← Home

@decocms/mesh

100
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

camudogimenes-decocxfirstdoit

Keywords

mcpmodel-context-protocolaigatewayself-hostedmeshtools

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/client/assets/agent-detail-DorbgMCC.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/avatar-CugGqtYT.js AI (source-diff): Radix component bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-B_VwaOIL.js AI (source-diff): Radix component bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-BR4l5LqE.js AI (source-diff): Vite bundle chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-BqWyJ8Lf.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-B7exWPCY.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BQq-kgnK.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-IIw3ZuFv.js AI (source-diff): Vite/Rollup bundled chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-Jwerghze.js AI (source-diff): Bundled Recharts chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-Jwerghze.js AI (source-diff): React synthetic event list, no real network+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CH7DXB6D.js AI (source-diff): Vite-bundled React app chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-D59JuXmr.js AI (source-diff): Bundled recharts/React output, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-D59JuXmr.js AI (source-diff): Standard bundled client JS, no dropper/loader behavior present. ai
source-diff obfuscated-file:dist/client/assets/chart-BV6LQupJ.js AI (source-diff): Bundled Recharts/Vite chunk; minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-BV6LQupJ.js AI (source-diff): React event-handler list in bundled chart lib; no real net+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agents-C--6EV5-.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-DPcF2-P-.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-CK4IO4hn.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DidLKXNZ.js AI (source-diff): Vite bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/chart-CRmafvjG.js AI (source-diff): Bundled recharts/vite output, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-CRmafvjG.js AI (source-diff): Bundled chart lib with standard React event handlers, no dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/agents-DGWGKRS7.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BhMLiL-f.js AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-CIF9KO_a.js AI (source-diff): Vite-bundled Radix UI wrapper, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-D1gS3bQB.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-CFQZRthi.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-Cv9JkmI-.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-1fpppHI8.js AI (source-diff): Radix UI bundled component chunk. ai
source-diff obfuscated-file:dist/client/assets/avatar-BTrmVIKy.js AI (source-diff): Radix UI bundled component chunk. ai
source-diff net-exec-file:dist/client/assets/chart-AQ18KTyy.js AI (source-diff): Bundled recharts/React chunk; no real net+exec payload, false positive on minified code. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-hb9jXDKm.js AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-Cl8pS3vq.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-By6iC7_M.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CJzFrvTT.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-BxVo2yFR.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-D8cz9rhw.js AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-CG14BRwH.js AI (source-diff): Bundled React vendor code; event-handler list, no dropper behavior. ai
source-diff obfuscated-file:dist/client/assets/chart-CG14BRwH.js AI (source-diff): Bundled recharts/vendor chunk, standard minified output. ai
source-diff obfuscated-file:dist/client/assets/chart-FVybnDVI.js AI (source-diff): Bundled recharts/React chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/client/assets/chart-FVybnDVI.js AI (source-diff): React event-handler list in bundled chunk, not a dropper. ai
source-diff obfuscated-file:dist/client/assets/chart-qGX5OGhH.js AI (source-diff): Minified recharts bundle. ai
source-diff net-exec-file:dist/client/assets/chart-qGX5OGhH.js AI (source-diff): React/recharts bundle triggers pattern; no dropper behavior in sample. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-C94NpUEI.js AI (source-diff): Bundled Vite/esbuild frontend chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-O2xYmHiO.js AI (source-diff): Vite-bundled client chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/agents-DyPfMtV-.js AI (source-diff): Vite-bundled client chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/avatar-CV6DueNx.js AI (source-diff): Radix UI wrapper, bundled minified output. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-dWBIY11w.js AI (source-diff): Radix UI wrapper, bundled minified output. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DhHcSPJe.js AI (source-diff): Vite/Rollup bundled client chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-8MAXcTFO.js AI (source-diff): Bundled client chunk from build tool. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-D8xv7ge_.js AI (source-diff): Bundled Radix-based component chunk. ai
source-diff obfuscated-file:dist/client/assets/avatar-BJrEI8Ge.js AI (source-diff): Bundled Radix-based component chunk. ai
source-diff obfuscated-file:dist/client/assets/chart-DYrz9LTc.js AI (source-diff): Bundled recharts/React output, not true obfuscation. ai
source-diff large-new-source-files AI (source-diff): Expected from full client bundle rebuild, not injected code. ai
source-diff net-exec-file:dist/client/assets/chart-DYrz9LTc.js AI (source-diff): False positive: bundled event-handler name list, no real net+exec payload. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-DXZR_qGt.js AI (source-diff): Vite/Rollup bundled client chunk, not true obfuscation. ai
source-diff net-exec-file:dist/client/assets/chart-x67ExPRF.js AI (source-diff): React DOM event constant arrays misidentified as net+exec; no real network/eval combo. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-CBK-Qs6u.js AI (source-diff): Vite-bundled client chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-Cd7yJ1ON.js AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-BZAY-W0i.js AI (source-diff): Vite-bundled client chunk, not true obfuscation. ai
phantom-deps phantom-dep:kysely-bun-worker AI (phantom-deps): Used via config/ORM wiring, not direct import; common pattern. ai
source-diff obfuscated-file:dist/client/assets/avatar-CWhMuzoF.js AI (source-diff): Vite-bundled Radix component chunk, not obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agent-detail-BJUWY-WI.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/avatar-CCAokYeJ.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
npm-metadata bundled-binaries AI (npm-metadata): Known quickjs WASM sandbox dependency, not an opaque backdoor. ai
source-diff obfuscated-file:dist/client/assets/alert-dialog-BTlhFSVr.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/agents-CVeQoUS0.js AI (source-diff): Vite-bundled client JS, not true obfuscation. ai
phantom-deps phantom-dep:nats AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@jitl/quickjs-wasmfile-release-sync AI (phantom-deps): Platform-specific binary package; expected phantom-dep pattern for bundled apps. ai
phantom-deps phantom-dep:@modelcontextprotocol/ext-apps AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:quickjs-emscripten-core AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@electric-sql/pglite AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@opentelemetry/core AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:@clickhouse/client AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:kysely-pglite AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
phantom-deps phantom-dep:kysely AI (phantom-deps): Bundled server app; deps referenced in config/bundled output, not direct imports. ai
typosquat typosquat.levenshtein:jest AI (typosquat): @decocms/mesh is a scoped MCP gateway package; name similarity to jest is purely coincidental. ai

Versions (showing 100 of 333)

Version Deps Published
2.105.0 5 / 94
2.104.0 5 / 94
2.103.0 5 / 94
2.102.0 5 / 94
2.101.0 5 / 94
2.100.0 5 / 94
2.99.0 5 / 94
2.98.0 5 / 94
2.97.3 5 / 94
2.97.2 5 / 94
2.97.1 5 / 94
2.97.0 5 / 94
2.96.3 5 / 93
2.96.2 5 / 93
2.96.1 5 / 93
2.96.0 5 / 93
2.95.0 4 / 91
2.94.0 4 / 91
2.93.0 4 / 91
2.92.0 4 / 91
2.91.0 4 / 91
2.90.0 4 / 91
2.89.0 4 / 90
2.88.0 4 / 90
2.87.0 4 / 90
2.86.0 4 / 90
2.85.0 4 / 90
2.84.0 4 / 90
2.83.0 4 / 90
2.82.2 4 / 90
2.82.1 4 / 90
2.82.0 4 / 90
2.81.2 4 / 90
2.81.1 4 / 90
2.81.0 4 / 90
2.80.1 4 / 90
2.80.0 4 / 90
2.79.1 4 / 90
2.79.0 4 / 90
2.78.1 4 / 90
2.78.0 4 / 90
2.77.0 4 / 90
2.76.0 4 / 90
2.75.0 4 / 90
2.74.0 4 / 90
2.73.0 4 / 90
2.72.1 4 / 90
2.72.0 4 / 90
2.71.1 4 / 90
2.71.0 4 / 90
2.70.0 4 / 91
2.69.0 4 / 91
2.68.0 4 / 91
2.67.0 4 / 91
2.66.0 4 / 91
2.65.1 4 / 91
2.65.0 4 / 91
2.64.4 4 / 91
2.64.3 4 / 91
2.64.2 4 / 91
2.64.1 4 / 91
2.64.0 4 / 91
2.63.1 4 / 91
2.63.0 4 / 91
2.62.0 4 / 91
2.61.0 4 / 91
2.60.0 4 / 91
2.59.7 4 / 91
2.59.6 4 / 91
2.59.5 4 / 91
2.59.4 4 / 91
2.59.3 4 / 91
2.59.2 4 / 91
2.59.1 4 / 91
2.59.0 4 / 91
2.58.3 4 / 91
2.58.2 4 / 91
2.58.1 4 / 91
2.58.0 4 / 93
2.57.1 4 / 93
2.57.0 4 / 93
2.56.1 4 / 93
2.56.0 4 / 93
2.55.0 4 / 93
2.54.0 4 / 93
2.53.0 4 / 93
2.52.0 4 / 93
2.51.5 4 / 93
2.51.4 4 / 92
2.51.3 4 / 86
2.51.2 4 / 86
2.51.1 4 / 86
2.51.0 4 / 86
2.50.0 4 / 87
2.49.0 4 / 87
2.48.0 4 / 87
2.47.0 4 / 87
2.46.0 4 / 87
2.45.0 4 / 87
2.44.3 4 / 87
Showing 100 of 333 Next page →

v2.105.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.104.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.103.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.102.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.101.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.100.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.99.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.98.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.97.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.97.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.97.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.97.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.96.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.96.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.96.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.96.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.95.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.94.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.93.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.92.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.91.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.90.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.89.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.88.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.87.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.86.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.85.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.84.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.83.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.82.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.82.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.82.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.81.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.81.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.81.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.80.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.80.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.79.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.79.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.78.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.78.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.77.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.76.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.75.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.74.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.73.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.72.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.72.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.71.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.71.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.70.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.69.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.68.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.67.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.66.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.65.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.65.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.64.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.64.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.64.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.64.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.64.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.63.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.63.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.62.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.61.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.60.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.7

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.6

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.59.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.58.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.58.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.58.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.58.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.57.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.57.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.56.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.56.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.55.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.54.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.53.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.52.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.51.5

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.51.4

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.51.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.51.2

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.51.1

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.51.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.50.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.49.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.48.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.47.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.46.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.45.0

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.44.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/server/node_modules/@jitl/quickjs-wasmfile-release-sync/dist/emscripten-module.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.