← Home

@diplodoc/client

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

rndnmrobot-dataui-npmalexey_w1003y3martyanov-avvseshmakhnatkindiplodoc-botreazy015goldsergseparatrix

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:build/client/vendor-f4e28d6d333a34f2.js AI (source-diff): Vendor bundle; webpack banner confirms build artifact. ai
source-diff net-exec-file:build/client/vendor-42f1b39e64aa43b8.js AI (source-diff): Vendor bundle chunk with normal fetch/exec patterns from bundled libs. ai
source-diff obfuscated-file:build/client/app-f94acb83de1926b6.js AI (source-diff): Webpack-bundled app entry, matches package purpose. ai
source-diff net-exec-file:build/client/app-f94acb83de1926b6.js AI (source-diff): Bundled React app with fetch/analytics, no malicious destination. ai
source-diff net-exec-file:build/client/vendor-1d9ceefec10e55cd.js AI (source-diff): Vendor bundle incl. analytics/consent code, no exfil destination. ai
source-diff net-exec-file:build/client/vendor-86d5823e387e8e15.js AI (source-diff): Vendor bundle with GTM/consent code, not a dropper. ai
source-diff obfuscated-file:build/client/app-98aba2614cd68782.js AI (source-diff): Webpack bundle output for app UI code. ai
source-diff net-exec-file:build/client/app-98aba2614cd68782.js AI (source-diff): Bundled analytics/router code, no hostile network+exec behavior found. ai
source-diff net-exec-file:build/client/vendor-bfbd11529400b045.js AI (source-diff): Vendor bundle incl. GTM/consent libs, standard client capability. ai
source-diff obfuscated-file:build/client/app-28b410dd0e289e80.js AI (source-diff): Webpack-bundled React app code. ai
source-diff net-exec-file:build/client/app-28b410dd0e289e80.js AI (source-diff): Client bundle fetch/exec patterns from React/router code, not malware. ai
source-diff obfuscated-file:build/client/search-6fbdaaffc89fe254.js AI (source-diff): Webpack-bundled search chunk. ai
source-diff net-exec-file:build/client/app-c87e24eeaae1b0dc.js AI (source-diff): Bundled UI code with normal fetch/react usage, no malicious behavior. ai
source-diff obfuscated-file:build/client/976-40cbc1d2518eb8ea.js AI (source-diff): Minified rspack bundle output, not true obfuscation. ai
source-diff obfuscated-file:build/client/app-c87e24eeaae1b0dc.js AI (source-diff): Minified React app bundle, standard webpack banner visible. ai
source-diff obfuscated-file:build/client/react-869ecca253e3f1ec.js AI (source-diff): Minified React vendor chunk, bundler banner confirmed. ai
source-diff obfuscated-file:build/client/search-b6246854f4238deb.js AI (source-diff): Minified search bundle, standard build output. ai
source-diff net-exec-file:build/client/vendor-38a8fe9ee299ccc3.js AI (source-diff): Bundled vendor chunk (GTM/analytics consent code), not a dropper. ai
source-diff obfuscated-file:build/client/search-c50badbbac7436bd.js AI (source-diff): Webpack-bundled search UI code, minified not obfuscated. ai
source-diff net-exec-file:build/client/vendor-e69d71e99c7f296b.js AI (source-diff): Vendor chunk bundling llhttp WASM; standard dependency bundling, no malicious destination. ai
source-diff net-exec-file:build/client/app-e70f636e61ffb694.js AI (source-diff): Bundled frontend app code; network+exec pattern is normal SPA bundling, not dropper behavior. ai
source-diff obfuscated-file:build/client/app-e70f636e61ffb694.js AI (source-diff): Webpack-bundled React app output, minified not obfuscated. ai
source-diff obfuscated-file:build/client/444-504c3782d2b3e0db.js AI (source-diff): Webpack-bundled worker code, minified not obfuscated. ai
source-diff net-exec-file:build/client/vendor-5856ec8889123518.js AI (source-diff): Vendor bundle with analytics/consent libs; bundler banner confirms build output. ai
source-diff obfuscated-file:build/client/search-df24dd819915a228.js AI (source-diff): Webpack-bundled search UI code, minified not obfuscated. ai
source-diff obfuscated-file:build/client/app-fe0aacfa5aced06d.js AI (source-diff): Webpack-bundled React app code, minified not obfuscated. ai
source-diff net-exec-file:build/client/vendor-d408a01b2db583a5.js AI (source-diff): Bundled vendor chunk (webpack banner); no concrete malicious network/exec behavior shown. ai
source-diff obfuscated-file:build/client/app-0639070057a9f030.js AI (source-diff): Webpack-bundled client app output, consistent with rspack build pipeline. ai
source-diff net-exec-file:build/client/app-f05ccf13e622345f.js AI (source-diff): Bundled client code, no fetched/executed payload. ai
source-diff obfuscated-file:build/client/app-f05ccf13e622345f.js AI (source-diff): Bundled app entry chunk, minified not obfuscated. ai
source-diff net-exec-file:build/client/vendor-6cbce46fb98effb2.js AI (source-diff): Vendor bundle includes cookie/http libs, no malicious net-exec. ai
source-diff net-exec-file:build/client/vendor-524b1f13dac0da4a.js AI (source-diff): Vendor bundle (cookie/http libs), no destination-specific malicious behavior. ai
source-diff net-exec-file:build/client/vendor-df2661ee19f97723.js AI (source-diff): Vendor bundle; network+exec pattern is standard library code, not malicious. ai
source-diff net-exec-file:build/client/vendor-19f237a87f1f5fe7.js AI (source-diff): Vendor bundle with cookie/react libs; bundler banner confirms build output. ai
source-diff net-exec-file:build/client/vendor-c530f888d6027e43.js AI (source-diff): Vendor bundle (webpack banner present); standard third-party deps bundled. ai
source-diff net-exec-file:build/client/vendor-03ddcd4b4ab9d816.js AI (source-diff): Bundled vendor chunk (cookie/llhttp wasm libs), bundler banner confirms build output. ai
source-diff net-exec-file:build/client/app-a183d21ccd5083cc.js AI (source-diff): Bundled frontend code; network calls are standard fetch/cookie utilities. ai
source-diff obfuscated-file:build/client/app-a183d21ccd5083cc.js AI (source-diff): Webpack-bundled React app output, not true obfuscation. ai
source-diff obfuscated-file:build/client/search-136c6c533ebeaf71.js AI (source-diff): Webpack-bundled search UI chunk, minified not obfuscated. ai
source-diff net-exec-file:build/client/vendor-4e00ede7781ad7e6.js AI (source-diff): Bundled vendor chunk with webpack banner; standard cookie/http libs. ai
source-diff net-exec-file:build/client/app-3ff8bc0b40bc2914.js AI (source-diff): Bundled frontend code with normal fetch/network usage, no dropper behavior. ai
source-diff net-exec-file:build/client/vendor-0069313875a03738.js AI (source-diff): Bundled vendor chunk (react, cookie lib), no malicious network+exec pattern. ai
source-diff obfuscated-file:build/client/search-70ce3e84166c4c4f.js AI (source-diff): Webpack-bundled search UI code, not obfuscation. ai
source-diff obfuscated-file:build/client/app-3ff8bc0b40bc2914.js AI (source-diff): Webpack-bundled React app code, not true obfuscation. ai
source-diff net-exec-file:build/client/vendor-d233676225962abc.js AI (source-diff): Vendor bundle with cookie/http libs, benign. ai
source-diff obfuscated-file:build/client/search-28dc709305a22ff6.js AI (source-diff): Webpack-bundled search module, minified not obfuscated. ai
source-diff net-exec-file:build/client/vendor-0c960903f3f3fa3b.js AI (source-diff): Bundled vendor chunk (cookie lib etc), not a dropper. ai
source-diff net-exec-file:build/client/app-b32c34bc8d075f06.js AI (source-diff): Bundled front-end code; cookie/network utils are normal for a docs client. ai
source-diff obfuscated-file:build/client/app-b32c34bc8d075f06.js AI (source-diff): Webpack-bundled minified app code, not true obfuscation. ai
source-diff net-exec-file:build/client/vendor-a93e4c6bfe86b5d7.js AI (source-diff): Standard bundled cookie/vendor lib, not malicious. ai
source-diff obfuscated-file:build/client/search-9e32646a6885333c.js AI (source-diff): Webpack-bundled search chunk, not obfuscation. ai
source-diff net-exec-file:build/client/app-8d806cd5f6e4032c.js AI (source-diff): Bundled vendor React/router code, no dropper behavior. ai
source-diff obfuscated-file:build/client/app-8d806cd5f6e4032c.js AI (source-diff): Webpack-bundled app chunk, not obfuscation. ai
source-diff obfuscated-file:build/client/search-b0696ebe1fdb98c8.js AI (source-diff): Bundled webpack build output, not true obfuscation. ai
source-diff obfuscated-file:build/client/app-9d9702ba413d6de9.js AI (source-diff): Bundled webpack build output, not true obfuscation. ai
source-diff net-exec-file:build/client/app-9d9702ba413d6de9.js AI (source-diff): Normal client bundle with fetch/eval patterns from React/router libs, no malicious target. ai
source-diff net-exec-file:build/client/vendor-f4ebaaa236d57a0e.js AI (source-diff): Vendor bundle includes cookie/llhttp libs; no malicious behavior. ai
source-diff obfuscated-file:build/client/app-c3e8973ab1d89cc8.js AI (source-diff): Bundled rspack/webpack client output, not true obfuscation. ai
source-diff net-exec-file:build/client/app-c3e8973ab1d89cc8.js AI (source-diff): Standard bundle containing fetch/eval patterns from React/router libs, no malicious target. ai
source-diff obfuscated-file:build/client/search-286bba91cb85430c.js AI (source-diff): Bundled build output, minified not obfuscated. ai
source-diff net-exec-file:build/client/vendor-fefbbd2336b585a3.js AI (source-diff): Vendor bundle (cookie lib etc.), benign dual-use APIs. ai
source-diff obfuscated-file:build/client/189-852cf8d3aaafb556.js AI (source-diff): Webpack-bundled build output, not true obfuscation. ai
source-diff net-exec-file:build/client/vendor-3968fc4a2edae571.js AI (source-diff): Vendor bundle includes wasm-based llhttp parser, standard dep code. ai
source-diff net-exec-file:build/client/app-a6d0ead9fe08075c.js AI (source-diff): Bundled client app code; no exfil/dropper behavior found. ai
source-diff obfuscated-file:build/client/search-d216d580378fde39.js AI (source-diff): Webpack-bundled build output, not true obfuscation. ai
source-diff obfuscated-file:build/client/app-a6d0ead9fe08075c.js AI (source-diff): Webpack-bundled build output, not true obfuscation. ai
source-diff obfuscated-file:build/client/app-5a8d013a5d4da23e.js AI (source-diff): Webpack-bundled app chunk; minified build output. ai
source-diff obfuscated-file:build/client/189-20d50a965a07f044.js AI (source-diff): Webpack-bundled client chunk; minified, not obfuscated malware. ai
source-diff net-exec-file:build/client/app-5a8d013a5d4da23e.js AI (source-diff): Standard bundled fetch/eval patterns from framework code, not a dropper. ai
source-diff obfuscated-file:build/client/search-280db1181ad0d7c9.js AI (source-diff): Webpack-bundled search chunk; minified, not obfuscated. ai
source-diff net-exec-file:build/client/vendor-cf4cf360b8f04e5b.js AI (source-diff): Vendor bundle containing cookie/wasm libs; benign bundled deps. ai
source-diff obfuscated-file:build/client/app-f86067fc0d7ffb1e.js AI (source-diff): Standard webpack/rspack minified React bundle; consistent with this package's documented build process. ai
source-diff net-exec-file:build/client/vendor-a301303071ab49a2.js AI (source-diff): Vendor bundle with cookie/HTTP parsing libs; normal frontend dependency bundling, no malicious indicators. ai
source-diff obfuscated-file:build/client/search-6389fee2cb71e580.js AI (source-diff): Standard webpack-minified search bundle; same build artifact pattern as other client files. ai
source-diff net-exec-file:build/client/app-f86067fc0d7ffb1e.js AI (source-diff): Network calls and dynamic module loading are normal in a React SPA bundle; no malicious payload evident. ai
npm-metadata no-description AI (npm-metadata): Established package with empty description field; not indicative of malice. ai
source-diff net-exec-file:build/client/vendor-d624c3b1cfc0a16a.js AI (source-diff): Vendor bundle with cookie/WASM parsing; normal for a bundled frontend package. ai
source-diff obfuscated-file:build/client/search-d6011929331ae16f.js AI (source-diff): Standard webpack-minified search bundle; consistent with this package's documented build output. ai
source-diff net-exec-file:build/client/app-06661d5c25bbe373.js AI (source-diff): Network calls and dynamic requires in webpack bundle are normal for a React frontend client package. ai
source-diff obfuscated-file:build/client/app-06661d5c25bbe373.js AI (source-diff): Standard webpack-minified React app bundle; consistent with this package's documented build output. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by CI/CD pipeline migration; package has 140 versions and active ecosystem use. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA attestation; legitimate pipeline change for diplodoc-platform org. ai
source-diff obfuscated-file:build/client/app-2f5a2932377400c3.js AI (source-diff): Minified webpack bundle; expected output for this frontend client package. ai
source-diff encoded-string-file:build/server/vendor.js AI (source-diff): Base64 string is the llhttp WASM binary, a well-known HTTP parser used by Node.js ecosystem. ai
source-diff net-exec-file:build/client/app-2f5a2932377400c3.js AI (source-diff): Network calls and dynamic requires are standard in bundled React/webpack frontend apps. ai
source-diff obfuscated-file:build/client/search-f5b7fe09164e8fb4.js AI (source-diff): Minified webpack bundle; expected output for this frontend client package. ai
source-diff net-exec-file:build/client/vendor-02b4192ee805dad6.js AI (source-diff): Vendor bundle with cookie/HTTP parsing code; standard bundled dependency output. ai

Versions (showing 51 of 51)

Version Deps Published
5.9.0 0 / 32
5.8.1 0 / 32
5.8.0 0 / 32
5.7.14 0 / 34
5.7.13 0 / 34
5.7.12 0 / 34
5.7.11 0 / 34
5.7.10 0 / 34
5.7.9 0 / 34
5.7.8 0 / 34
5.7.7 0 / 34
5.7.6 0 / 34
5.7.5 0 / 34
5.7.4 0 / 34
5.7.3 0 / 34
5.7.2 0 / 34
5.7.1 0 / 34
5.7.0 0 / 34
5.6.1 0 / 34
5.6.0 0 / 34
5.5.4 0 / 34
5.5.3 0 / 34
5.5.2 0 / 34
5.5.1 0 / 34
5.5.0 0 / 34
5.4.1 0 / 34
5.4.0 0 / 34
5.3.1 0 / 34
5.3.0 0 / 34
5.2.17 0 / 34
5.2.15 0 / 34
5.2.14 0 / 34
5.2.13 0 / 34
5.2.12 0 / 34
5.2.10 0 / 34
5.2.9 0 / 34
5.2.8 0 / 34
5.2.7 0 / 34
5.2.6 0 / 34
5.2.5 0 / 34
5.2.4 0 / 34
5.2.3 0 / 34
5.2.2 0 / 36
5.2.1 0 / 36
5.2.0 0 / 36
5.1.1 0 / 36
5.1.0 0 / 36
5.0.0 0 / 36
4.2.0 0 / 36
4.1.4 0 / 36
4.1.2 0 / 36

v5.9.0

6 findings
HIGH New obfuscated file: build/client/189-20d50a965a07f044.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/app-5a8d013a5d4da23e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-5a8d013a5d4da23e.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-280db1181ad0d7c9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-cf4cf360b8f04e5b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.1

6 findings
HIGH New obfuscated file: build/client/189-852cf8d3aaafb556.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/app-a6d0ead9fe08075c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-a6d0ead9fe08075c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-d216d580378fde39.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-3968fc4a2edae571.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.8.0

6 findings
HIGH New obfuscated file: build/client/189-852cf8d3aaafb556.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/app-a6d0ead9fe08075c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-a6d0ead9fe08075c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-d216d580378fde39.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-3968fc4a2edae571.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.5.3

5 findings
HIGH New obfuscated file: build/client/app-a183d21ccd5083cc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-a183d21ccd5083cc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-136c6c533ebeaf71.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-19f237a87f1f5fe7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.5.2

5 findings
HIGH New obfuscated file: build/client/app-a183d21ccd5083cc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-a183d21ccd5083cc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-136c6c533ebeaf71.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-03ddcd4b4ab9d816.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.5.1

5 findings
HIGH New obfuscated file: build/client/app-a183d21ccd5083cc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-a183d21ccd5083cc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-136c6c533ebeaf71.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-c530f888d6027e43.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.5.0

5 findings
HIGH New obfuscated file: build/client/app-a183d21ccd5083cc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-a183d21ccd5083cc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-136c6c533ebeaf71.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-4e00ede7781ad7e6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.1

5 findings
HIGH New obfuscated file: build/client/app-b32c34bc8d075f06.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-b32c34bc8d075f06.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-28dc709305a22ff6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-0c960903f3f3fa3b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.4.0

5 findings
HIGH New obfuscated file: build/client/app-b32c34bc8d075f06.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-b32c34bc8d075f06.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-28dc709305a22ff6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-0c960903f3f3fa3b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.1

5 findings
HIGH New obfuscated file: build/client/app-3ff8bc0b40bc2914.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-3ff8bc0b40bc2914.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-70ce3e84166c4c4f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-0069313875a03738.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.0

5 findings
HIGH New obfuscated file: build/client/app-3ff8bc0b40bc2914.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-3ff8bc0b40bc2914.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-70ce3e84166c4c4f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-0069313875a03738.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.12

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-98aba2614cd68782.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-98aba2614cd68782.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-6fbdaaffc89fe254.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-1d9ceefec10e55cd.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.10

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-98aba2614cd68782.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-98aba2614cd68782.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-6fbdaaffc89fe254.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-86d5823e387e8e15.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.9

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-98aba2614cd68782.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-98aba2614cd68782.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-6fbdaaffc89fe254.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-86d5823e387e8e15.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.8

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-28b410dd0e289e80.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-28b410dd0e289e80.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-6fbdaaffc89fe254.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-bfbd11529400b045.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.7

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-28b410dd0e289e80.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-28b410dd0e289e80.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-6fbdaaffc89fe254.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-f4e28d6d333a34f2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.6

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-b6246854f4238deb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-f4e28d6d333a34f2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.5

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-b6246854f4238deb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-38a8fe9ee299ccc3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.4

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-b6246854f4238deb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-38a8fe9ee299ccc3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.3

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-b6246854f4238deb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-38a8fe9ee299ccc3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.2

7 findings
HIGH New obfuscated file: build/client/976-40cbc1d2518eb8ea.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-c87e24eeaae1b0dc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/react-869ecca253e3f1ec.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/client/search-b6246854f4238deb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-42f1b39e64aa43b8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.1

6 findings
HIGH New obfuscated file: build/client/444-504c3782d2b3e0db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/client/app-e70f636e61ffb694.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-e70f636e61ffb694.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-c50badbbac7436bd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-e69d71e99c7f296b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.0

6 findings
HIGH New obfuscated file: build/client/444-504c3782d2b3e0db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/client/app-e70f636e61ffb694.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-e70f636e61ffb694.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-c50badbbac7436bd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-e69d71e99c7f296b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.1

6 findings
HIGH New obfuscated file: build/client/444-504c3782d2b3e0db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/client/app-f94acb83de1926b6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-f94acb83de1926b6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-df24dd819915a228.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-e69d71e99c7f296b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.0

6 findings
HIGH New obfuscated file: build/client/444-504c3782d2b3e0db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/client/app-f94acb83de1926b6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/app-f94acb83de1926b6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/client/search-df24dd819915a228.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-5856ec8889123518.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

5 findings
HIGH New obfuscated file: build/client/444-504c3782d2b3e0db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/client/app-fe0aacfa5aced06d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/search-df24dd819915a228.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-5856ec8889123518.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.0

4 findings
HIGH New obfuscated file: build/client/app-0639070057a9f030.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/vendor-d408a01b2db583a5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: robot-dataui-npm → GitHub Actions (on 2025-11-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (robot-dataui-npm) on 2025-11-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.1.4

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: robot-dataui-npm → GitHub Actions (on 2025-11-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (robot-dataui-npm) on 2025-11-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v4.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.