← Home

@dxos/network-manager

Network Manager

32
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mykola-vrmchkdxos-botgcolottisebikap-gm2richburdonegorgripasovmarik_drzad-pyivladmeschzarconontolwittjosiah

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/lib/browser/chunk-XYSYUN63.mjs AI (source-diff): Bundled build output of package's own networking source, not a dropper. ai
source-diff net-exec-file:dist/lib/node/chunk-4YAYC7WN.cjs AI (source-diff): Bundled build output of package's own networking source, not a dropper. ai
source-diff net-exec-file:dist/lib/node/chunk-FYVBSNF4.cjs AI (source-diff): Bundled build output of network-manager lib; network+dynamic code is core functionality, not a dropper. ai
source-diff net-exec-file:dist/lib/browser/chunk-SKTAEJ7M.mjs AI (source-diff): Same bundled chunk, browser build; no malicious behavior present. ai
source-diff net-exec-file:dist/lib/node/chunk-IQBYIEAR.cjs AI (source-diff): Bundled transport/connection code; network+dynamic-require is expected in WebRTC library bundle. ai
source-diff net-exec-file:dist/lib/browser/chunk-ZQ4OU7JZ.mjs AI (source-diff): Bundled browser transport chunk; require-shim polyfill pattern, not exec malware. ai
phantom-deps phantom-dep:@dxos/edge-client AI (phantom-deps): Same-org scoped dep, false positive pattern. ai
source-diff net-exec-file:dist/lib/browser/chunk-ZT4NXID2.mjs AI (source-diff): Bundled browser build output, same source module, not obfuscated. ai
source-diff net-exec-file:dist/lib/node/chunk-DZJ3BJOK.cjs AI (source-diff): Bundled build output of network-manager's own connection code, not a dropper. ai
phantom-deps phantom-dep:@dxos/config AI (phantom-deps): First-party same-org dep, config re-export pattern. ai
phantom-deps phantom-dep:@dxos/crypto AI (phantom-deps): First-party same-org dep. ai
phantom-deps phantom-dep:@dxos/credentials AI (phantom-deps): First-party same-org dep. ai
maintainer-change maintainer-removed AI (maintainer-change): Org-level maintainer cleanup consistent with CI/CD migration; no malicious indicators present. ai
provenance publisher-changed AI (provenance): DXOS migrated CI publishing from dxos-bot to GitHub Actions; SLSA attestation confirms legitimate CI/CD origin. ai
phantom-deps phantom-dep:nanomessage-rpc AI (phantom-deps): nanomessage-rpc is a declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:tiny-invariant AI (phantom-deps): tiny-invariant is a declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:isomorphic-ws AI (phantom-deps): isomorphic-ws is a declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:ws AI (phantom-deps): ws is a declared runtime dep used via isomorphic-ws abstraction; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:p-defer AI (phantom-deps): p-defer is a declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:xor-distance AI (phantom-deps): xor-distance is a declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:stream AI (phantom-deps): stream is a declared runtime dep; phantom-dep heuristic false positive for this monorepo package. ai

Versions (showing 32 of 32)

Version Deps Published
0.10.0 15 / 4
0.9.0 15 / 4
0.8.3 22 / 7
0.8.2 22 / 7
0.8.1 22 / 7
0.8.0 22 / 7
0.7.4 22 / 7
0.7.3 22 / 7
0.7.2 22 / 7
0.7.1 22 / 7
0.7.0 22 / 7
0.6.13 27 / 8
0.6.12 27 / 8
0.6.11 27 / 8
0.6.10 27 / 8
0.6.9 27 / 8
0.6.8 27 / 8
0.6.7 26 / 8
0.6.6 26 / 8
0.6.5 25 / 7
0.6.4 25 / 7
0.6.3 25 / 7
0.6.2 25 / 7
0.6.1 25 / 7
0.6.0 25 / 7
0.5.8 25 / 7
0.5.7 25 / 7
0.5.6 25 / 7
0.5.5 25 / 7
0.5.4 25 / 7
0.5.3 25 / 7
0.5.2 25 / 7

v0.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.13

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-4YAYC7WN.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-XYSYUN63.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.12

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-4YAYC7WN.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-XYSYUN63.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.11

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-4YAYC7WN.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-XYSYUN63.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.10

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-FYVBSNF4.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-SKTAEJ7M.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.9

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-IQBYIEAR.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-ZQ4OU7JZ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.8

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-IQBYIEAR.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-ZQ4OU7JZ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.7

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-DZJ3BJOK.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-ZT4NXID2.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

3 findings
HIGH New file with network + code execution: dist/lib/node/chunk-DZJ3BJOK.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/lib/browser/chunk-ZT4NXID2.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.