← Home

@elliemae/pui-service-sdk

SDK for creating NodeJS MicroServices

5
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

encw.dev

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): Established internal SDK with long release cadence, not account takeover pattern. ai
source-diff net-exec-file:build/docs/assets/js/main.1af77d65.js AI (source-diff): Bundled docs site JS, false positive on net+exec pattern. ai
source-diff net-exec-file:build/docs/assets/js/7961.f21e0819.js AI (source-diff): Bundled docs site JS, false positive on net+exec pattern. ai
source-diff net-exec-file:build/docs/assets/js/common.7dc9fc3a.js AI (source-diff): Bundled docs site JS, false positive on net+exec pattern. ai
source-diff obfuscated-file:build/docs/assets/js/common.7dc9fc3a.js AI (source-diff): Docusaurus/webpack docs build output, not obfuscation. ai
phantom-deps phantom-dep:@types/cors AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. ai
phantom-deps phantom-dep:@types/hpp AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. ai
phantom-deps phantom-dep:@types/compression AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. ai
phantom-deps phantom-dep:@types/express AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. ai
phantom-deps phantom-dep:@types/uuid AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. ai
dependencies unvetted-dep:express-pino-logger AI (dependencies): express-pino-logger is a well-known pino logging middleware for Express; no advisory history. ai
dependencies unvetted-dep:hpp AI (dependencies): hpp is a known Express HTTP parameter pollution middleware; stable low-risk dep for this SDK. ai
phantom-deps phantom-dep:pg AI (phantom-deps): SDK declares pg as a runtime dep for consumers; config-referenced pattern is stable for this package. ai
phantom-deps phantom-dep:express-pino-logger AI (phantom-deps): Logging middleware declared for consumer use; stable false positive for this SDK. ai
phantom-deps phantom-dep:@prisma/client AI (phantom-deps): Prisma client declared for consumer use; stable false positive for this SDK. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): Logging dep declared for consumer use; stable false positive for this SDK. ai
phantom-deps phantom-dep:express-jwt AI (phantom-deps): Auth middleware declared for consumer use; stable false positive for this SDK. ai
phantom-deps phantom-dep:escape-html AI (phantom-deps): Utility dep declared for consumer use; stable false positive for this SDK. ai
phantom-deps phantom-dep:ajv-formats AI (phantom-deps): Companion to ajv; config-referenced pattern stable for this SDK. ai
phantom-deps phantom-dep:prisma AI (phantom-deps): ORM dep declared for consumer use; config-referenced pattern stable for this SDK. ai
phantom-deps phantom-dep:ajv AI (phantom-deps): Validation dep used via config; stable false positive for this SDK. ai

Versions (showing 5 of 5)

Version Deps Published
4.8.1 22 / 12
4.8.0 22 / 12
4.7.4 22 / 12
4.7.2 27 / 7
4.6.0 27 / 7

v4.8.1

21 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: encw.dev.

HIGH New obfuscated file: build/docs/assets/js/1194.1753da98.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/1634.51cbd3fa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/17896441.b9ffcabf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/3969.684a59db.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/docs/assets/js/4854.9eb06acd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/5616.e1c58dfc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/6659.df3dd95f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/docs/assets/js/7961.f21e0819.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: build/docs/assets/js/7961.f21e0819.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/8350.e0ff4db4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/docs/assets/js/9282.626c1482.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/987.9d0beb40.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/a8bb5334.56e06673.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/a94703ab.f03132cb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/c377a04b.b4ef245c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: build/docs/assets/js/common.7dc9fc3a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: build/docs/assets/js/common.7dc9fc3a.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: build/docs/assets/js/main.1af77d65.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: build/docs/assets/js/main.1af77d65.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.