@everymatrix/cashier-methods-list
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CashierMethodsList-CCAqzm-1.cjs | AI (source-diff): Bundled/minified Svelte component output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DYyjRpTm.js | AI (source-diff): Bundled/minified Svelte component output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BEy09Eo9.js | AI (source-diff): Bundled/minified Svelte component output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BEyQW6Zd.js | AI (source-diff): Minified bundler output, consistent build pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CdrV9VIF.js | AI (source-diff): Minified bundler output, consistent build pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CTUypjId.cjs | AI (source-diff): Minified bundler output (esbuild/rollup helpers), not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BLNkFl4M.js | AI (source-diff): Bundled minified build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BIMdZpJT.cjs | AI (source-diff): Bundled minified build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-B9Lg8EG8.js | AI (source-diff): Bundled minified build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CroX4WQT.js | AI (source-diff): Standard ESM build output for a Svelte component; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BQKiNww3.cjs | AI (source-diff): Standard minified CJS build output for a Svelte component; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-Dxqvras0.js | AI (source-diff): Standard ESM build output for a Svelte component; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BqKh2TPE.js | AI (source-diff): Standard Vite/Rollup ESM bundle output for Svelte component; not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DwMW2sMX.js | AI (source-diff): Standard Vite/Rollup ESM bundle output for Svelte component; not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BSLTlsYM.cjs | AI (source-diff): Standard Vite/Rollup CJS bundle output for Svelte component; not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-C846UBGU.js | AI (source-diff): Standard minified Svelte bundle output; stable pattern for this component library package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-eM03HNfY.js | AI (source-diff): Standard minified Svelte bundle output; stable pattern for this component library package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CuP1ojFe.cjs | AI (source-diff): Standard minified Svelte bundle output; stable pattern for this component library package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-qbUUs4Yf.cjs | AI (source-diff): Standard Svelte/Rollup minified bundle output; not malicious obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-GpRa3Xd7.js | AI (source-diff): Standard Svelte/Rollup minified bundle output; not malicious obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-TXDO2H7v.js | AI (source-diff): Standard Svelte/Rollup minified bundle output; not malicious obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CFZZOKpc.js | AI (source-diff): Standard build output for Svelte component; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CK_Lhegp.js | AI (source-diff): Standard build output for Svelte component; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DzSYVD19.cjs | AI (source-diff): Standard minified build output for Svelte component; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BNO_3M_F.cjs | AI (source-diff): Standard minified Svelte bundle output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-Vzg-wLI3.js | AI (source-diff): Standard minified Svelte bundle output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-JWFVpzR9.js | AI (source-diff): Standard minified Svelte bundle output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DN_phmYs.cjs | AI (source-diff): Standard CJS bundle of Svelte component; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DgKemLH6.js | AI (source-diff): Standard ESM bundle of Svelte component; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CofeGxcF.js | AI (source-diff): Standard ESM bundle of Svelte component; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-WXyddtkn.js | AI (source-diff): Standard minified Svelte component bundle; pattern repeats across every version of this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BJj9LVwd.cjs | AI (source-diff): Standard minified Svelte component bundle; pattern repeats across every version of this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BeS3VCSB.js | AI (source-diff): Standard minified Svelte component bundle; pattern repeats across every version of this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped component library; no description/repo/deps is consistent across 502 published versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern for this internal component package across all versions. | ai |
Versions (showing 51 of 468)
| Version | Deps | Published |
|---|---|---|
| 1.94.81 | 0 / 0 | |
| 1.94.80 | 0 / 0 | |
| 1.94.79 | 0 / 0 | |
| 1.94.78 | 0 / 0 | |
| 1.94.77 | 0 / 0 | |
| 1.94.76 | 0 / 0 | |
| 1.94.75 | 0 / 0 | |
| 1.94.74 | 0 / 0 | |
| 1.94.73 | 0 / 0 | |
| 1.94.72 | 0 / 0 | |
| 1.94.71 | 0 / 0 | |
| 1.94.70 | 0 / 0 | |
| 1.94.69 | 0 / 0 | |
| 1.94.68 | 0 / 0 | |
| 1.94.67 | 0 / 0 | |
| 1.94.66 | 0 / 0 | |
| 1.94.65 | 0 / 0 | |
| 1.94.64 | 0 / 0 | |
| 1.94.63 | 0 / 0 | |
| 1.94.62 | 0 / 0 | |
| 1.94.61 | 0 / 0 | |
| 1.94.60 | 0 / 0 | |
| 1.94.59 | 0 / 0 | |
| 1.94.58 | 0 / 0 | |
| 1.94.57 | 0 / 0 | |
| 1.94.56 | 0 / 0 | |
| 1.94.55 | 0 / 0 | |
| 1.94.54 | 0 / 0 | |
| 1.94.53 | 0 / 0 | |
| 1.94.52 | 0 / 0 | |
| 1.94.51 | 0 / 0 | |
| 1.94.50 | 0 / 0 | |
| 1.94.49 | 0 / 0 | |
| 1.94.48 | 0 / 0 | |
| 1.94.47 | 0 / 0 | |
| 1.94.46 | 0 / 0 | |
| 1.94.45 | 0 / 0 | |
| 1.94.44 | 0 / 0 | |
| 1.94.43 | 0 / 0 | |
| 1.94.42 | 0 / 0 | |
| 1.94.41 | 0 / 0 | |
| 1.94.40 | 0 / 0 | |
| 1.94.39 | 0 / 0 | |
| 1.94.38 | 0 / 0 | |
| 1.94.37 | 0 / 0 | |
| 1.94.36 | 0 / 0 | |
| 1.94.35 | 0 / 0 | |
| 1.94.34 | 0 / 0 | |
| 1.94.33 | 0 / 0 | |
| 1.94.32 | 0 / 0 | |
| 1.94.31 | 0 / 0 |
v1.94.81
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.80
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.79
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.76
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.75
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.74
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.73
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.72
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.71
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.70
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.69
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.68
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.67
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.66
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.65
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.64
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.63
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.62
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.61
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.60
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.58
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.57
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.56
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.55
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.54
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.53
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.