@diplodoc/client
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:build/client/vendor-f4e28d6d333a34f2.js | AI (source-diff): Vendor bundle; webpack banner confirms build artifact. | ai | |
| source-diff | net-exec-file:build/client/vendor-42f1b39e64aa43b8.js | AI (source-diff): Vendor bundle chunk with normal fetch/exec patterns from bundled libs. | ai | |
| source-diff | obfuscated-file:build/client/app-f94acb83de1926b6.js | AI (source-diff): Webpack-bundled app entry, matches package purpose. | ai | |
| source-diff | net-exec-file:build/client/app-f94acb83de1926b6.js | AI (source-diff): Bundled React app with fetch/analytics, no malicious destination. | ai | |
| source-diff | net-exec-file:build/client/vendor-1d9ceefec10e55cd.js | AI (source-diff): Vendor bundle incl. analytics/consent code, no exfil destination. | ai | |
| source-diff | net-exec-file:build/client/vendor-86d5823e387e8e15.js | AI (source-diff): Vendor bundle with GTM/consent code, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/app-98aba2614cd68782.js | AI (source-diff): Webpack bundle output for app UI code. | ai | |
| source-diff | net-exec-file:build/client/app-98aba2614cd68782.js | AI (source-diff): Bundled analytics/router code, no hostile network+exec behavior found. | ai | |
| source-diff | net-exec-file:build/client/vendor-bfbd11529400b045.js | AI (source-diff): Vendor bundle incl. GTM/consent libs, standard client capability. | ai | |
| source-diff | obfuscated-file:build/client/app-28b410dd0e289e80.js | AI (source-diff): Webpack-bundled React app code. | ai | |
| source-diff | net-exec-file:build/client/app-28b410dd0e289e80.js | AI (source-diff): Client bundle fetch/exec patterns from React/router code, not malware. | ai | |
| source-diff | obfuscated-file:build/client/search-6fbdaaffc89fe254.js | AI (source-diff): Webpack-bundled search chunk. | ai | |
| source-diff | net-exec-file:build/client/app-c87e24eeaae1b0dc.js | AI (source-diff): Bundled UI code with normal fetch/react usage, no malicious behavior. | ai | |
| source-diff | obfuscated-file:build/client/976-40cbc1d2518eb8ea.js | AI (source-diff): Minified rspack bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/app-c87e24eeaae1b0dc.js | AI (source-diff): Minified React app bundle, standard webpack banner visible. | ai | |
| source-diff | obfuscated-file:build/client/react-869ecca253e3f1ec.js | AI (source-diff): Minified React vendor chunk, bundler banner confirmed. | ai | |
| source-diff | obfuscated-file:build/client/search-b6246854f4238deb.js | AI (source-diff): Minified search bundle, standard build output. | ai | |
| source-diff | net-exec-file:build/client/vendor-38a8fe9ee299ccc3.js | AI (source-diff): Bundled vendor chunk (GTM/analytics consent code), not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/search-c50badbbac7436bd.js | AI (source-diff): Webpack-bundled search UI code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-e69d71e99c7f296b.js | AI (source-diff): Vendor chunk bundling llhttp WASM; standard dependency bundling, no malicious destination. | ai | |
| source-diff | net-exec-file:build/client/app-e70f636e61ffb694.js | AI (source-diff): Bundled frontend app code; network+exec pattern is normal SPA bundling, not dropper behavior. | ai | |
| source-diff | obfuscated-file:build/client/app-e70f636e61ffb694.js | AI (source-diff): Webpack-bundled React app output, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:build/client/444-504c3782d2b3e0db.js | AI (source-diff): Webpack-bundled worker code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-5856ec8889123518.js | AI (source-diff): Vendor bundle with analytics/consent libs; bundler banner confirms build output. | ai | |
| source-diff | obfuscated-file:build/client/search-df24dd819915a228.js | AI (source-diff): Webpack-bundled search UI code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:build/client/app-fe0aacfa5aced06d.js | AI (source-diff): Webpack-bundled React app code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-d408a01b2db583a5.js | AI (source-diff): Bundled vendor chunk (webpack banner); no concrete malicious network/exec behavior shown. | ai | |
| source-diff | obfuscated-file:build/client/app-0639070057a9f030.js | AI (source-diff): Webpack-bundled client app output, consistent with rspack build pipeline. | ai | |
| source-diff | net-exec-file:build/client/app-f05ccf13e622345f.js | AI (source-diff): Bundled client code, no fetched/executed payload. | ai | |
| source-diff | obfuscated-file:build/client/app-f05ccf13e622345f.js | AI (source-diff): Bundled app entry chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-6cbce46fb98effb2.js | AI (source-diff): Vendor bundle includes cookie/http libs, no malicious net-exec. | ai | |
| source-diff | net-exec-file:build/client/vendor-524b1f13dac0da4a.js | AI (source-diff): Vendor bundle (cookie/http libs), no destination-specific malicious behavior. | ai | |
| source-diff | net-exec-file:build/client/vendor-df2661ee19f97723.js | AI (source-diff): Vendor bundle; network+exec pattern is standard library code, not malicious. | ai | |
| source-diff | net-exec-file:build/client/vendor-19f237a87f1f5fe7.js | AI (source-diff): Vendor bundle with cookie/react libs; bundler banner confirms build output. | ai | |
| source-diff | net-exec-file:build/client/vendor-c530f888d6027e43.js | AI (source-diff): Vendor bundle (webpack banner present); standard third-party deps bundled. | ai | |
| source-diff | net-exec-file:build/client/vendor-03ddcd4b4ab9d816.js | AI (source-diff): Bundled vendor chunk (cookie/llhttp wasm libs), bundler banner confirms build output. | ai | |
| source-diff | net-exec-file:build/client/app-a183d21ccd5083cc.js | AI (source-diff): Bundled frontend code; network calls are standard fetch/cookie utilities. | ai | |
| source-diff | obfuscated-file:build/client/app-a183d21ccd5083cc.js | AI (source-diff): Webpack-bundled React app output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/search-136c6c533ebeaf71.js | AI (source-diff): Webpack-bundled search UI chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-4e00ede7781ad7e6.js | AI (source-diff): Bundled vendor chunk with webpack banner; standard cookie/http libs. | ai | |
| source-diff | net-exec-file:build/client/app-3ff8bc0b40bc2914.js | AI (source-diff): Bundled frontend code with normal fetch/network usage, no dropper behavior. | ai | |
| source-diff | net-exec-file:build/client/vendor-0069313875a03738.js | AI (source-diff): Bundled vendor chunk (react, cookie lib), no malicious network+exec pattern. | ai | |
| source-diff | obfuscated-file:build/client/search-70ce3e84166c4c4f.js | AI (source-diff): Webpack-bundled search UI code, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/app-3ff8bc0b40bc2914.js | AI (source-diff): Webpack-bundled React app code, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/vendor-d233676225962abc.js | AI (source-diff): Vendor bundle with cookie/http libs, benign. | ai | |
| source-diff | obfuscated-file:build/client/search-28dc709305a22ff6.js | AI (source-diff): Webpack-bundled search module, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-0c960903f3f3fa3b.js | AI (source-diff): Bundled vendor chunk (cookie lib etc), not a dropper. | ai | |
| source-diff | net-exec-file:build/client/app-b32c34bc8d075f06.js | AI (source-diff): Bundled front-end code; cookie/network utils are normal for a docs client. | ai | |
| source-diff | obfuscated-file:build/client/app-b32c34bc8d075f06.js | AI (source-diff): Webpack-bundled minified app code, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/vendor-a93e4c6bfe86b5d7.js | AI (source-diff): Standard bundled cookie/vendor lib, not malicious. | ai | |
| source-diff | obfuscated-file:build/client/search-9e32646a6885333c.js | AI (source-diff): Webpack-bundled search chunk, not obfuscation. | ai | |
| source-diff | net-exec-file:build/client/app-8d806cd5f6e4032c.js | AI (source-diff): Bundled vendor React/router code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:build/client/app-8d806cd5f6e4032c.js | AI (source-diff): Webpack-bundled app chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/search-b0696ebe1fdb98c8.js | AI (source-diff): Bundled webpack build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/app-9d9702ba413d6de9.js | AI (source-diff): Bundled webpack build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/app-9d9702ba413d6de9.js | AI (source-diff): Normal client bundle with fetch/eval patterns from React/router libs, no malicious target. | ai | |
| source-diff | net-exec-file:build/client/vendor-f4ebaaa236d57a0e.js | AI (source-diff): Vendor bundle includes cookie/llhttp libs; no malicious behavior. | ai | |
| source-diff | obfuscated-file:build/client/app-c3e8973ab1d89cc8.js | AI (source-diff): Bundled rspack/webpack client output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/app-c3e8973ab1d89cc8.js | AI (source-diff): Standard bundle containing fetch/eval patterns from React/router libs, no malicious target. | ai | |
| source-diff | obfuscated-file:build/client/search-286bba91cb85430c.js | AI (source-diff): Bundled build output, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-fefbbd2336b585a3.js | AI (source-diff): Vendor bundle (cookie lib etc.), benign dual-use APIs. | ai | |
| source-diff | obfuscated-file:build/client/189-852cf8d3aaafb556.js | AI (source-diff): Webpack-bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/client/vendor-3968fc4a2edae571.js | AI (source-diff): Vendor bundle includes wasm-based llhttp parser, standard dep code. | ai | |
| source-diff | net-exec-file:build/client/app-a6d0ead9fe08075c.js | AI (source-diff): Bundled client app code; no exfil/dropper behavior found. | ai | |
| source-diff | obfuscated-file:build/client/search-d216d580378fde39.js | AI (source-diff): Webpack-bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/app-a6d0ead9fe08075c.js | AI (source-diff): Webpack-bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/client/app-5a8d013a5d4da23e.js | AI (source-diff): Webpack-bundled app chunk; minified build output. | ai | |
| source-diff | obfuscated-file:build/client/189-20d50a965a07f044.js | AI (source-diff): Webpack-bundled client chunk; minified, not obfuscated malware. | ai | |
| source-diff | net-exec-file:build/client/app-5a8d013a5d4da23e.js | AI (source-diff): Standard bundled fetch/eval patterns from framework code, not a dropper. | ai | |
| source-diff | obfuscated-file:build/client/search-280db1181ad0d7c9.js | AI (source-diff): Webpack-bundled search chunk; minified, not obfuscated. | ai | |
| source-diff | net-exec-file:build/client/vendor-cf4cf360b8f04e5b.js | AI (source-diff): Vendor bundle containing cookie/wasm libs; benign bundled deps. | ai | |
| source-diff | obfuscated-file:build/client/app-f86067fc0d7ffb1e.js | AI (source-diff): Standard webpack/rspack minified React bundle; consistent with this package's documented build process. | ai | |
| source-diff | net-exec-file:build/client/vendor-a301303071ab49a2.js | AI (source-diff): Vendor bundle with cookie/HTTP parsing libs; normal frontend dependency bundling, no malicious indicators. | ai | |
| source-diff | obfuscated-file:build/client/search-6389fee2cb71e580.js | AI (source-diff): Standard webpack-minified search bundle; same build artifact pattern as other client files. | ai | |
| source-diff | net-exec-file:build/client/app-f86067fc0d7ffb1e.js | AI (source-diff): Network calls and dynamic module loading are normal in a React SPA bundle; no malicious payload evident. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package with empty description field; not indicative of malice. | ai | |
| source-diff | net-exec-file:build/client/vendor-d624c3b1cfc0a16a.js | AI (source-diff): Vendor bundle with cookie/WASM parsing; normal for a bundled frontend package. | ai | |
| source-diff | obfuscated-file:build/client/search-d6011929331ae16f.js | AI (source-diff): Standard webpack-minified search bundle; consistent with this package's documented build output. | ai | |
| source-diff | net-exec-file:build/client/app-06661d5c25bbe373.js | AI (source-diff): Network calls and dynamic requires in webpack bundle are normal for a React frontend client package. | ai | |
| source-diff | obfuscated-file:build/client/app-06661d5c25bbe373.js | AI (source-diff): Standard webpack-minified React app bundle; consistent with this package's documented build output. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Dormancy explained by CI/CD pipeline migration; package has 140 versions and active ecosystem use. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA attestation; legitimate pipeline change for diplodoc-platform org. | ai | |
| source-diff | obfuscated-file:build/client/app-2f5a2932377400c3.js | AI (source-diff): Minified webpack bundle; expected output for this frontend client package. | ai | |
| source-diff | encoded-string-file:build/server/vendor.js | AI (source-diff): Base64 string is the llhttp WASM binary, a well-known HTTP parser used by Node.js ecosystem. | ai | |
| source-diff | net-exec-file:build/client/app-2f5a2932377400c3.js | AI (source-diff): Network calls and dynamic requires are standard in bundled React/webpack frontend apps. | ai | |
| source-diff | obfuscated-file:build/client/search-f5b7fe09164e8fb4.js | AI (source-diff): Minified webpack bundle; expected output for this frontend client package. | ai | |
| source-diff | net-exec-file:build/client/vendor-02b4192ee805dad6.js | AI (source-diff): Vendor bundle with cookie/HTTP parsing code; standard bundled dependency output. | ai |
Versions (showing 51 of 51)
| Version | Deps | Published |
|---|---|---|
| 5.9.0 | 0 / 32 | |
| 5.8.1 | 0 / 32 | |
| 5.8.0 | 0 / 32 | |
| 5.7.14 | 0 / 34 | |
| 5.7.13 | 0 / 34 | |
| 5.7.12 | 0 / 34 | |
| 5.7.11 | 0 / 34 | |
| 5.7.10 | 0 / 34 | |
| 5.7.9 | 0 / 34 | |
| 5.7.8 | 0 / 34 | |
| 5.7.7 | 0 / 34 | |
| 5.7.6 | 0 / 34 | |
| 5.7.5 | 0 / 34 | |
| 5.7.4 | 0 / 34 | |
| 5.7.3 | 0 / 34 | |
| 5.7.2 | 0 / 34 | |
| 5.7.1 | 0 / 34 | |
| 5.7.0 | 0 / 34 | |
| 5.6.1 | 0 / 34 | |
| 5.6.0 | 0 / 34 | |
| 5.5.4 | 0 / 34 | |
| 5.5.3 | 0 / 34 | |
| 5.5.2 | 0 / 34 | |
| 5.5.1 | 0 / 34 | |
| 5.5.0 | 0 / 34 | |
| 5.4.1 | 0 / 34 | |
| 5.4.0 | 0 / 34 | |
| 5.3.1 | 0 / 34 | |
| 5.3.0 | 0 / 34 | |
| 5.2.17 | 0 / 34 | |
| 5.2.15 | 0 / 34 | |
| 5.2.14 | 0 / 34 | |
| 5.2.13 | 0 / 34 | |
| 5.2.12 | 0 / 34 | |
| 5.2.10 | 0 / 34 | |
| 5.2.9 | 0 / 34 | |
| 5.2.8 | 0 / 34 | |
| 5.2.7 | 0 / 34 | |
| 5.2.6 | 0 / 34 | |
| 5.2.5 | 0 / 34 | |
| 5.2.4 | 0 / 34 | |
| 5.2.3 | 0 / 34 | |
| 5.2.2 | 0 / 36 | |
| 5.2.1 | 0 / 36 | |
| 5.2.0 | 0 / 36 | |
| 5.1.1 | 0 / 36 | |
| 5.1.0 | 0 / 36 | |
| 5.0.0 | 0 / 36 | |
| 4.2.0 | 0 / 36 | |
| 4.1.4 | 0 / 36 | |
| 4.1.2 | 0 / 36 |
v5.9.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.8.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.5.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.4.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.4.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.3.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.12
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.10
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.9
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.8
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.7
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.6
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.5
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.4
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.3
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.2
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.2.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (robot-dataui-npm) on 2025-11-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v4.1.4
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (robot-dataui-npm) on 2025-11-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v4.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.