.90.0 | 4 / 91 | |
| 2.89.0 | 4 / 90 | |
| 2.88.0 | 4 / 90 | |
| 2.87.0 | 4 / 90 | |
| 2.86.0 | 4 / 90 | |
| 2.85.0 | 4 / 90 | |
| 2.84.0 | 4 / 90 | |
| 2.83.0 | 4 / 90 | |
| 2.82.2 | 4 / 90 | |
| 2.82.1 | 4 / 90 | |
| 2.82.0 | 4 / 90 | |
| 2.81.2 | 4 / 90 | |
| 2.81.1 | 4 / 90 | |
| 2.81.0 | 4 / 90 | |
| 2.80.1 | 4 / 90 | |
| 2.80.0 | 4 / 90 | |
| 2.79.1 | 4 / 90 | |
| 2.79.0 | 4 / 90 | |
| 2.78.1 | 4 / 90 | |
| 2.78.0 | 4 / 90 | |
| 2.77.0 | 4 / 90 | |
| 2.76.0 | 4 / 90 | |
| 2.75.0 | 4 / 90 | |
| 2.74.0 | 4 / 90 | |
| 2.73.0 | 4 / 90 | |
| 2.72.1 | 4 / 90 | |
| 2.72.0 | 4 / 90 | |
| 2.71.1 | 4 / 90 | |
| 2.71.0 | 4 / 90 | |
| 2.70.0 | 4 / 91 | |
| 2.69.0 | 4 / 91 | |
| 2.68.0 | 4 / 91 | |
| 2.67.0 | 4 / 91 | |
| 2.66.0 | 4 / 91 | |
| 2.65.1 | 4 / 91 | |
| 2.65.0 | 4 / 91 | |
| 2.64.4 | 4 / 91 | |
| 2.64.3 | 4 / 91 | |
| 2.64.2 | 4 / 91 | |
| 2.64.1 | 4 / 91 | |
| 2.64.0 | 4 / 91 | |
| 2.63.1 | 4 / 91 | |
| 2.63.0 | 4 / 91 | |
| 2.62.0 | 4 / 91 | |
| 2.61.0 | 4 / 91 | |
| 2.60.0 | 4 / 91 | |
| 2.59.7 | 4 / 91 | |
| 2.59.6 | 4 / 91 | |
| 2.59.5 | 4 / 91 | |
| 2.59.4 | 4 / 91 | |
| 2.59.3 | 4 / 91 | |
| 2.59.2 | 4 / 91 | |
| 2.59.1 | 4 / 91 | |
| 2.59.0 | 4 / 91 | |
| 2.58.3 | 4 / 91 | |
| 2.58.2 | 4 / 91 | |
| 2.58.1 | 4 / 91 | |
| 2.58.0 | 4 / 93 | |
| 2.57.1 | 4 / 93 | |
| 2.57.0 | 4 / 93 | |
| 2.56.1 | 4 / 93 | |
| 2.56.0 | 4 / 93 | |
| 2.55.0 | 4 / 93 | |
| 2.54.0 | 4 / 93 | |
| 2.53.0 | 4 / 93 | |
| 2.52.0 | 4 / 93 | |
| 2.51.5 | 4 / 93 | |
| 2.51.4 | 4 / 92 | |
| 2.51.3 | 4 / 86 | |
| 2.51.2 | 4 / 86 | |
| 2.51.1 | 4 / 86 | |
| 2.51.0 | 4 / 86 | |
| 2.50.0 | 4 / 87 | |
| 2.49.0 | 4 / 87 | |
| 2.48.0 | 4 / 87 | |
| 2.47.0 | 4 / 87 | |
| 2.46.0 | 4 / 87 | |
| 2.45.0 | 4 / 87 | |
| 2.44.3 | 4 / 87 |
v2.105.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.104.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.103.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.102.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.101.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.100.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.99.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.98.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.97.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.97.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.97.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.97.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.96.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.96.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.96.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.96.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.95.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.94.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.93.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.92.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.91.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.90.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.89.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.88.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.87.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.86.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.85.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.84.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.83.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.82.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.82.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.82.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.81.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.81.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.81.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.80.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.80.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.79.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.79.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.78.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.78.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.77.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.76.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.75.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.74.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.73.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.72.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.72.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.71.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.71.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.70.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.69.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.68.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.67.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.66.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.65.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.65.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.64.4
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.64.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.64.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.64.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.64.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.63.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.63.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.62.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.61.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.60.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.7
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.6
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.5
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.4
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.59.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.58.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.58.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.58.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.58.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.57.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.57.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.56.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.56.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.55.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.54.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.53.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.52.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.51.5
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.51.4
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.51.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.51.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.51.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.51.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.50.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.49.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.48.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.47.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.46.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.45.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.44.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.