@everymatrix/casino-promotions-nd
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:svelte | AI (phantom-deps): Build-tool dependency; used in scripts and config, not runtime import. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Build-tool dependency; used in scripts, not runtime import. | ai | |
| phantom-deps | phantom-dep:sirv-cli | AI (phantom-deps): Build-tool dependency; used in scripts, not runtime import. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-D-GtKSQh.js | AI (source-diff): Minified bundler output (esbuild/vite chunk), not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-BhhcGTxu.cjs | AI (source-diff): Minified bundler output (esbuild/vite chunk), not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-8aREoZ90.js | AI (source-diff): Minified bundler output (esbuild/vite chunk), not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-C5DMyqhN.js | AI (source-diff): Standard Vite/Svelte minified bundle output; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DEDfGcCx.js | AI (source-diff): Standard Vite/Svelte minified bundle output; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-CGaKBRPQ.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:stencil/index-b2193545-9K-aI7zC.cjs | AI (source-diff): Stencil runtime CJS bundle; minified but not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DbINkDsn.cjs | AI (source-diff): Standard minified Svelte/Stencil component bundle output for this package. | ai | |
| source-diff | obfuscated-file:stencil/ui-skeleton-ed169f8f-CpiCXJrP.cjs | AI (source-diff): UI skeleton component with CSS; standard build output. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-BOnhYATT.js | AI (source-diff): ESM version of the same component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-EtmwLYu8.js | AI (source-diff): ESM version of the same component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DB1oDErp.js | AI (source-diff): Vite-bundled ESM output; minified but readable structure, no malicious indicators. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DJfYThbo.js | AI (source-diff): Vite-bundled ESM output; standard build artifact for this package. | ai | |
| source-diff | obfuscated-file:stencil/ui-skeleton-ae35c6f2-xLf3HyeB.cjs | AI (source-diff): Stencil component bundle with CSS-in-JS; not obfuscated. | ai | |
| source-diff | obfuscated-file:stencil/index-b2193545-YW9b062G.cjs | AI (source-diff): Standard Stencil runtime bundle; content matches known Stencil patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-CXPvA0xD.cjs | AI (source-diff): Standard Stencil/Vite minified build output; long lines are bundled JS, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-EaNbzUGB.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-B5Rz-3zH.js | AI (source-diff): Standard Vite/Svelte minified bundle output; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-oZQ8b9QM.js | AI (source-diff): Standard Vite/Svelte minified bundle output; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-BR8-U9oH.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output; consistent with prior releases of this UI component package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DxI-IFg2.js | AI (source-diff): Standard Rollup/Vite minified bundle output; consistent with prior releases of this UI component package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-BXMZjt_D.js | AI (source-diff): Standard Rollup/Vite minified bundle output; consistent with prior releases of this UI component package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped internal UI component package in a monorepo; no repo/deps/keywords is expected for this type of package. | ai |
Versions (showing 100 of 479)
| Version | Deps | Published |
|---|---|---|
| 1.94.81 | 0 / 0 | |
| 1.94.80 | 0 / 0 | |
| 1.94.79 | 0 / 0 | |
| 1.94.78 | 0 / 0 | |
| 1.94.77 | 0 / 0 | |
| 1.94.76 | 0 / 0 | |
| 1.94.75 | 0 / 0 | |
| 1.94.74 | 0 / 0 | |
| 1.94.73 | 0 / 0 | |
| 1.94.72 | 0 / 0 | |
| 1.94.71 | 0 / 0 | |
| 1.94.70 | 0 / 0 | |
| 1.94.69 | 0 / 0 | |
| 1.94.68 | 0 / 0 | |
| 1.94.67 | 0 / 0 | |
| 1.94.66 | 0 / 0 | |
| 1.94.65 | 0 / 0 | |
| 1.94.64 | 0 / 0 | |
| 1.94.63 | 0 / 0 | |
| 1.94.62 | 0 / 0 | |
| 1.94.61 | 0 / 0 | |
| 1.94.60 | 0 / 0 | |
| 1.94.59 | 0 / 0 | |
| 1.94.58 | 0 / 0 | |
| 1.94.57 | 0 / 0 | |
| 1.94.56 | 0 / 0 | |
| 1.94.55 | 0 / 0 | |
| 1.94.54 | 0 / 0 | |
| 1.94.53 | 0 / 0 | |
| 1.94.52 | 0 / 0 | |
| 1.94.51 | 0 / 0 | |
| 1.94.50 | 0 / 0 | |
| 1.94.49 | 0 / 0 | |
| 1.94.48 | 0 / 0 | |
| 1.94.47 | 0 / 0 | |
| 1.94.46 | 0 / 0 | |
| 1.94.45 | 0 / 0 | |
| 1.94.44 | 0 / 0 | |
| 1.94.43 | 0 / 0 | |
| 1.94.42 | 0 / 0 | |
| 1.94.41 | 0 / 0 | |
| 1.94.40 | 0 / 0 | |
| 1.94.39 | 0 / 0 | |
| 1.94.38 | 0 / 0 | |
| 1.94.37 | 0 / 0 | |
| 1.94.36 | 0 / 0 | |
| 1.94.35 | 0 / 0 | |
| 1.94.34 | 0 / 0 | |
| 1.94.33 | 0 / 0 | |
| 1.94.32 | 0 / 0 | |
| 1.94.31 | 0 / 0 | |
| 1.94.30 | 0 / 0 | |
| 1.94.29 | 0 / 0 | |
| 1.94.28 | 0 / 0 | |
| 1.94.27 | 0 / 0 | |
| 1.94.26 | 0 / 0 | |
| 1.94.25 | 0 / 0 | |
| 1.94.24 | 0 / 0 | |
| 1.94.23 | 0 / 0 | |
| 1.94.22 | 0 / 0 | |
| 1.94.21 | 0 / 0 | |
| 1.94.20 | 0 / 0 | |
| 1.94.19 | 0 / 0 | |
| 1.94.18 | 0 / 0 | |
| 1.94.17 | 0 / 0 | |
| 1.94.16 | 0 / 0 | |
| 1.94.15 | 0 / 0 | |
| 1.94.9 | 0 / 0 | |
| 1.94.8 | 0 / 0 | |
| 1.94.7 | 0 / 0 | |
| 1.94.6 | 0 / 0 | |
| 1.94.5 | 0 / 0 | |
| 1.94.4 | 0 / 0 | |
| 1.94.3 | 0 / 0 | |
| 1.94.2 | 0 / 0 | |
| 1.94.1 | 0 / 0 | |
| 1.94.0 | 0 / 0 | |
| 1.93.15 | 0 / 0 | |
| 1.93.14 | 0 / 0 | |
| 1.93.13 | 0 / 0 | |
| 1.93.12 | 0 / 0 | |
| 1.93.11 | 0 / 0 | |
| 1.93.10 | 0 / 0 | |
| 1.93.9 | 0 / 0 | |
| 1.93.8 | 0 / 0 | |
| 1.93.7 | 0 / 0 | |
| 1.93.6 | 0 / 0 | |
| 1.93.5 | 0 / 0 | |
| 1.93.4 | 0 / 0 | |
| 1.93.3 | 0 / 0 | |
| 1.93.2 | 0 / 0 | |
| 1.93.1 | 0 / 0 | |
| 1.93.0 | 0 / 0 | |
| 1.92.8 | 0 / 0 | |
| 1.92.7 | 0 / 0 | |
| 1.92.6 | 0 / 0 | |
| 1.92.5 | 0 / 0 | |
| 1.92.4 | 0 / 0 | |
| 1.92.3 | 0 / 0 | |
| 1.92.2 | 0 / 0 |
v1.94.81
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.80
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.79
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.78
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.76
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.75
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.74
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.73
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.72
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.71
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.70
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.69
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.68
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.67
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.66
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.65
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.64
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.63
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.62
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.61
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.60
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.58
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.55
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.53
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.94.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.