@fjall/deploy-core
Shared deployment engine for Fjall — used by CLI and webapp worker
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@aws-sdk/client-acm | AI (phantom-deps): Framework-scoped AWS SDK client used by convention in deploy toolkit. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/domain/zoneClassifier.js | AI (source-diff): Minified build output, not true obfuscation; logic matches stated AWS deployment functionality. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/domain/delegationDestroyMirror.js | AI (source-diff): Minified build output, legitimate Route53 delegation logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/domain/delegatedDomainDeploy.js | AI (source-diff): Minified build output, no malicious behavior present. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/domain/nsPropagationGate.js | AI (source-diff): Minified build output, legitimate DNS propagation logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/drift/route53RecordPreflight.js | AI (source-diff): Minified build output, legitimate drift-check logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/domain/caaPreflight.js | AI (source-diff): Minified build output from repo's own minify-dist build step, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/services/infrastructure/LambdaService.js | AI (source-diff): Minified build output, imports official @aws-sdk/client-lambda; matches package purpose. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/application/lambdaCodeOnlyRollout.js | AI (source-diff): Minified build output from repo's own minify-dist.mjs, not obfuscation; legit AWS Lambda deploy logic. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Publisher has long clean track record (278 approved, 0 rejected); no new suspicious maintainer added. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/builders/staticSiteBuilder.js | AI (source-diff): Minified build output, standard static-site build orchestration code. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/application/databaseEndpointReconcile.js | AI (source-diff): Minified build output from documented minify-dist step, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/application/serviceImageTagsRollback.js | AI (source-diff): Minified build output from documented minify-dist.mjs step, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/restart/restartApplication.js | AI (source-diff): Minified build output from documented minify-dist.mjs step, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from minified build output across new feature files. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Official @aws-sdk/client-rds matches new RDS remediation feature. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-rds | AI (phantom-deps): Framework-scoped AWS SDK client loaded by convention, consistent with other AWS SDK phantom deps. | ai | |
| source-diff | obfuscated-file:dist/src/services/infrastructure/cfnRegistrySeed.js | AI (source-diff): Minified build output (documented minify-dist.mjs step), not obfuscation; benign CFN data. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-account | AI (phantom-deps): Framework-scoped AWS SDK client; loaded by convention in this AWS deployment package. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/application/applicationDeploy.js | AI (source-diff): Minified TypeScript build output per package.json build script; content is AWS CDK orchestration logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/unlock/bucketPolicyTriage.js | AI (source-diff): Minified build output; content is S3 bucket policy analysis logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/application/buildSecretResolver.js | AI (source-diff): Minified build output; content is AWS Secrets Manager/SSM secret resolution logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/organisation/cascadeDestroyHelpers.js | AI (source-diff): Minified build output; content is AWS CloudFormation cascade destroy orchestration. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/organisation/cascadeHelpers.js | AI (source-diff): Minified build output; content is AWS org cascade helper logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/application/codeOnlyDeploy.js | AI (source-diff): Minified build output; content is ECS code-only deploy logic. | ai | |
| source-diff | obfuscated-file:dist/src/types/deployEmitter.js | AI (source-diff): Minified build output; content is deploy event emitter type logic. | ai | |
| source-diff | obfuscated-file:dist/src/types/deployEvent.js | AI (source-diff): Minified build output; content is Zod schema definitions for deploy events. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/application/dockerBuildHelper.js | AI (source-diff): Minified build output consistent with package build pipeline. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/organisation/organisationDestroy.js | AI (source-diff): Minified build output consistent with package build pipeline. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/organisation/organisationSetup.js | AI (source-diff): Minified build output consistent with package build pipeline. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/unlock/restoreAndReconcileQuarantinedBucket.js | AI (source-diff): Minified build output consistent with package build pipeline. | ai | |
| phantom-deps | phantom-dep:aws-cdk | AI (phantom-deps): aws-cdk is invoked as a CLI tool via tsx/child_process, not imported directly. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-ssm | AI (phantom-deps): Used in buildSecretResolver.js as seen in sample; phantom-dep is a false positive. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/organisationDeploy/orgCascadeDeploy.js | AI (source-diff): Same minified build output pattern; content is org-level CDK deploy orchestration. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sqs | AI (phantom-deps): AWS SDK clients are loaded by convention in this deployment engine; phantom-dep is a stable false positive. | ai | |
| source-diff | obfuscated-file:dist/src/aws/targetReadiness.js | AI (source-diff): Same minified build output pattern; content is AWS target readiness probing logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/stackCleanup/failedStack.js | AI (source-diff): Same minified build output pattern; content is CloudFormation/S3 stack cleanup logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/organisationDeploy/cascadeExecution.js | AI (source-diff): Package intentionally minifies dist output via minify-dist.mjs build step; content is legitimate AWS orchestration code. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/trailMigration/trailMigration.js | AI (source-diff): Package intentionally minifies dist output via minify-dist.mjs build step; content is readable CloudTrail/KMS logic, not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-secrets-manager | AI (phantom-deps): Framework-scoped AWS SDK dep loaded by convention, consistent with other accepted phantom deps in this package. | ai | |
| source-diff | obfuscated-file:dist/src/services/infrastructure/EcsService.js | AI (source-diff): Same intentional minification; content is legitimate AWS ECS service wrapper code. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/codeOnlyDeploy.js | AI (source-diff): Package intentionally minifies dist output via minify-dist.mjs build step; content is legitimate ECS orchestration code. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-ecr | AI (phantom-deps): AWS SDK clients are loaded by convention/factory pattern; consistent with other accepted phantom AWS SDK deps in this package. | ai | |
| provenance | no-provenance | AI (provenance): Consistent across all @fjall/deploy-core versions; no provenance is the norm for this package family. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sts | AI (phantom-deps): AWS SDK packages loaded by convention in deployment engine; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:@smithy/node-http-handler | AI (phantom-deps): Smithy HTTP handler used as AWS SDK transport; convention-loaded, not directly imported. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): AWS SDK packages loaded by convention in deployment engine; not directly imported but legitimately declared. | ai |
Versions (showing 51 of 80)
| Version | Deps | Published |
|---|---|---|
| 3.10.0 | 30 / 3 | |
| 3.9.0 | 30 / 3 | |
| 3.8.1 | 30 / 3 | |
| 3.8.0 | 30 / 3 | |
| 3.7.0 | 30 / 3 | |
| 3.6.1 | 30 / 3 | |
| 3.6.0 | 30 / 3 | |
| 3.5.2 | 29 / 3 | |
| 3.4.1 | 29 / 3 | |
| 3.3.0 | 29 / 3 | |
| 3.2.1 | 29 / 3 | |
| 3.1.0 | 29 / 3 | |
| 3.0.0 | 29 / 3 | |
| 2.34.0 | 28 / 3 | |
| 2.33.0 | 28 / 3 | |
| 2.32.0 | 28 / 3 | |
| 2.31.1 | 28 / 3 | |
| 2.30.3 | 27 / 3 | |
| 2.30.0 | 26 / 3 | |
| 2.29.0 | 26 / 3 | |
| 2.27.0 | 25 / 3 | |
| 2.25.0 | 25 / 3 | |
| 2.24.0 | 25 / 3 | |
| 2.23.1 | 24 / 3 | |
| 2.23.0 | 24 / 3 | |
| 2.22.1 | 24 / 3 | |
| 2.22.0 | 24 / 3 | |
| 2.21.0 | 20 / 3 | |
| 2.20.1 | 20 / 3 | |
| 2.20.0 | 20 / 3 | |
| 2.19.6 | 20 / 3 | |
| 2.19.5 | 20 / 3 | |
| 2.19.4 | 20 / 3 | |
| 2.19.3 | 20 / 2 | |
| 2.19.2 | 20 / 2 | |
| 2.19.1 | 20 / 2 | |
| 2.19.0 | 20 / 2 | |
| 2.18.3 | 20 / 2 | |
| 2.18.2 | 20 / 2 | |
| 2.18.1 | 20 / 2 | |
| 2.18.0 | 20 / 2 | |
| 2.17.0 | 20 / 2 | |
| 2.16.0 | 20 / 2 | |
| 2.15.0 | 20 / 2 | |
| 2.14.0 | 20 / 2 | |
| 2.13.0 | 18 / 2 | |
| 2.12.0 | 16 / 2 | |
| 2.11.1 | 16 / 2 | |
| 2.9.1 | 15 / 2 | |
| 2.9.0 | 15 / 2 | |
| 2.8.0 | 15 / 2 |
v3.10.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (josephce) than the most recent previously approved version (peoram) on 2026-07-16, but josephce is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.30.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.0
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.27.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.0
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.21.0
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.