← Home

@flowfuse/flowfuse

An open source low-code development platform

23
Versions
SEE LICENSE IN ./LICENSE
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

hardillbknollearyflowfuse-user

Keywords

low-code-platformlow-code-developmentlow-code-development-platformvisual-programmingflow-based-programmingno-codelow-codenode-red

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:frontend/dist/app/main.1729015ac167af1b6578.js AI (source-diff): Webpack bundler output for frontend build, not true obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/setup.ec2e6b57e5d059b45675.js AI (source-diff): Webpack bundler output for frontend build, not true obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/setup.34c244b6b4f8a832f366.js AI (source-diff): Webpack-bundled setup wizard chunk; same icon/module pattern. ai
source-diff net-exec-file:frontend/dist/app/vendors.f946515216b240b0054b.js AI (source-diff): Vendor bundle containing node-red flow-renderer + HTTP client libs, not a dropper. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.16bdf45a1691a23e86f3.js AI (source-diff): Webpack-bundled frontend asset; sample shows benign SVG icon components. ai
source-diff obfuscated-file:frontend/dist/app/main.1cdec14f12421ceac108.js AI (source-diff): Webpack-bundled frontend main entry; standard module resolution code. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.c7665d54f260de0c87a9.js AI (source-diff): Webpack bundle output for frontend app, not obfuscation. ai
source-diff net-exec-file:frontend/dist/app/vendors.bfc0b7c3f0b912f18c3f.js AI (source-diff): Bundled Node-RED editor vendor code; no exfil behavior evident. ai
source-diff obfuscated-file:frontend/dist/app/setup.8b73a2e88c0ffad342c9.js AI (source-diff): Webpack bundle output for frontend app, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/main.46b3e1b57f79ca894b4d.js AI (source-diff): Webpack bundle output for frontend app, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/main.740697272a8a60025a8a.js AI (source-diff): Webpack-bundled frontend asset, minified not obfuscated. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.2c5ee6925b6e42222078.js AI (source-diff): Webpack-bundled frontend asset, minified not obfuscated. ai
source-diff net-exec-file:frontend/dist/app/vendors.164857397e7eac984cd5.js AI (source-diff): Bundled Node-RED editor vendor code, no exfil behavior observed. ai
source-diff obfuscated-file:frontend/dist/app/setup.ad5f7ce700707c0c5fa5.js AI (source-diff): Webpack-bundled frontend asset, minified not obfuscated. ai
source-diff obfuscated-file:frontend/dist/app/setup.a410d7f125349d4e6a73.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/main.fa95294cc8c0adb1ddab.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/main.204025873ddf29846309.js AI (source-diff): Webpack bundle output, standard build artifact for this large frontend app. ai
maintainer-change maintainer-added AI (maintainer-change): flowfuse-user is a known maintainer per provenance record, matches prior approved history. ai
source-diff obfuscated-file:frontend/dist/app/setup.b7d5ad7760e411b664b4.js AI (source-diff): Webpack bundle output, standard build artifact for this large frontend app. ai
source-diff net-exec-file:frontend/dist/app/vendors.c21524f6d4c01a6a54f1.js AI (source-diff): Bundled vendor code (Node-RED flow editor deps) with LICENSE.txt banner, not a dropper. ai
source-diff net-exec-file:frontend/dist/app/vendors.90a7f5b0c1e056dda76c.js AI (source-diff): Bundled vendor JS (Node-RED editor UI libs), not a dropper. ai
source-diff obfuscated-file:frontend/dist/app/setup.94dc2e6b50c9da19cacf.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/main.0035fbe0d465917e8a17.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.6bdc9078fc644355f74a.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/setup.c4b347f6aa908f2d3bd5.js AI (source-diff): Webpack bundle output, not obfuscation; standard frontend build artifact. ai
source-diff obfuscated-file:frontend/dist/app/main.d73888dd7ceba89902b9.js AI (source-diff): Webpack bundle output, not obfuscation; standard frontend build artifact. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.bea542179e19f4f02b86.js AI (source-diff): Webpack bundle output, not obfuscation; standard frontend build artifact. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.2a7dcb06438b5c8863b7.js AI (source-diff): Webpack bundle output with banner; minified icon-library code, not obfuscation. ai
source-diff net-exec-file:frontend/dist/app/vendors.c8816fadbf341ce44380.js AI (source-diff): Bundled vendor libraries (node-red editor code), not a dropper/loader. ai
source-diff obfuscated-file:frontend/dist/app/setup.c45dfc55df29b0837915.js AI (source-diff): Webpack bundle output with banner; standard minified frontend bundle. ai
source-diff obfuscated-file:frontend/dist/app/main.501e64c2bcd289cbfa97.js AI (source-diff): Webpack bundle output with banner; standard minified frontend bundle. ai
source-diff obfuscated-file:frontend/dist/app/setup.d524b9913f8b4456d0b4.js AI (source-diff): Webpack-bundled frontend output, confirmed by banner and content in sample. ai
source-diff obfuscated-file:frontend/dist/app/main.e05ab5e9ccfff8a2a975.js AI (source-diff): Webpack-bundled frontend output, confirmed by banner and content in sample. ai
source-diff obfuscated-file:frontend/dist/app/setup.25caf3f5ae028d1035af.js AI (source-diff): Webpack bundle output, minified not obfuscated; consistent with build pipeline. ai
source-diff net-exec-file:frontend/dist/app/vendors.a734e9702f6147ce4301.js AI (source-diff): Bundled vendor chunk containing normal frontend libs (node-red UI), no exfil behavior evidenced. ai
source-diff obfuscated-file:frontend/dist/app/main.ba6ea1e8b6bb6ae022da.js AI (source-diff): Webpack bundle output, minified not obfuscated; consistent with build pipeline. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.6c61aa69c04ff1aaee2b.js AI (source-diff): Bundled vendor libs (keyboard layout data etc.), not obfuscation. ai
source-diff net-exec-file:frontend/dist/app/vendors.2dc18973cb02434acde7.js AI (source-diff): Vendor bundle containing Node-RED flow editor libs; no exfil destination shown. ai
source-diff obfuscated-file:frontend/dist/app/setup.785d783aa1cdfb429f6a.js AI (source-diff): Webpack setup bundle, same benign pattern as other frontend chunks. ai
source-diff obfuscated-file:frontend/dist/app/main.ec417dc2a740bef1ba05.js AI (source-diff): Main webpack bundle for the Node-RED editor frontend. ai
source-diff obfuscated-file:frontend/dist/app/98.ed37d1dc158c757b67aa.js AI (source-diff): Webpack-bundled Vue frontend chunk, not obfuscated malware. ai
source-diff obfuscated-file:frontend/dist/app/259.c9cf9fe90bd6ef41d6d9.js AI (source-diff): Webpack-bundled Vue frontend chunk, not obfuscated malware. ai
source-diff obfuscated-file:frontend/dist/app/306.ec53aa095e81498d9251.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/351.3f488897707b86c5d581.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/main.6d008057c6f3a8b44b09.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/setup.825f2085cab2e86df7d5.js AI (source-diff): Webpack-bundled frontend build output, not obfuscation. ai
dependencies unvetted-dep:handlebars AI (dependencies): Widely-used templating lib, longstanding dependency. ai
dependencies unvetted-dep:sequelize AI (dependencies): Widely-used ORM, core runtime dependency of the platform. ai
source-diff net-exec-file:frontend/dist/app/vendors.c307897aab382526d7a1.js AI (source-diff): Bundled Node-RED editor vendor code, no fetched/executed remote payload. ai
source-diff obfuscated-file:frontend/dist/app/setup.01ca6c48d494364afe44.js AI (source-diff): Standard webpack setup bundle for this app. ai
source-diff obfuscated-file:frontend/dist/app/main.32a2a782772438d81ae5.js AI (source-diff): Standard webpack main bundle for this app. ai
source-diff obfuscated-file:frontend/dist/app/259.33efa911be1f032af2c7.js AI (source-diff): Webpack-bundled Vue component chunk, not true obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/810.59c4a89113d00fc80609.js AI (source-diff): Webpack-bundled Vue component chunk, not true obfuscation. ai
source-diff net-exec-file:frontend/dist/app/vendors.b51b268554d861d1381b.js AI (source-diff): Bundled node-red renderer/UI utility code, no evidence of loader/dropper behavior. ai
source-diff obfuscated-file:frontend/dist/app/259.5956c694df613a2c238c.js AI (source-diff): Webpack-bundled Vue app chunk with source map; minified build output, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/358.f331e13b549d4f0c2d7f.js AI (source-diff): Bundled frontend chunk, not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.367fe8b52c4e6f46c29c.js AI (source-diff): Bundled vendor chunk (keyboard-layout lib etc.), not obfuscation. ai
source-diff obfuscated-file:frontend/dist/app/main.5c2c541ebfc4ea4337be.js AI (source-diff): Bundled main app chunk with source map. ai
source-diff obfuscated-file:frontend/dist/app/setup.65e4a19274728311099a.js AI (source-diff): Bundled setup app chunk with source map. ai
semgrep semgrep:env-spread AI (semgrep): Git-ops SSL CA env passthrough for local git commands, not exfiltration. ai
source-diff obfuscated-file:frontend/dist/app/setup.977d8b35e25bd87678b7.js AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. ai
source-diff obfuscated-file:frontend/dist/app/main.0c7540b9b51085db2b3c.js AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.59ef3cc2961ccaa223b2.js AI (source-diff): Webpack-minified vendor bundle; standard build output for this package. ai
source-diff obfuscated-file:frontend/dist/app/351.b1db596abcd8550f2338.js AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. ai
source-diff obfuscated-file:frontend/dist/app/306.1d909ec274be9101dbfa.js AI (source-diff): Webpack-minified frontend chunk; standard build output for this package. ai
source-diff net-exec-file:frontend/dist/app/vendors.783b2aa3017faaefcc68.js AI (source-diff): Webpack runtime loader in vendor bundle; not a dropper — standard pattern for this SPA package. ai
phantom-deps phantom-dep:@sentry/webpack-plugin AI (phantom-deps): Webpack plugin referenced in webpack config, not imported directly; expected pattern. ai
phantom-deps phantom-dep:@headlessui/vue AI (phantom-deps): Vue UI component loaded via plugin config, not direct import; stable pattern for this package. ai
phantom-deps phantom-dep:vue3-google-login AI (phantom-deps): Frontend plugin registered via config; consistent with this package's Vue app pattern. ai
phantom-deps phantom-dep:@aws-sdk/credential-provider-node AI (phantom-deps): AWS SDK credential provider loaded by framework convention; stable false positive. ai
phantom-deps phantom-dep:pinia-plugin-persistedstate AI (phantom-deps): Pinia plugin registered via config; consistent with Vue app pattern. ai
phantom-deps phantom-dep:@flowfuse/driver-localfs AI (phantom-deps): Same-org driver loaded dynamically by design; stable false positive. ai
phantom-deps phantom-dep:@flowfuse/flow-renderer AI (phantom-deps): Same-org package loaded by convention; not a phantom dep concern. ai
phantom-deps phantom-dep:@vuepic/vue-datepicker AI (phantom-deps): Vue component registered via plugin config; stable false positive for this package. ai
source-diff obfuscated-file:frontend/dist/app/setup.7e7c6737112dab660f83.js AI (source-diff): Standard webpack setup bundle; minification is expected for this package. ai
source-diff obfuscated-file:frontend/dist/app/main.b09d3709717814e4b520.js AI (source-diff): Standard webpack main bundle; minification is expected for this package. ai
source-diff obfuscated-file:frontend/dist/app/650.d0554ba6e443754b1548.js AI (source-diff): Standard webpack-minified Vue frontend chunk; consistent with FlowFuse's build pipeline. ai
source-diff net-exec-file:frontend/dist/app/vendors.6a06e499ec7c122e93f7.js AI (source-diff): Node-RED flow renderer vendor bundle; network+eval patterns are part of the Node-RED editor, not malware. ai
source-diff obfuscated-file:frontend/dist/app/setup.973fea8af982fb9cd335.js AI (source-diff): Webpack setup bundle; standard minified frontend output for FlowFuse. ai
source-diff obfuscated-file:frontend/dist/app/main.29b5294ab4c18d4e098a.js AI (source-diff): Webpack main bundle; standard minified frontend output for FlowFuse. ai
source-diff obfuscated-file:frontend/dist/app/async-vendors.c1ff7afd926865d3a9bd.js AI (source-diff): Webpack async vendor chunk with Heroicons SVG components; normal build artifact. ai
source-diff obfuscated-file:frontend/dist/app/39.aabcfa36578b85cd171f.js AI (source-diff): Standard webpack-minified Vue frontend chunk; consistent with FlowFuse's build pipeline. ai
phantom-deps phantom-dep:echarts AI (phantom-deps): Frontend charting dep; stable false positive. ai
phantom-deps phantom-dep:lottie-web-vue AI (phantom-deps): Frontend animation dep; stable false positive. ai
phantom-deps phantom-dep:@heroicons/vue AI (phantom-deps): Frontend icon dep; stable false positive. ai
phantom-deps phantom-dep:vue-shepherd AI (phantom-deps): Frontend tour dep; stable false positive. ai
phantom-deps phantom-dep:highlight.js AI (phantom-deps): Frontend syntax highlighting dep; stable false positive. ai
phantom-deps phantom-dep:vue-echarts AI (phantom-deps): Frontend charting wrapper; stable false positive. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): Optional pino formatter loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@sentry/vue AI (phantom-deps): Frontend Sentry integration; stable false positive. ai
phantom-deps phantom-dep:vue-router AI (phantom-deps): Frontend routing dep; stable false positive. ai
phantom-deps phantom-dep:dompurify AI (phantom-deps): Frontend sanitization dep; stable false positive. ai
phantom-deps phantom-dep:sqlite3 AI (phantom-deps): DB driver loaded by convention via sequelize; stable false positive. ai
phantom-deps phantom-dep:vuex AI (phantom-deps): Frontend framework dep referenced in config; stable false positive. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Config-referenced frontend dep; stable false positive for this package. ai
phantom-deps phantom-dep:vue AI (phantom-deps): Vue is a frontend framework referenced in webpack/config files; phantom-dep heuristic false positive for bundled frontend apps. ai
semgrep semgrep:child-process-import AI (semgrep): Used in install-stack.js CLI helper script — expected for a platform installer binary. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding of avatar identifier — benign UI feature. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decoding is part of AES-256-CTR credential decryption — legitimate crypto usage. ai
semgrep semgrep:dynamic-require AI (semgrep): Used for pluggable cache driver loading — documented plugin pattern for this platform. ai
phantom-deps phantom-dep:pinia AI (phantom-deps): Frontend state management dep; stable false positive. ai
phantom-deps phantom-dep:marked AI (phantom-deps): Frontend dep referenced in config; stable false positive. ai

Versions (showing 23 of 23)

Version Deps Published
2.32.1 71 / 62
2.32.0 71 / 61
2.31.3 70 / 61
2.31.2 72 / 61
2.31.0 72 / 61
2.30.1 71 / 60
2.30.0 71 / 60
2.29.1 72 / 51
2.29.0 72 / 51
2.28.1 71 / 51
2.28.0 71 / 51
2.27.1 69 / 50
2.27.0 69 / 50
2.26.2 69 / 50
2.26.1 69 / 50
2.26.0 69 / 50
2.25.0 68 / 50
2.24.5 68 / 50
2.24.4 68 / 50
2.24.3 68 / 50
2.24.2 68 / 50
2.24.1 68 / 50
2.24.0 68 / 50

v2.32.1

7 findings
HIGH New obfuscated file: frontend/dist/app/259.c9cf9fe90bd6ef41d6d9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/98.ed37d1dc158c757b67aa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/async-vendors.6c61aa69c04ff1aaee2b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.ec417dc2a740bef1ba05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.785d783aa1cdfb429f6a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.2dc18973cb02434acde7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.32.0

9 findings
HIGH New obfuscated file: frontend/dist/app/259.5956c694df613a2c238c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: frontend/dist/app/358.f331e13b549d4f0c2d7f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: frontend/dist/app/async-vendors.367fe8b52c4e6f46c29c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: frontend/dist/app/main.5c2c541ebfc4ea4337be.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: frontend/dist/app/setup.65e4a19274728311099a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: frontend/dist/app/vendors.b51b268554d861d1381b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH env-spread: forge/ee/lib/gitops/backends/generic.js:45 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/FlowFuse/flowfuse/blob/fc1b7da8281750bf949fab87a9f1a8dcd7bfaa93/forge/ee/lib/gitops/backends/generic.js#L45 43 | caFile = `${workingDir}-ca.pem` 44 | await fs.writeFile(caFile, repoOptions.caCertificate) > 45 | gitEnv = { ...process.env, GIT_SSL_CAINFO: caFile } 46 | } 47 |

HIGH env-spread: forge/ee/lib/gitops/backends/generic.js:142 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/FlowFuse/flowfuse/blob/fc1b7da8281750bf949fab87a9f1a8dcd7bfaa93/forge/ee/lib/gitops/backends/generic.js#L142 140 | caFile = `${workingDir}-ca.pem` 141 | await fs.writeFile(caFile, repoOptions.caCertificate) > 142 | gitEnv = { ...process.env, GIT_SSL_CAINFO: caFile } 143 | } 144 |

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.28.1

6 findings
HIGH New obfuscated file: frontend/dist/app/async-vendors.2a7dcb06438b5c8863b7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.501e64c2bcd289cbfa97.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.c45dfc55df29b0837915.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.c8816fadbf341ce44380.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hardillb → flowfuse-user (on 2026-03-25, known maintainer) provenance

This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-03-25, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.28.0

6 findings
HIGH New obfuscated file: frontend/dist/app/async-vendors.2a7dcb06438b5c8863b7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.204025873ddf29846309.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.b7d5ad7760e411b664b4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.c21524f6d4c01a6a54f1.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hardillb → flowfuse-user (on 2026-03-12, known maintainer) provenance

This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-03-12, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.27.1

6 findings
HIGH New obfuscated file: frontend/dist/app/async-vendors.2c5ee6925b6e42222078.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.740697272a8a60025a8a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.ad5f7ce700707c0c5fa5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.164857397e7eac984cd5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hardillb → flowfuse-user (on 2026-02-27, known maintainer) provenance

This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-02-27, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.27.0

6 findings
HIGH New obfuscated file: frontend/dist/app/async-vendors.c7665d54f260de0c87a9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.46b3e1b57f79ca894b4d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.8b73a2e88c0ffad342c9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.bfc0b7c3f0b912f18c3f.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hardillb → flowfuse-user (on 2026-02-12, known maintainer) provenance

This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-02-12, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.26.2

6 findings
HIGH New obfuscated file: frontend/dist/app/async-vendors.6bdc9078fc644355f74a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.0035fbe0d465917e8a17.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.94dc2e6b50c9da19cacf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.90a7f5b0c1e056dda76c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: hardillb → flowfuse-user (on 2026-02-03, known maintainer) provenance

This version was published by a different npm account (flowfuse-user) than the most recent previously approved version (hardillb) on 2026-02-03, but flowfuse-user is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.26.1

5 findings
HIGH New obfuscated file: frontend/dist/app/async-vendors.bea542179e19f4f02b86.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.d73888dd7ceba89902b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.c4b347f6aa908f2d3bd5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.a734e9702f6147ce4301.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.26.0

4 findings
HIGH New obfuscated file: frontend/dist/app/main.ba6ea1e8b6bb6ae022da.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.25caf3f5ae028d1035af.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.a734e9702f6147ce4301.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.25.0

3 findings
HIGH New obfuscated file: frontend/dist/app/main.e05ab5e9ccfff8a2a975.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.d524b9913f8b4456d0b4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.24.5

3 findings
HIGH New obfuscated file: frontend/dist/app/main.1729015ac167af1b6578.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.ec2e6b57e5d059b45675.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.24.4

3 findings
HIGH New obfuscated file: frontend/dist/app/main.fa95294cc8c0adb1ddab.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.a410d7f125349d4e6a73.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.24.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.24.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.24.1

5 findings
HIGH New obfuscated file: frontend/dist/app/async-vendors.16bdf45a1691a23e86f3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/main.1cdec14f12421ceac108.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: frontend/dist/app/setup.34c244b6b4f8a832f366.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: frontend/dist/app/vendors.f946515216b240b0054b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.