@ecan-bi/pivot-table
### 项目开发指南 ``` // 下载项目依赖(node_modules) yarn install --registry=https://registry.npm.taobao.org
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/index-a109dbd3.mjs | AI (source-diff): axios import in bundled UI library code, no exfil target observed. | ai | |
| source-diff | obfuscated-file:dist/index-a109dbd3.mjs | AI (source-diff): Vite/Rollup bundle output (banner + vue/echarts imports), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-a1cc897c.mjs | AI (source-diff): Vite/Rollup bundle output for a Vue component library, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-a1cc897c.mjs | AI (source-diff): Bundled axios/echarts library code, no dropper behavior observed. | ai | |
| source-diff | net-exec-file:dist/index-50bba2e6.mjs | AI (source-diff): Bundled UI library code (axios/echarts/ant-design-vue), no evidence of dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-50bba2e6.mjs | AI (source-diff): Vite/Rollup bundle output with accompanying sourcemap; not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-02780d26.mjs | AI (source-diff): axios usage in bundled UI component, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-02780d26.mjs | AI (source-diff): Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-6395f4f4.mjs | AI (source-diff): Bundled UI library using axios/vue normally; no dropper/loader behavior present. | ai | |
| source-diff | obfuscated-file:dist/index-6395f4f4.mjs | AI (source-diff): Vite/Rollup bundle output, not true obfuscation; no malicious behavior found. | ai | |
| source-diff | net-exec-file:dist/index-3ca16065.mjs | AI (source-diff): axios import is the component's own HTTP client bundled inline, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-3ca16065.mjs | AI (source-diff): Bundled vite/esbuild output, not true obfuscation; standard vue-component bundle. | ai | |
| source-diff | net-exec-file:dist/index-35087210.mjs | AI (source-diff): Bundled UI lib importing axios/echarts; no malicious network+exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-35087210.mjs | AI (source-diff): Vite/rollup bundled output with source-map, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-d3de25f9.mjs | AI (source-diff): Vite/rollup-bundled ESM dist with banner header; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-d3de25f9.mjs | AI (source-diff): axios + Vue dynamic component resolution in bundled output; no fetched binary or hostile target. | ai | |
| source-diff | obfuscated-file:dist/index-7e6d3d53.mjs | AI (source-diff): Standard vite bundle output with recognizable imports; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/index-7e6d3d53.mjs | AI (source-diff): axios+dynamic code inside a UI bundle, no evidence of dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-7863b01b.mjs | AI (source-diff): Standard Vite/Rollup minified bundle, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-7863b01b.mjs | AI (source-diff): Bundled axios/vue lib triggers heuristic; no malicious network+exec behavior found. | ai | |
| source-diff | net-exec-file:dist/index-1eaea0ed.mjs | AI (source-diff): axios import + normal JS eval-like patterns in bundled UI lib, no dropper behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-1eaea0ed.mjs | AI (source-diff): Minified vite bundle with standard Vue/axios imports, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-0859ac36.mjs | AI (source-diff): axios + dynamic code patterns are normal in a bundled Vue component lib, no malicious target found. | ai | |
| source-diff | obfuscated-file:dist/index-0859ac36.mjs | AI (source-diff): Bundled Vite/Rollup ESM output for a Vue UI library, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-8b504455.mjs | AI (source-diff): axios import triggers network heuristic; no dropper behavior in code. | ai | |
| source-diff | obfuscated-file:dist/index-8b504455.mjs | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-1e9eac99.mjs | AI (source-diff): axios import in bundled UI lib, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-1e9eac99.mjs | AI (source-diff): Vite/Rollup bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-0c084163.mjs | AI (source-diff): axios+eval patterns are bundled framework code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-0c084163.mjs | AI (source-diff): Standard Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-0a929c31.mjs | AI (source-diff): Vite/Rollup bundle output, not true obfuscation; matches package's normal build artifacts. | ai | |
| source-diff | net-exec-file:dist/index-0a929c31.mjs | AI (source-diff): axios/echarts usage inside bundled UI component library, no hostile destination. | ai | |
| source-diff | net-exec-file:dist/index-1c8a46a1.mjs | AI (source-diff): Standard axios/vue bundle; network+exec pattern is normal for a UI lib bundle. | ai | |
| source-diff | obfuscated-file:dist/index-1c8a46a1.mjs | AI (source-diff): Bundled Vue component library output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-810def50.mjs | AI (source-diff): Standard axios import inside bundled UI code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-810def50.mjs | AI (source-diff): Bundled Vue component library output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-c36e79f0.mjs | AI (source-diff): axios/echarts bundled into build output; no exfil destination identified. | ai | |
| source-diff | obfuscated-file:dist/index-c36e79f0.mjs | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation; matches package's UI-library purpose. | ai | |
| source-diff | obfuscated-file:dist/index-b5c42d49.mjs | AI (source-diff): Vite/rollup bundle output with banner comment and standard imports; not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-b5c42d49.mjs | AI (source-diff): axios/echarts usage inside bundled UI library, no exfil behavior to unrelated destination. | ai | |
| source-diff | obfuscated-file:dist/index-2d589426.mjs | AI (source-diff): Bundled minified Vue component output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-2d589426.mjs | AI (source-diff): axios/dynamic-import inside UI bundle, no exfil destination shown. | ai | |
| source-diff | net-exec-file:dist/index-635d9326.mjs | AI (source-diff): Bundle uses axios/echarts normally; no exfil or dropper behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-635d9326.mjs | AI (source-diff): Standard bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-41d959ec.mjs | AI (source-diff): Bundled axios/echarts imports, no malicious exec pattern found. | ai | |
| source-diff | obfuscated-file:dist/index-41d959ec.mjs | AI (source-diff): Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-03c764ca.mjs | AI (source-diff): Same bundled file; axios import is a normal dependency, no exfil target found. | ai | |
| source-diff | obfuscated-file:dist/index-03c764ca.mjs | AI (source-diff): Vite/Rollup bundle output with banner comment and standard vue/echarts imports, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-fd1a691d.mjs | AI (source-diff): axios import in bundled UI lib, no exfil or fetched-binary behavior. | ai | |
| source-diff | obfuscated-file:dist/index-fd1a691d.mjs | AI (source-diff): Bundled Vue component code, not true obfuscation (readable imports, no _0x/eval-atob). | ai | |
| source-diff | net-exec-file:dist/index-d073710e.mjs | AI (source-diff): axios import in bundled UI library, not a dropper/loader pattern. | ai | |
| source-diff | obfuscated-file:dist/index-d073710e.mjs | AI (source-diff): Bundled Vite/Rollup output with long lines; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-94659242.mjs | AI (source-diff): Standard Vite bundle output, not true obfuscation (_0x/eval-atob). | ai | |
| source-diff | net-exec-file:dist/index-94659242.mjs | AI (source-diff): Bundled axios usage inside build output, not a dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/index-e10ad265.mjs | AI (source-diff): Vite/rollup bundle output, not true obfuscation (_0x/eval-atob/packer). | ai | |
| source-diff | net-exec-file:dist/index-e10ad265.mjs | AI (source-diff): Bundled UI library code; network+exec pattern is axios/vue framework code, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/index-64a64e77.mjs | AI (source-diff): Bundled build artifact importing axios/vue; no fetched-binary or exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/index-64a64e77.mjs | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-0614a2e5.mjs | AI (source-diff): Vite/Rollup bundle output with long minified lines, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-0614a2e5.mjs | AI (source-diff): Bundled axios+vue app code, no fetched-binary or exfil behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-4a10f9f9.mjs | AI (source-diff): Bundled Vite/rollup output, not true obfuscation (no _0x/eval-atob/packer). | ai | |
| source-diff | net-exec-file:dist/index-4a10f9f9.mjs | AI (source-diff): axios import is bundled dep used for the library's own data fetching, not exfil. | ai | |
| source-diff | net-exec-file:dist/index-a1bf09b5.mjs | AI (source-diff): axios import in bundled UI library code, no dropper/loader behavior found. | ai | |
| source-diff | encoded-string-file:dist/index.umd.js | AI (source-diff): Long strings are CSS/template literals in minified UMD bundle. | ai | |
| source-diff | obfuscated-file:dist/index-a1bf09b5.mjs | AI (source-diff): Bundled Vite/Rollup output with recognizable imports, not true obfuscation. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Same-org scoped dependency, not a supply-chain substitution. | ai | |
| source-diff | net-exec-file:dist/index-f06fe9ac.mjs | AI (source-diff): Bundled UI lib code (axios+echarts imports), not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-f06fe9ac.mjs | AI (source-diff): Minified Vite/Rollup bundle output, not true obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): Org-scoped internal BI component; lack of provenance is consistent across all versions and not a risk indicator here. | ai | |
| phantom-deps | phantom-dep:@ecan-bi/datav | AI (phantom-deps): Same-org dependency; phantom detection is a false positive for this package's build pattern. | ai | |
| phantom-deps | phantom-dep:monaco-editor | AI (phantom-deps): Listed in both dependencies and devDependencies; config-file reference is a stable false positive. | ai | |
| phantom-deps | phantom-dep:@visactor/vtable-export | AI (phantom-deps): Referenced in config files only; consistent with bundled/peer usage pattern across versions. | ai | |
| phantom-deps | phantom-dep:@visactor/vtable | AI (phantom-deps): Referenced in config files only; consistent with bundled/peer usage pattern across versions. | ai |
Versions (showing 51 of 57)
| Version | Deps | Published |
|---|---|---|
| 1.1.16 | 5 / 31 | |
| 1.1.15 | 5 / 31 | |
| 1.1.14 | 5 / 31 | |
| 1.1.12 | 5 / 31 | |
| 1.1.11 | 5 / 31 | |
| 1.1.10 | 5 / 31 | |
| 1.1.8 | 5 / 31 | |
| 1.1.7 | 5 / 31 | |
| 1.1.6 | 5 / 31 | |
| 1.1.5 | 5 / 31 | |
| 1.1.4 | 5 / 31 | |
| 1.1.3 | 5 / 31 | |
| 1.1.2 | 5 / 31 | |
| 1.1.1 | 5 / 31 | |
| 1.0.79 | 5 / 31 | |
| 1.0.78 | 5 / 31 | |
| 1.0.77 | 5 / 31 | |
| 1.0.76 | 5 / 31 | |
| 1.0.75 | 5 / 31 | |
| 1.0.74 | 4 / 31 | |
| 1.0.73 | 4 / 31 | |
| 1.0.72 | 4 / 31 | |
| 1.0.71 | 3 / 31 | |
| 1.0.70 | 3 / 31 | |
| 1.0.68 | 3 / 31 | |
| 1.0.67 | 3 / 31 | |
| 1.0.66 | 3 / 31 | |
| 1.0.65 | 3 / 31 | |
| 1.0.64 | 3 / 31 | |
| 1.0.63 | 3 / 31 | |
| 1.0.62 | 3 / 31 | |
| 1.0.61 | 3 / 31 | |
| 1.0.60 | 3 / 31 | |
| 1.0.59 | 3 / 31 | |
| 1.0.58 | 3 / 31 | |
| 1.0.56 | 3 / 31 | |
| 1.0.55 | 3 / 31 | |
| 1.0.54 | 3 / 31 | |
| 1.0.53 | 3 / 31 | |
| 1.0.52 | 3 / 31 | |
| 1.0.51 | 3 / 31 | |
| 1.0.50 | 3 / 31 | |
| 1.0.49 | 3 / 31 | |
| 1.0.48 | 3 / 31 | |
| 1.0.47 | 3 / 31 | |
| 1.0.46 | 3 / 31 | |
| 1.0.45 | 3 / 31 | |
| 1.0.44 | 3 / 31 | |
| 1.0.43 | 3 / 31 | |
| 1.0.42 | 3 / 31 | |
| 1.0.41 | 3 / 31 |
v1.1.16
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.15
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.14
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.79
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.78
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.77
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.76
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.75
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.74
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.73
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.72
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.71
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.70
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.68
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.67
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.66
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.65
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.64
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.63
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.62
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.61
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.60
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.59
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.58
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.56
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.55
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.54
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.53
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.52
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.51
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.50
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.49
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.48
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.47
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.46
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.45
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.44
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.43
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.42
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.41
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.