@dxos/network-manager
Network Manager
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/lib/browser/chunk-XYSYUN63.mjs | AI (source-diff): Bundled build output of package's own networking source, not a dropper. | ai | |
| source-diff | net-exec-file:dist/lib/node/chunk-4YAYC7WN.cjs | AI (source-diff): Bundled build output of package's own networking source, not a dropper. | ai | |
| source-diff | net-exec-file:dist/lib/node/chunk-FYVBSNF4.cjs | AI (source-diff): Bundled build output of network-manager lib; network+dynamic code is core functionality, not a dropper. | ai | |
| source-diff | net-exec-file:dist/lib/browser/chunk-SKTAEJ7M.mjs | AI (source-diff): Same bundled chunk, browser build; no malicious behavior present. | ai | |
| source-diff | net-exec-file:dist/lib/node/chunk-IQBYIEAR.cjs | AI (source-diff): Bundled transport/connection code; network+dynamic-require is expected in WebRTC library bundle. | ai | |
| source-diff | net-exec-file:dist/lib/browser/chunk-ZQ4OU7JZ.mjs | AI (source-diff): Bundled browser transport chunk; require-shim polyfill pattern, not exec malware. | ai | |
| phantom-deps | phantom-dep:@dxos/edge-client | AI (phantom-deps): Same-org scoped dep, false positive pattern. | ai | |
| source-diff | net-exec-file:dist/lib/browser/chunk-ZT4NXID2.mjs | AI (source-diff): Bundled browser build output, same source module, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/lib/node/chunk-DZJ3BJOK.cjs | AI (source-diff): Bundled build output of network-manager's own connection code, not a dropper. | ai | |
| phantom-deps | phantom-dep:@dxos/config | AI (phantom-deps): First-party same-org dep, config re-export pattern. | ai | |
| phantom-deps | phantom-dep:@dxos/crypto | AI (phantom-deps): First-party same-org dep. | ai | |
| phantom-deps | phantom-dep:@dxos/credentials | AI (phantom-deps): First-party same-org dep. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Org-level maintainer cleanup consistent with CI/CD migration; no malicious indicators present. | ai | |
| provenance | publisher-changed | AI (provenance): DXOS migrated CI publishing from dxos-bot to GitHub Actions; SLSA attestation confirms legitimate CI/CD origin. | ai | |
| phantom-deps | phantom-dep:nanomessage-rpc | AI (phantom-deps): nanomessage-rpc is a declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:tiny-invariant | AI (phantom-deps): tiny-invariant is a declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:isomorphic-ws | AI (phantom-deps): isomorphic-ws is a declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a declared runtime dep used via isomorphic-ws abstraction; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:p-defer | AI (phantom-deps): p-defer is a declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:xor-distance | AI (phantom-deps): xor-distance is a declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:stream | AI (phantom-deps): stream is a declared runtime dep; phantom-dep heuristic false positive for this monorepo package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 0.10.0 | 15 / 4 | |
| 0.9.0 | 15 / 4 | |
| 0.8.3 | 22 / 7 | |
| 0.8.2 | 22 / 7 | |
| 0.8.1 | 22 / 7 | |
| 0.8.0 | 22 / 7 | |
| 0.7.4 | 22 / 7 | |
| 0.7.3 | 22 / 7 | |
| 0.7.2 | 22 / 7 | |
| 0.7.1 | 22 / 7 | |
| 0.7.0 | 22 / 7 | |
| 0.6.13 | 27 / 8 | |
| 0.6.12 | 27 / 8 | |
| 0.6.11 | 27 / 8 | |
| 0.6.10 | 27 / 8 | |
| 0.6.9 | 27 / 8 | |
| 0.6.8 | 27 / 8 | |
| 0.6.7 | 26 / 8 | |
| 0.6.6 | 26 / 8 | |
| 0.6.5 | 25 / 7 | |
| 0.6.4 | 25 / 7 | |
| 0.6.3 | 25 / 7 | |
| 0.6.2 | 25 / 7 | |
| 0.6.1 | 25 / 7 | |
| 0.6.0 | 25 / 7 | |
| 0.5.8 | 25 / 7 | |
| 0.5.7 | 25 / 7 | |
| 0.5.6 | 25 / 7 | |
| 0.5.5 | 25 / 7 | |
| 0.5.4 | 25 / 7 | |
| 0.5.3 | 25 / 7 | |
| 0.5.2 | 25 / 7 |
v0.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.13
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.12
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.11
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.10
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.9
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.8
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.7
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.6
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.