@everymatrix/casino-modal
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CasinoModal-D8lK9TP_.js | AI (source-diff): Bundled build output, matches pattern of sibling files. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-BGJRj7h6.js | AI (source-diff): Bundled build output, standard Svelte/JS bundler helpers. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-CrkUUnet.cjs | AI (source-diff): Bundled build output (esbuild helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-BwkMKKYu.js | AI (source-diff): Bundled build output, standard minified JS helpers. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-Cjk9RvGH.cjs | AI (source-diff): Bundled build output (esbuild/vite banner), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-CeD3iiwm.js | AI (source-diff): Bundled build output, standard minified JS helpers. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-CNhAaW5C.js | AI (source-diff): Bundled Vite/Rollup build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-DT6EeT6K.cjs | AI (source-diff): Bundled Vite/Rollup build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-D9rfYGUP.js | AI (source-diff): Bundled Vite/Rollup build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-jtf5m89J.cjs | AI (source-diff): Bundled build output (esbuild-style), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-BtrASRC-.js | AI (source-diff): Bundled build output (esbuild-style), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-Cef7jttj.js | AI (source-diff): Bundled build output (esbuild-style), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-CqfnLttT.js | AI (source-diff): Bundled Svelte build output, not true obfuscation; consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-BBq_phDj.cjs | AI (source-diff): Minified bundler output (esbuild/rollup style), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-k6qooyWQ.js | AI (source-diff): Minified bundler output (esbuild/rollup style), not true obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known EveryMatrix org accounts; consistent with internal publishing rotation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-_mJbZveA.cjs | AI (source-diff): Bundled minified build output (esbuild-style preamble), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-Dib1gGis.js | AI (source-diff): Bundled minified build output, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Build environment utility; used in build/dev scripts, not direct import. | ai | |
| phantom-deps | phantom-dep:sirv-cli | AI (phantom-deps): Dev server tool; used in start script, not direct import. | ai | |
| phantom-deps | phantom-dep:svelte | AI (phantom-deps): Svelte framework dependency; referenced in build config and scripts, not direct import. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-5I3ffJnt.cjs | AI (source-diff): Bundled/minified build output (esbuild banner vars), not true obfuscation. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal EveryMatrix component lib; sparse metadata is normal, not spam. | ai | |
| source-diff | obfuscated-file:components/CasinoModal-Cc1YsxcQ.js | AI (source-diff): Bundled/minified build output, not true obfuscation. | ai |
Versions (showing 51 of 88)
| Version | Deps | Published |
|---|---|---|
| 1.62.4 | 0 / 0 | |
| 1.62.3 | 0 / 0 | |
| 1.62.2 | 0 / 0 | |
| 1.62.1 | 0 / 0 | |
| 1.62.0 | 0 / 0 | |
| 1.60.1 | 0 / 0 | |
| 1.60.0 | 0 / 0 | |
| 1.59.2 | 0 / 0 | |
| 1.57.0 | 0 / 0 | |
| 1.56.3 | 0 / 0 | |
| 1.56.2 | 0 / 0 | |
| 1.56.0 | 0 / 0 | |
| 1.55.0 | 0 / 0 | |
| 1.54.6 | 0 / 0 | |
| 1.54.4 | 0 / 0 | |
| 1.54.2 | 0 / 0 | |
| 1.54.0 | 0 / 0 | |
| 1.53.12 | 0 / 0 | |
| 1.53.11 | 0 / 0 | |
| 1.53.10 | 0 / 0 | |
| 1.53.0 | 0 / 0 | |
| 1.52.6 | 0 / 0 | |
| 1.52.5 | 0 / 0 | |
| 1.52.4 | 0 / 0 | |
| 1.52.3 | 0 / 0 | |
| 1.52.2 | 0 / 0 | |
| 1.52.1 | 0 / 0 | |
| 1.52.0 | 0 / 0 | |
| 1.51.0 | 0 / 0 | |
| 1.50.1 | 0 / 0 | |
| 1.49.2 | 0 / 0 | |
| 1.49.1 | 0 / 0 | |
| 1.49.0 | 0 / 0 | |
| 1.48.2 | 0 / 0 | |
| 1.48.1 | 0 / 0 | |
| 1.48.0 | 0 / 0 | |
| 1.47.3 | 0 / 0 | |
| 1.47.2 | 0 / 0 | |
| 1.47.1 | 0 / 0 | |
| 1.47.0 | 0 / 0 | |
| 1.46.1 | 0 / 0 | |
| 1.46.0 | 0 / 0 | |
| 1.45.14 | 0 / 0 | |
| 1.45.13 | 0 / 0 | |
| 1.45.11 | 0 / 0 | |
| 1.45.10 | 0 / 0 | |
| 1.45.9 | 0 / 0 | |
| 1.45.8 | 0 / 0 | |
| 1.45.7 | 0 / 0 | |
| 1.45.6 | 0 / 0 | |
| 1.45.5 | 0 / 0 |
v1.62.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.62.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-03-28, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.62.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-03-27, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.62.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-03-26, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.62.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-03-26. It has since remained available on npm for 479 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-03-19. It has since remained available on npm for 487 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.60.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-03-17. It has since remained available on npm for 488 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.59.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-03-12. It has since remained available on npm for 493 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.57.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-03-03. It has since remained available on npm for 502 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.56.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-02-27. It has since remained available on npm for 507 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.56.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-02-25. It has since remained available on npm for 508 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.56.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-02-19, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.55.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-02-17. It has since remained available on npm for 516 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.54.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-02-05, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.54.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-31, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.54.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-31, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.54.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (emfe_release) than the most recent previously approved version (raulvasileem) on 2025-01-29. It has since remained available on npm for 535 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.12
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-31, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.53.11
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-31, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.53.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-31, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.53.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-01-23. It has since remained available on npm for 541 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.6
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-17, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.52.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-01-16. It has since remained available on npm for 548 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.4
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-01-15. It has since remained available on npm for 549 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-01-14. It has since remained available on npm for 551 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.52.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-13, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.52.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-13, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.52.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2025-01-10. It has since remained available on npm for 554 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.51.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2025-01-03, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.50.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2024-12-23. It has since remained available on npm for 572 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.49.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-12-17, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.49.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-12-16, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.49.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-12-11, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.48.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2024-12-09. It has since remained available on npm for 586 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.48.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2024-12-05. It has since remained available on npm for 590 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.48.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-12-03, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.47.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-29, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.47.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-28, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.47.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2024-11-27. It has since remained available on npm for 598 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.47.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (maria.bumbar) than the most recent previously approved version (raulvasileem) on 2024-11-27. It has since remained available on npm for 598 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.46.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-22, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.46.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-20, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.45.14
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-19, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.45.13
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.11
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.45.9
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-14, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.45.8
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-11, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.45.7
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-06, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.45.6
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-05, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.45.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (adrian.pripon) than the most recent previously approved version (raulvasileem) on 2024-11-01, but adrian.pripon is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.