@flowfuse/flowfuse
An open source low-code development platform
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:frontend/dist/app/main.1729015ac167af1b6578.js | AI (source-diff): Webpack bundler output for frontend build, not true obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.ec2e6b57e5d059b45675.js | AI (source-diff): Webpack bundler output for frontend build, not true obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.34c244b6b4f8a832f366.js | AI (source-diff): Webpack-bundled setup wizard chunk; same icon/module pattern. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.f946515216b240b0054b.js | AI (source-diff): Vendor bundle containing node-red flow-renderer + HTTP client libs, not a dropper. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.16bdf45a1691a23e86f3.js | AI (source-diff): Webpack-bundled frontend asset; sample shows benign SVG icon components. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.1cdec14f12421ceac108.js | AI (source-diff): Webpack-bundled frontend main entry; standard module resolution code. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.c7665d54f260de0c87a9.js | AI (source-diff): Webpack bundle output for frontend app, not obfuscation. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.bfc0b7c3f0b912f18c3f.js | AI (source-diff): Bundled Node-RED editor vendor code; no exfil behavior evident. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.8b73a2e88c0ffad342c9.js | AI (source-diff): Webpack bundle output for frontend app, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.46b3e1b57f79ca894b4d.js | AI (source-diff): Webpack bundle output for frontend app, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.740697272a8a60025a8a.js | AI (source-diff): Webpack-bundled frontend asset, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.2c5ee6925b6e42222078.js | AI (source-diff): Webpack-bundled frontend asset, minified not obfuscated. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.164857397e7eac984cd5.js | AI (source-diff): Bundled Node-RED editor vendor code, no exfil behavior observed. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.ad5f7ce700707c0c5fa5.js | AI (source-diff): Webpack-bundled frontend asset, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.a410d7f125349d4e6a73.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.fa95294cc8c0adb1ddab.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.204025873ddf29846309.js | AI (source-diff): Webpack bundle output, standard build artifact for this large frontend app. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): flowfuse-user is a known maintainer per provenance record, matches prior approved history. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.b7d5ad7760e411b664b4.js | AI (source-diff): Webpack bundle output, standard build artifact for this large frontend app. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.c21524f6d4c01a6a54f1.js | AI (source-diff): Bundled vendor code (Node-RED flow editor deps) with LICENSE.txt banner, not a dropper. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.90a7f5b0c1e056dda76c.js | AI (source-diff): Bundled vendor JS (Node-RED editor UI libs), not a dropper. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.94dc2e6b50c9da19cacf.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.0035fbe0d465917e8a17.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.6bdc9078fc644355f74a.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.c4b347f6aa908f2d3bd5.js | AI (source-diff): Webpack bundle output, not obfuscation; standard frontend build artifact. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.d73888dd7ceba89902b9.js | AI (source-diff): Webpack bundle output, not obfuscation; standard frontend build artifact. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.bea542179e19f4f02b86.js | AI (source-diff): Webpack bundle output, not obfuscation; standard frontend build artifact. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.2a7dcb06438b5c8863b7.js | AI (source-diff): Webpack bundle output with banner; minified icon-library code, not obfuscation. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.c8816fadbf341ce44380.js | AI (source-diff): Bundled vendor libraries (node-red editor code), not a dropper/loader. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.c45dfc55df29b0837915.js | AI (source-diff): Webpack bundle output with banner; standard minified frontend bundle. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.501e64c2bcd289cbfa97.js | AI (source-diff): Webpack bundle output with banner; standard minified frontend bundle. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.d524b9913f8b4456d0b4.js | AI (source-diff): Webpack-bundled frontend output, confirmed by banner and content in sample. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.e05ab5e9ccfff8a2a975.js | AI (source-diff): Webpack-bundled frontend output, confirmed by banner and content in sample. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.25caf3f5ae028d1035af.js | AI (source-diff): Webpack bundle output, minified not obfuscated; consistent with build pipeline. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.a734e9702f6147ce4301.js | AI (source-diff): Bundled vendor chunk containing normal frontend libs (node-red UI), no exfil behavior evidenced. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.ba6ea1e8b6bb6ae022da.js | AI (source-diff): Webpack bundle output, minified not obfuscated; consistent with build pipeline. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.6c61aa69c04ff1aaee2b.js | AI (source-diff): Bundled vendor libs (keyboard layout data etc.), not obfuscation. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.2dc18973cb02434acde7.js | AI (source-diff): Vendor bundle containing Node-RED flow editor libs; no exfil destination shown. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.785d783aa1cdfb429f6a.js | AI (source-diff): Webpack setup bundle, same benign pattern as other frontend chunks. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.ec417dc2a740bef1ba05.js | AI (source-diff): Main webpack bundle for the Node-RED editor frontend. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/98.ed37d1dc158c757b67aa.js | AI (source-diff): Webpack-bundled Vue frontend chunk, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/259.c9cf9fe90bd6ef41d6d9.js | AI (source-diff): Webpack-bundled Vue frontend chunk, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/306.ec53aa095e81498d9251.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/351.3f488897707b86c5d581.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.6d008057c6f3a8b44b09.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.825f2085cab2e86df7d5.js | AI (source-diff): Webpack-bundled frontend build output, not obfuscation. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Widely-used templating lib, longstanding dependency. | ai | |
| dependencies | unvetted-dep:sequelize | AI (dependencies): Widely-used ORM, core runtime dependency of the platform. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.c307897aab382526d7a1.js | AI (source-diff): Bundled Node-RED editor vendor code, no fetched/executed remote payload. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.01ca6c48d494364afe44.js | AI (source-diff): Standard webpack setup bundle for this app. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.32a2a782772438d81ae5.js | AI (source-diff): Standard webpack main bundle for this app. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/259.33efa911be1f032af2c7.js | AI (source-diff): Webpack-bundled Vue component chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/810.59c4a89113d00fc80609.js | AI (source-diff): Webpack-bundled Vue component chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.b51b268554d861d1381b.js | AI (source-diff): Bundled node-red renderer/UI utility code, no evidence of loader/dropper behavior. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/259.5956c694df613a2c238c.js | AI (source-diff): Webpack-bundled Vue app chunk with source map; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/358.f331e13b549d4f0c2d7f.js | AI (source-diff): Bundled frontend chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.367fe8b52c4e6f46c29c.js | AI (source-diff): Bundled vendor chunk (keyboard-layout lib etc.), not obfuscation. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.5c2c541ebfc4ea4337be.js | AI (source-diff): Bundled main app chunk with source map. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.65e4a19274728311099a.js | AI (source-diff): Bundled setup app chunk with source map. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Git-ops SSL CA env passthrough for local git commands, not exfiltration. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.977d8b35e25bd87678b7.js | AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.0c7540b9b51085db2b3c.js | AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.59ef3cc2961ccaa223b2.js | AI (source-diff): Webpack-minified vendor bundle; standard build output for this package. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/351.b1db596abcd8550f2338.js | AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/306.1d909ec274be9101dbfa.js | AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.783b2aa3017faaefcc68.js | AI (source-diff): Webpack runtime loader in vendor bundle; not a dropper — standard pattern for this SPA package. | ai | |
| phantom-deps | phantom-dep:@sentry/webpack-plugin | AI (phantom-deps): Webpack plugin referenced in webpack config, not imported directly; expected pattern. | ai | |
| phantom-deps | phantom-dep:@headlessui/vue | AI (phantom-deps): Vue UI component loaded via plugin config, not direct import; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:vue3-google-login | AI (phantom-deps): Frontend plugin registered via config; consistent with this package's Vue app pattern. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/credential-provider-node | AI (phantom-deps): AWS SDK credential provider loaded by framework convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:pinia-plugin-persistedstate | AI (phantom-deps): Pinia plugin registered via config; consistent with Vue app pattern. | ai | |
| phantom-deps | phantom-dep:@flowfuse/driver-localfs | AI (phantom-deps): Same-org driver loaded dynamically by design; stable false positive. | ai | |
| phantom-deps | phantom-dep:@flowfuse/flow-renderer | AI (phantom-deps): Same-org package loaded by convention; not a phantom dep concern. | ai | |
| phantom-deps | phantom-dep:@vuepic/vue-datepicker | AI (phantom-deps): Vue component registered via plugin config; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.7e7c6737112dab660f83.js | AI (source-diff): Standard webpack setup bundle; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.b09d3709717814e4b520.js | AI (source-diff): Standard webpack main bundle; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/650.d0554ba6e443754b1548.js | AI (source-diff): Standard webpack-minified Vue frontend chunk; consistent with FlowFuse's build pipeline. | ai | |
| source-diff | net-exec-file:frontend/dist/app/vendors.6a06e499ec7c122e93f7.js | AI (source-diff): Node-RED flow renderer vendor bundle; network+eval patterns are part of the Node-RED editor, not malware. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/setup.973fea8af982fb9cd335.js | AI (source-diff): Webpack setup bundle; standard minified frontend output for FlowFuse. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/main.29b5294ab4c18d4e098a.js | AI (source-diff): Webpack main bundle; standard minified frontend output for FlowFuse. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/async-vendors.c1ff7afd926865d3a9bd.js | AI (source-diff): Webpack async vendor chunk with Heroicons SVG components; normal build artifact. | ai | |
| source-diff | obfuscated-file:frontend/dist/app/39.aabcfa36578b85cd171f.js | AI (source-diff): Standard webpack-minified Vue frontend chunk; consistent with FlowFuse's build pipeline. | ai | |
| phantom-deps | phantom-dep:echarts | AI (phantom-deps): Frontend charting dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:lottie-web-vue | AI (phantom-deps): Frontend animation dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:@heroicons/vue | AI (phantom-deps): Frontend icon dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:vue-shepherd | AI (phantom-deps): Frontend tour dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:highlight.js | AI (phantom-deps): Frontend syntax highlighting dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:vue-echarts | AI (phantom-deps): Frontend charting wrapper; stable false positive. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): Optional pino formatter loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:@sentry/vue | AI (phantom-deps): Frontend Sentry integration; stable false positive. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): Frontend routing dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Frontend sanitization dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:sqlite3 | AI (phantom-deps): DB driver loaded by convention via sequelize; stable false positive. | ai | |
| phantom-deps | phantom-dep:vuex | AI (phantom-deps): Frontend framework dep referenced in config; stable false positive. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): Config-referenced frontend dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:vue | AI (phantom-deps): Vue is a frontend framework referenced in webpack/config files; phantom-dep heuristic false positive for bundled frontend apps. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Used in install-stack.js CLI helper script — expected for a platform installer binary. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decoding of avatar identifier — benign UI feature. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decoding is part of AES-256-CTR credential decryption — legitimate crypto usage. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Used for pluggable cache driver loading — documented plugin pattern for this platform. | ai | |
| phantom-deps | phantom-dep:pinia | AI (phantom-deps): Frontend state management dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Frontend dep referenced in config; stable false positive. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 2.32.1 | 71 / 62 | |
| 2.32.0 | 71 / 61 | |
| 2.31.3 | 70 / 61 | |
| 2.31.2 | 72 / 61 | |
| 2.31.0 | 72 / 61 | |
| 2.30.1 | 71 / 60 | |
| 2.30.0 | 71 / 60 | |
| 2.29.1 | 72 / 51 | |
| 2.29.0 | 72 / 51 | |
| 2.28.1 | 71 / 51 | |
| 2.28.0 | 71 / 51 | |
| 2.27.1 | 69 / 50 | |
| 2.27.0 | 69 / 50 | |
| 2.26.2 | 69 / 50 | |
| 2.26.1 | 69 / 50 | |
| 2.26.0 | 69 / 50 | |
| 2.25.0 | 68 / 50 | |
| 2.24.5 | 68 / 50 | |
| 2.24.4 | 68 / 50 | |
| 2.24.3 | 68 / 50 | |
| 2.24.2 | 68 / 50 | |
| 2.24.1 | 68 / 50 | |
| 2.24.0 | 68 / 50 |
v2.32.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.32.0
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/FlowFuse/flowfuse/blob/fc1b7da8281750bf949fab87a9f1a8dcd7bfaa93/forge/ee/lib/gitops/backends/generic.js#L45 43 | caFile = `${workingDir}-ca.pem` 44 | await fs.writeFile(caFile, repoOptions.caCertificate) > 45 | gitEnv = { ...process.env, GIT_SSL_CAINFO: caFile } 46 | } 47 |
Spreading entire process.env into an object — may capture all secrets Source: https://github.com/FlowFuse/flowfuse/blob/fc1b7da8281750bf949fab87a9f1a8dcd7bfaa93/forge/ee/lib/gitops/backends/generic.js#L142 140 | caFile = `${workingDir}-ca.pem` 141 | await fs.writeFile(caFile, repoOptions.caCertificate) > 142 | gitEnv = { ...process.env, GIT_SSL_CAINFO: caFile } 143 | } 144 |
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.28.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-03-25, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.28.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-03-12, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.27.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-02-27, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.27.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-02-12, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.26.2
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-02-03, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.26.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.26.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.24.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.