@elliemae/pui-service-sdk
SDK for creating NodeJS MicroServices
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Established internal SDK with long release cadence, not account takeover pattern. | ai | |
| source-diff | net-exec-file:build/docs/assets/js/main.1af77d65.js | AI (source-diff): Bundled docs site JS, false positive on net+exec pattern. | ai | |
| source-diff | net-exec-file:build/docs/assets/js/7961.f21e0819.js | AI (source-diff): Bundled docs site JS, false positive on net+exec pattern. | ai | |
| source-diff | net-exec-file:build/docs/assets/js/common.7dc9fc3a.js | AI (source-diff): Bundled docs site JS, false positive on net+exec pattern. | ai | |
| source-diff | obfuscated-file:build/docs/assets/js/common.7dc9fc3a.js | AI (source-diff): Docusaurus/webpack docs build output, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@types/cors | AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/hpp | AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/compression | AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/express | AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. | ai | |
| phantom-deps | phantom-dep:@types/uuid | AI (phantom-deps): @types/* packages are convention-loaded TypeScript definitions, not directly imported. | ai | |
| dependencies | unvetted-dep:express-pino-logger | AI (dependencies): express-pino-logger is a well-known pino logging middleware for Express; no advisory history. | ai | |
| dependencies | unvetted-dep:hpp | AI (dependencies): hpp is a known Express HTTP parameter pollution middleware; stable low-risk dep for this SDK. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): SDK declares pg as a runtime dep for consumers; config-referenced pattern is stable for this package. | ai | |
| phantom-deps | phantom-dep:express-pino-logger | AI (phantom-deps): Logging middleware declared for consumer use; stable false positive for this SDK. | ai | |
| phantom-deps | phantom-dep:@prisma/client | AI (phantom-deps): Prisma client declared for consumer use; stable false positive for this SDK. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): Logging dep declared for consumer use; stable false positive for this SDK. | ai | |
| phantom-deps | phantom-dep:express-jwt | AI (phantom-deps): Auth middleware declared for consumer use; stable false positive for this SDK. | ai | |
| phantom-deps | phantom-dep:escape-html | AI (phantom-deps): Utility dep declared for consumer use; stable false positive for this SDK. | ai | |
| phantom-deps | phantom-dep:ajv-formats | AI (phantom-deps): Companion to ajv; config-referenced pattern stable for this SDK. | ai | |
| phantom-deps | phantom-dep:prisma | AI (phantom-deps): ORM dep declared for consumer use; config-referenced pattern stable for this SDK. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): Validation dep used via config; stable false positive for this SDK. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 4.8.1 | 22 / 12 | |
| 4.8.0 | 22 / 12 | |
| 4.7.4 | 22 / 12 | |
| 4.7.2 | 27 / 7 | |
| 4.6.0 | 27 / 7 |
v4.8.1
21 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: encw.dev.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.