@easbot/utils
Shared utilities library for EASBOT ecosystem
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/chunks/main-K27GCHMT.cjs | AI (source-diff): esbuild-bundled vendor chunk, not genuine obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-GVYBF75T.mjs | AI (source-diff): esbuild-bundled vendor chunk, not genuine obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-LS64TONI.mjs | AI (source-diff): Bundled esbuild library code shipped via tsup, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-JZ7RERNZ.cjs | AI (source-diff): Bundled esbuild library code shipped via tsup, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-3BSIJH3A.cjs | AI (source-diff): Bundled esbuild internals, not obfuscated malicious code. | ai | |
| provenance | missing-githead | AI (provenance): Publish tooling change, not malicious; publisher has strong track record. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-SIKGRMGH.mjs | AI (source-diff): Vendored esbuild bundle inside tsup build output, not obfuscated attacker code. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-VPVKM4OQ.cjs | AI (source-diff): Vendored esbuild bundle inside tsup build output, not obfuscated attacker code. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-5MBAAGCL.cjs | AI (source-diff): esbuild bundled output via tsup, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-NR2RC5BC.mjs | AI (source-diff): esbuild bundled output via tsup, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@hono/standard-validator | AI (phantom-deps): Used via config/plugin wiring, not direct import; low risk for this lib. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-ZMRSNK7G.mjs | AI (source-diff): Vendored esbuild bundle output, not obfuscated attacker code. | ai | |
| source-diff | obfuscated-file:dist/chunks/main-RIJAJS2R.cjs | AI (source-diff): Vendored esbuild bundle output, not obfuscated attacker code. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a well-established, widely-used library with no known malicious history; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Declared in dependencies; likely used indirectly or in config/re-export patterns within this utils library. | ai | |
| phantom-deps | phantom-dep:hono-openapi | AI (phantom-deps): Declared in dependencies; referenced in config files as noted by analyzer — stable false positive for this package. | ai |
Versions (showing 51 of 60)
| Version | Deps | Published |
|---|---|---|
| 0.3.10 | 15 / 7 | |
| 0.3.9 | 14 / 7 | |
| 0.3.8 | 14 / 7 | |
| 0.3.7 | 14 / 7 | |
| 0.3.5 | 15 / 7 | |
| 0.3.4 | 14 / 7 | |
| 0.3.3 | 14 / 7 | |
| 0.3.2 | 14 / 7 | |
| 0.3.0 | 14 / 7 | |
| 0.2.49 | 14 / 7 | |
| 0.2.48 | 14 / 7 | |
| 0.2.47 | 14 / 7 | |
| 0.2.46 | 14 / 7 | |
| 0.2.45 | 14 / 7 | |
| 0.2.44 | 14 / 7 | |
| 0.2.43 | 14 / 7 | |
| 0.2.42 | 14 / 7 | |
| 0.2.41 | 14 / 7 | |
| 0.2.40 | 14 / 7 | |
| 0.2.39 | 14 / 7 | |
| 0.2.38 | 14 / 7 | |
| 0.2.37 | 14 / 7 | |
| 0.2.36 | 14 / 7 | |
| 0.2.35 | 14 / 7 | |
| 0.2.34 | 14 / 7 | |
| 0.2.33 | 14 / 7 | |
| 0.2.32 | 14 / 7 | |
| 0.2.30 | 14 / 7 | |
| 0.2.28 | 14 / 7 | |
| 0.2.27 | 14 / 7 | |
| 0.2.26 | 14 / 7 | |
| 0.2.25 | 14 / 7 | |
| 0.2.24 | 14 / 7 | |
| 0.2.23 | 13 / 7 | |
| 0.2.22 | 13 / 7 | |
| 0.2.21 | 13 / 7 | |
| 0.2.20 | 13 / 7 | |
| 0.2.19 | 13 / 7 | |
| 0.2.18 | 13 / 7 | |
| 0.2.16 | 13 / 7 | |
| 0.2.15 | 13 / 7 | |
| 0.2.14 | 13 / 7 | |
| 0.2.13 | 13 / 7 | |
| 0.2.11 | 13 / 7 | |
| 0.2.10 | 13 / 7 | |
| 0.2.9 | 13 / 7 | |
| 0.2.7 | 13 / 7 | |
| 0.2.6 | 9 / 11 | |
| 0.2.5 | 10 / 11 | |
| 0.2.4 | 10 / 11 | |
| 0.2.3 | 10 / 11 |
v0.3.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.49
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.48
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.47
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.21
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.19
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.16
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.14
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.11
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.9
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.7
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.5
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.4
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.3
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jallenhou.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (esbuild) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.