@epilot/sdk
JavaScript/TypeScript SDK for epilot APIs
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): CI publish metadata artifact; provenance direction unchanged. | ai | |
| source-diff | obfuscated-file:dist/access-token-7Y2MDFZH.cjs | AI (source-diff): tsup-bundled per-API module, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/app-5VPBDFW2.cjs | AI (source-diff): Contains OpenAPI JSON definitions, no actual dynamic exec/network payload. | ai | |
| provenance | publisher-changed | AI (provenance): Move to GitHub Actions CI publisher with SLSA provenance is an improvement, not compromise. | ai | |
| source-diff | obfuscated-file:dist/entity-RCWJZZXM.cjs | AI (source-diff): Bundled API client output, minified not obfuscated. | ai | |
| provenance | regressed-provenance | AI (provenance): Manual publish by known maintainer already on prior versions, not a new actor. | ai | |
| source-diff | obfuscated-file:dist/customer-portal-AEFMNNYP.cjs | AI (source-diff): Bundled tsup output with embedded docs strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/customer-portal.d-BJNWYMt9.d.ts | AI (source-diff): Generated type definitions, long lines from auto-gen, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/journey-KDR5EU3W.js | AI (source-diff): Bundled tsup output with embedded docs strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/customer-portal-Y3GLUVMW.js | AI (source-diff): Bundled tsup output with embedded docs strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/customer-portal.d-BJNWYMt9.d.cts | AI (source-diff): Generated type definitions, long lines from auto-gen, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/audit-logs-D2LFUA2R.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/billing-DUWDISHP.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/blueprint-manifest-SHNZPK5O.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app-IKHWU222.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-agents-PWHKNRCX.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/address-suggestions-IUQMYF27.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/address-HA4RMRNQ.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/access-token-6BJDZSFE.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/automation-3HGCK725.cjs | AI (source-diff): Bundled tsup output embedding doc strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/erp-integration-A33WOGPF.cjs | AI (source-diff): Standard tsup bundle output with readable API docs content; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/erp-integration.d-B4XPU_j-.d.ts | AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/erp-integration-76K5HOGL.js | AI (source-diff): Standard tsup ESM bundle with readable API docs content; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/erp-integration.d-B4XPU_j-.d.cts | AI (source-diff): TypeScript declaration file with long lines from generated type definitions; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/README-6MG272KM.cjs | AI (source-diff): Minified CJS bundle; standard tsup build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/user-7ZN2XO7G.cjs | AI (source-diff): Standard tsup CJS bundle output embedding API doc strings; not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:dist/README-PTYV6PQI.cjs | AI (source-diff): Standard tsup CJS bundle output embedding API doc strings; not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:dist/environments-TZYXLYXA.cjs | AI (source-diff): Standard tsup CJS bundle output embedding API doc strings; not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:dist/design-NISDHPFD.cjs | AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/sharing-MR7ANOST.cjs | AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/template-variables-I72B5WS6.cjs | AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/workflow-CQOBZ25C.cjs | AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/workflow-definition-CVBYKAUY.cjs | AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/automation.d-CzhG2m4L.d.cts | AI (source-diff): TypeScript declaration file with large type definitions; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/blueprint-manifest-VBOWPK52.cjs | AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/README-Z5AKTGJA.cjs | AI (source-diff): CJS bundle chunk with large API doc strings; standard tsup output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/journey-REBN4TGQ.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/automation-IOCVCTKR.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/blueprint-manifest-IEQ6YBY7.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/configuration-hub-LKSRCGYT.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/customer-portal-5LMHNBMD.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/data-governance-2U5UU4GM.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/deduplication-PKKTZAEA.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/design-XZKOZLTR.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/email-settings-NQJJKS2P.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/entity-TFMH5VTZ.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/environments-QJ4UMJ5C.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/erp-integration-PAVHSUDM.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/erp-integration-runtime-OZ4YSTQX.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/integration-toolkit-VNMDI55O.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/message-J2SFQJNB.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| source-diff | obfuscated-file:dist/query-JSDB2F2U.cjs | AI (source-diff): Minified CJS bundle containing readable API docs; standard build output for this SDK. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Internal epilot GmbH team rotation; SLSA provenance confirms CI-published release. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Internal epilot GmbH team rotation; SLSA provenance confirms CI-published release. | ai | |
| source-diff | obfuscated-file:dist/targeting-67M7H7T7.cjs | AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/blueprint-manifest-GCV7H74X.cjs | AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/targeting-XHHZ2TK4.js | AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/blueprint-manifest-6DEYW5MW.js | AI (source-diff): Standard tsup bundle output with readable API doc content; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/webhooks-SK2STDKR.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/README-IVBISSWB.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/pricing-F7HQ6BWC.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/notes-SLEUSNP4.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/metering-MHBFU7QH.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/journey-ATC3Y5AW.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/integration-toolkit-3I3IPVFN.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/file-BGJVE7QG.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/event-catalog-5JBHJJ2I.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/entity-SS36LQO6.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/email-settings-YJ4X5VFU.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/design-W3D3UPGB.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/customer-portal-5OSGSYGF.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/configuration-hub-Q5JBYB52.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | obfuscated-file:dist/app-74LECFMK.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/calendar-2YDAYG7S.cjs | AI (source-diff): Standard tsup CJS bundle output; content is readable API docs/SDK code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): SDK adds new API modules per version; large file count is expected growth pattern for this package. | ai | |
| source-diff | net-exec-file:dist/app.d-BOR23dso.d.cts | AI (source-diff): TypeScript declaration file (.d.cts); network/exec pattern is a false positive on type-level API surface definitions. | ai | |
| source-diff | obfuscated-file:dist/customer-portal.d-BRwiQehb.d.cts | AI (source-diff): Large TypeScript declaration file from tsup; long lines are generated type unions, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/entity-RT4YRZDG.js | AI (source-diff): Standard tsup ESM bundle; same pattern as CJS counterpart. | ai | |
| source-diff | obfuscated-file:dist/entity.d-__Tx1Y0J.d.ts | AI (source-diff): TypeScript declaration file with readable OpenAPI types; long lines from type unions. | ai | |
| source-diff | obfuscated-file:dist/entity.d-__Tx1Y0J.d.cts | AI (source-diff): TypeScript declaration file with readable OpenAPI types; long lines from type unions. | ai | |
| source-diff | obfuscated-file:dist/entity-M5F22DSS.cjs | AI (source-diff): Standard tsup CJS bundle; long lines are embedded API doc strings, not obfuscation. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 2.14.2 | 0 / 7 | |
| 2.7.7 | 0 / 7 | |
| 2.7.6 | 0 / 7 | |
| 2.7.5 | 0 / 7 | |
| 2.7.4 | 0 / 7 | |
| 2.4.3 | 0 / 7 | |
| 2.3.7 | 0 / 7 | |
| 2.3.6 | 0 / 7 | |
| 2.3.5 | 0 / 7 | |
| 2.3.2 | 0 / 7 | |
| 2.3.1 | 0 / 7 | |
| 2.3.0 | 0 / 7 | |
| 2.2.7 | 0 / 7 | |
| 2.2.6 | 0 / 7 | |
| 2.2.5 | 0 / 7 | |
| 2.2.2 | 0 / 7 | |
| 2.2.1 | 0 / 7 | |
| 2.2.0 | 0 / 7 | |
| 2.1.10 | 0 / 7 | |
| 2.1.9 | 0 / 7 | |
| 2.1.8 | 0 / 7 | |
| 2.1.7 | 0 / 7 | |
| 2.1.6 | 0 / 7 | |
| 2.1.5 | 0 / 7 | |
| 2.1.4 | 0 / 7 | |
| 2.1.0 | 0 / 7 | |
| 2.0.4 | 0 / 7 | |
| 2.0.3 | 0 / 7 |
v2.14.2
20 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.6
2 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-04-15, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.2
17 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-03-25, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.1
7 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-03-24, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.0
7 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (anttiviljami) than the most recent previously approved version (GitHub Actions) on 2026-03-24, but anttiviljami is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.1.10
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.9
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.7
13 findingsThis version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.6
13 findingsThis version was published by a different npm account than previous versions on 2026-03-23. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.5
13 findingsThis version was published by a different npm account than previous versions on 2026-03-22. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.4
13 findingsThis version was published by a different npm account than previous versions on 2026-03-20. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.0
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.