← Home

@fluid-app/portal-sdk

SDK for building custom Fluid portals

100
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

parkerb-at-fluidparkerfluidblowmagebrs89sethfluidtingeym

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/FluidProvider-P_MBgI-c.cjs AI (source-diff): Bundled build output (long require-chain lines), not true obfuscation; code is plain widget logic. ai
source-diff obfuscated-file:dist/MessagingScreen-CsZsCnnX.cjs AI (source-diff): Bundled build output, sample shows normal React hook/component code. ai
source-diff net-exec-file:dist/FluidProvider-P_MBgI-c.cjs AI (source-diff): Bundler chunk referencing app API contexts, no dropper/loader behavior found. ai
source-diff obfuscated-file:dist/MessagingScreen-nng7xcyK.cjs AI (source-diff): Bundled build output for new Messaging feature, not obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-T7GATgZf.cjs AI (source-diff): Bundled require-chain of internal chunks, no fetched/executed remote payload. ai
source-diff obfuscated-file:dist/FluidProvider-T7GATgZf.cjs AI (source-diff): Minified bundler output (tsdown/rollup chunk), not true obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-B-6PKi1Z.mjs AI (source-diff): Bundled ESM chunk output, minified imports not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-CszrlhFR.mjs AI (source-diff): Bundled ESM chunk output for messaging UI, not obfuscation. ai
source-diff bulk-obfuscated-files:dist AI (source-diff): Bundled build output (tsdown/rollup chunks), not true obfuscation. ai
email-domain unclaimed-email:blowmage.com AI (email-domain): Hygiene issue on established SDK, not behavioral evidence of compromise. ai
source-diff bulk-net-exec-files:dist AI (source-diff): Sample shows ordinary requires/bundled code, no fetch+exec payload. ai
source-diff net-exec-file:dist/FluidProvider-D_jry4m5.cjs AI (source-diff): Network+exec pattern is normal React SDK code (fetch/query hooks), not a dropper. ai
source-diff obfuscated-file:dist/MessagingScreen-JZNWyshx.cjs AI (source-diff): Bundled build output, matches package widget structure. ai
source-diff obfuscated-file:dist/FluidProvider-D_jry4m5.cjs AI (source-diff): Minified bundler output (tsdown/esbuild require-chain), not true obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-fziXNUL8.cjs AI (source-diff): Bundled module graph; no actual network+exec malicious payload in sample. ai
source-diff obfuscated-file:dist/MessagingScreen-vGbrEL0w.mjs AI (source-diff): Bundled ESM output, same pattern as sibling chunks. ai
source-diff obfuscated-file:dist/FluidProvider-Bps-x5Rz.mjs AI (source-diff): Bundled ESM output with long import lists, not obfuscation. ai
source-diff obfuscated-file:dist/use-portal-card-add-3ds-flow-Cr6rGltD.cjs AI (source-diff): Bundled build output, standard chunked requires. ai
source-diff obfuscated-file:dist/MessagingScreen-Ch82wmzw.cjs AI (source-diff): Bundled build output, standard chunked requires. ai
source-diff obfuscated-file:dist/FluidProvider-fziXNUL8.cjs AI (source-diff): Bundled build output (tsdown/rollup chunk requires), not true obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-BqGHECjV.cjs AI (source-diff): Bundler chunk with require+network APIs used for app data fetching, no dropper behavior. ai
source-diff obfuscated-file:dist/use-portal-card-add-3ds-flow-BLmdLBnY.cjs AI (source-diff): Bundled build output, not obfuscation. ai
source-diff net-exec-file:dist/ShareablesScreen-BTa8CeWo.cjs AI (source-diff): Bundler chunk, no malicious network/exec behavior found in sample. ai
source-diff obfuscated-file:dist/ShareablesScreen-BTa8CeWo.cjs AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-BGtnLjT4.cjs AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-BqGHECjV.cjs AI (source-diff): Bundled build output, not obfuscation; legible module requires and component code. ai
source-diff net-exec-file:dist/FluidProvider-d2xkELCP.cjs AI (source-diff): require chain is bundler chunk loading, not dropper/loader behavior. ai
source-diff obfuscated-file:dist/MessagingScreen-d4E-pPU2.mjs AI (source-diff): Bundled ESM build output. ai
source-diff obfuscated-file:dist/FluidProvider-Vox9-7PR.mjs AI (source-diff): Bundled ESM build output. ai
source-diff obfuscated-file:dist/MessagingScreen-zlASVP2j.cjs AI (source-diff): Bundled build output, matches known SDK component structure. ai
source-diff obfuscated-file:dist/FluidProvider-d2xkELCP.cjs AI (source-diff): Bundled build output (tsdown/vite chunks), not true obfuscation. ai
source-diff net-exec-file:dist/ShareablesScreen-CxuFvClS.cjs AI (source-diff): Bundled app code, no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/MessagingScreen-DcJ43dZs.cjs AI (source-diff): Bundled build output, not obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-NemU6JGa.cjs AI (source-diff): Standard fetch/query code in bundled chunk, no dropper behavior. ai
source-diff obfuscated-file:dist/FluidProvider-NemU6JGa.cjs AI (source-diff): Bundled build output (tsdown/rollup chunk), not true obfuscation. ai
source-diff obfuscated-file:dist/ShareablesScreen-CxuFvClS.cjs AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/use-portal-card-add-3ds-flow-BojVWS0M.cjs AI (source-diff): Bundled build output, not obfuscation. ai
dependencies unvetted-dep:@fluid-app/portal-preview AI (dependencies): First-party monorepo sibling dependency, same publisher/org. ai
dependencies unvetted-dep:@fluid-app/widget-runtime AI (dependencies): First-party sibling package within same @fluid-app monorepo. ai
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party siblings, not external packages. ai
dependencies unvetted-dep:@fluid-app/ui-components AI (dependencies): First-party sibling package within same @fluid-app monorepo. ai
source-diff obfuscated-file:dist/FluidProvider-I5DPaIq7.cjs AI (source-diff): Bundled build output (require chain to sibling chunks), not true obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-D0O8xW76.cjs AI (source-diff): Bundled build output for messaging widget, not obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-I5DPaIq7.cjs AI (source-diff): Bundled SDK code; no concrete malicious network/exec behavior shown. ai
source-diff net-exec-file:dist/FluidProvider-CoSgK0jL.cjs AI (source-diff): Bundled UI SDK chunk requiring sibling first-party modules, not a loader/dropper. ai
source-diff obfuscated-file:dist/FluidProvider-CoSgK0jL.cjs AI (source-diff): Bundled tsdown output with long lines, not true obfuscation; matches internal SDK module graph. ai
source-diff net-exec-file:dist/FluidProvider-BLri8EGR.cjs AI (source-diff): Standard bundled require/fetch calls, no hostile network+exec behavior found. ai
source-diff obfuscated-file:dist/FluidProvider-BLri8EGR.cjs AI (source-diff): Bundled build output (tsdown/esbuild chunking), not true obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-CLcsshRX.cjs AI (source-diff): Bundled build output, matches package's widget architecture. ai
dependencies unvetted-dep:@fluid-app/messaging-ui AI (dependencies): First-party sibling package in same monorepo/org. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): Utility used via config/build tooling, common false positive. ai
dependencies unvetted-dep:@fluid-app/messaging-api-client AI (dependencies): First-party sibling package in same monorepo/org. ai
dependencies unvetted-dep:@fluid-app/portal-widgets AI (dependencies): First-party sibling package in same monorepo/org. ai
dependencies unvetted-dep:@fluid-app/messaging-core AI (dependencies): First-party sibling package in same monorepo/org. ai
dependencies unvetted-dep:@fluid-app/auth AI (dependencies): First-party sibling package in same monorepo/org. ai
dependencies unvetted-dep:@fluid-app/portal-core AI (dependencies): First-party sibling package in same monorepo/org. ai
phantom-deps phantom-dep:class-variance-authority AI (phantom-deps): Utility used via config/build tooling, common false positive. ai
phantom-deps phantom-dep:@radix-ui/react-slot AI (phantom-deps): UI lib referenced indirectly, common false positive. ai
phantom-deps phantom-dep:tailwind-merge AI (phantom-deps): Utility used via config/build tooling, common false positive. ai
phantom-deps phantom-dep:qrcode.react AI (phantom-deps): UI lib referenced indirectly, common false positive. ai
phantom-deps phantom-dep:recharts AI (phantom-deps): UI lib referenced indirectly, common false positive. ai
source-diff obfuscated-file:dist/FluidProvider-0sOzJmJn.cjs AI (source-diff): Bundled require-graph of internal widgets, not true obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-0sOzJmJn.cjs AI (source-diff): Bundled SDK code, no evidence of loader/dropper behavior. ai
source-diff net-exec-file:dist/FluidProvider-Cdz1kU5H.cjs AI (source-diff): Bundler chunk requiring sibling modules; no concrete malicious network/exec behavior shown. ai
source-diff obfuscated-file:dist/FluidProvider-Cdz1kU5H.cjs AI (source-diff): Bundled build output aggregating internal widget chunks, not true obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-lgII8Oel.cjs AI (source-diff): Bundled/minified require-graph output from tsdown build, not true obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-lgII8Oel.cjs AI (source-diff): Widget SDK bundle with normal fetch/dynamic-import, no exfil behavior shown. ai
source-diff net-exec-file:dist/FluidProvider-BYY876dq.cjs AI (source-diff): Bundled SDK code aggregating widget modules, no fetched-binary exec observed. ai
source-diff obfuscated-file:dist/FluidProvider-BYY876dq.cjs AI (source-diff): Bundled tsdown output (require-chunk pattern), not true obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-IFbNov8P.cjs AI (source-diff): Bundled tsdown output with long lines, not real obfuscation; no malicious payload in sample. ai
source-diff net-exec-file:dist/FluidProvider-IFbNov8P.cjs AI (source-diff): False positive: sample is local require() chain of bundled chunks, not network+exec dropper. ai
source-diff net-exec-file:dist/FluidProvider-BIeO1i4r.cjs AI (source-diff): Bundled SDK network client code, not a dropper/loader pattern. ai
source-diff obfuscated-file:dist/FluidProvider-BIeO1i4r.cjs AI (source-diff): Bundled require-graph output, not true obfuscation (no _0x/eval-atob/packer). ai
source-diff net-exec-file:dist/FluidProvider-DTdECylI.cjs AI (source-diff): Bundle aggregates internal widget modules; no fetched/executed payload. ai
source-diff obfuscated-file:dist/FluidProvider-DTdECylI.cjs AI (source-diff): Bundled build output (tsdown/rollup), not true obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-DXvgVTmO.cjs AI (source-diff): False positive on bundled widget-loading code, no fetched/executed payload observed. ai
source-diff obfuscated-file:dist/FluidProvider-DXvgVTmO.cjs AI (source-diff): Bundled require-chain aggregator, not true obfuscation; long lines are build output. ai
source-diff obfuscated-file:dist/FluidProvider-CMfpLju8.cjs AI (source-diff): Minified bundler output (tsdown/esbuild), not true obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-CvyQL50O.cjs AI (source-diff): Minified bundler output, not obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-CMfpLju8.cjs AI (source-diff): Bundled require chain of internal widgets, no dropper/loader behavior. ai
source-diff net-exec-file:dist/FluidProvider-CZan7yJ3.cjs AI (source-diff): Bundled component chunk; no concrete malicious network/exec behavior shown. ai
source-diff obfuscated-file:dist/FluidProvider-CZan7yJ3.cjs AI (source-diff): Bundled build chunk (tsdown/rollup require-graph), not true obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-Bc-ejPL4.cjs AI (source-diff): Bundled build output (tsdown), not true obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-k9i2ahoH.mjs AI (source-diff): Bundled ESM build output. ai
source-diff obfuscated-file:dist/FluidProvider-BeoE50u-.mjs AI (source-diff): Bundled ESM build output with long import lines. ai
source-diff obfuscated-file:dist/MessagingScreen-D_6wWdwM.cjs AI (source-diff): Bundled build output, minified chunk requires. ai
source-diff net-exec-file:dist/FluidProvider-Bc-ejPL4.cjs AI (source-diff): Bundle mixes unrelated require+fetch calls across the file, not a dropper. ai
source-diff net-exec-file:dist/FluidProvider-BFU7ermL.cjs AI (source-diff): Bundled SDK code; no fetched-binary or exfil behavior present. ai
source-diff obfuscated-file:dist/MessagingScreen-D_wVko-i.cjs AI (source-diff): Bundled build output for messaging UI module, not obfuscated. ai
source-diff obfuscated-file:dist/FluidProvider-BFU7ermL.cjs AI (source-diff): Bundled tsdown output with long require chains, not true obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-DeYSVcMd.cjs AI (source-diff): Minified bundler output, not true obfuscation; no malicious behavior in sample. ai
source-diff net-exec-file:dist/FluidProvider-Y4bOFCeb.cjs AI (source-diff): Bundled SDK code; no evidence of malicious network/exec behavior beyond normal app bundle. ai
source-diff obfuscated-file:dist/FluidProvider-Y4bOFCeb.cjs AI (source-diff): Bundled build output (tsdown/rollup chunks) with source maps, not true obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-D9zBmiaG.mjs AI (source-diff): Bundled ESM chunk, consistent with tsdown build output. ai
source-diff obfuscated-file:dist/FluidProvider-BFF-jYEi.mjs AI (source-diff): Bundled ESM chunk with source map, not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-DDvXMf79.cjs AI (source-diff): Bundled build output, matches package's normal chunked dist layout. ai
source-diff net-exec-file:dist/FluidProvider-Ca_m3XxG.cjs AI (source-diff): Sample shows only internal module requires, no fetched/executed remote code. ai
source-diff large-new-source-files AI (source-diff): Expected growth from bundler chunk splitting in an actively developed monorepo SDK. ai
source-diff obfuscated-file:dist/MessagingScreen-xdkxwXU-.cjs AI (source-diff): Bundled minified output, standard React/query imports, not obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-Ca_m3XxG.cjs AI (source-diff): Bundled minified output (tsdown/esbuild chunk), not true obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-Dgy4onF4.cjs AI (source-diff): Bundled SDK code using react-query/API clients per package purpose, not a dropper. ai
source-diff obfuscated-file:dist/MessagingScreen-CCb05_Wj.mjs AI (source-diff): Bundled ESM build output for messaging screen feature. ai
source-diff obfuscated-file:dist/FluidProvider-DV227FL2.mjs AI (source-diff): Bundled ESM build output, same provider module as cjs counterpart. ai
source-diff obfuscated-file:dist/MessagingScreen-C69BJ8Fz.cjs AI (source-diff): Bundled build output, matches package's messaging UI feature. ai
source-diff obfuscated-file:dist/FluidProvider-Dgy4onF4.cjs AI (source-diff): Bundled build output (tsdown/esbuild chunk requires), not true obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-D2ZXrmtu.cjs AI (source-diff): False positive on bundled require calls, no evidence of exfil/dropper behavior. ai
source-diff obfuscated-file:dist/use-portal-card-add-3ds-flow-Ca7Fvofg.cjs AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-Dne7NwPj.cjs AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-D2ZXrmtu.cjs AI (source-diff): Bundler-concatenated require graph, not true obfuscation; readable source. ai
source-diff obfuscated-file:dist/MessagingScreen-CkXV8WHH.cjs AI (source-diff): Standard tsdown/vite bundle output with readable source, comments, and named imports — not obfuscated. ai
source-diff obfuscated-file:dist/MessagingScreen-BaGLql5n.cjs AI (source-diff): Standard tsdown bundle output with source maps; long lines are minified but not obfuscated — readable code visible in sample. ai
source-diff obfuscated-file:dist/src-UnXevN9n.cjs AI (source-diff): Standard tsdown/rollup CJS bundle with readable source regions and known deps; not obfuscated. ai
source-diff obfuscated-file:dist/MessagingScreen-DgbNN4BF.cjs AI (source-diff): Standard tsdown/rollup CJS bundle with readable source regions and known deps; not obfuscated. ai
source-diff obfuscated-file:dist/FluidProvider-DGxCCmVB.cjs AI (source-diff): Standard Vite/tsdown bundle with readable widget imports; long lines are minified but not obfuscated. ai
source-diff obfuscated-file:dist/MessagingScreen-GLb5id9n.cjs AI (source-diff): Same build artifact pattern; readable source with React/tanstack-query imports, not malicious obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-DGxCCmVB.cjs AI (source-diff): Network calls and dynamic requires are part of the SDK's normal API client and widget loading pattern. ai
source-diff obfuscated-file:dist/MessagingScreen-8gH4_8Qn.cjs AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-CBDJKNe2.mjs AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-hXzE3QsO.mjs AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. ai
source-diff net-exec-file:dist/FluidProvider-B3i7W5r6.cjs AI (source-diff): Network calls and dynamic requires are normal React SDK bundle patterns, not dropper behavior. ai
source-diff obfuscated-file:dist/FluidProvider-B3i7W5r6.cjs AI (source-diff): Standard Vite/tsdown minified bundle output; not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-DlRwCPg8.mjs AI (source-diff): Standard Vite bundle output; sample shows readable React/ESM code, long lines are bundler artifacts. ai
source-diff obfuscated-file:dist/MessagingScreen-_-sdlwh0.cjs AI (source-diff): Standard Vite bundle output; sample shows readable React code with normal imports, not malicious obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-ClnTfJPR.mjs AI (source-diff): Standard ESM bundle output for messaging screen; not obfuscated. ai
source-diff obfuscated-file:dist/FluidProvider-CiMgrTE0.cjs AI (source-diff): Standard Vite/tsdown bundle output; long lines are minified but readable widget imports, not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-B0nvkVRJ.cjs AI (source-diff): Standard Vite/tsdown bundle output for messaging feature; not obfuscated. ai
source-diff net-exec-file:dist/FluidProvider-CiMgrTE0.cjs AI (source-diff): Network calls and dynamic requires are expected in a portal SDK provider bundle; no dropper pattern visible. ai
source-diff obfuscated-file:dist/FluidProvider-BdjVFM6g.mjs AI (source-diff): Standard ESM bundle output; long import lines are normal for bundled SDK. ai
source-diff net-exec-file:dist/FluidProvider-BAg3B4eD.cjs AI (source-diff): Network calls and dynamic requires are normal React SDK bundler patterns, not dropper behavior. ai
source-diff obfuscated-file:dist/MessagingScreen-CJ0Rj-M7.cjs AI (source-diff): Standard bundled CJS output for MessagingScreen feature; no malicious patterns. ai
source-diff obfuscated-file:dist/FluidProvider-BAg3B4eD.cjs AI (source-diff): Standard Vite/tsdown bundle output; long lines are minified but not obfuscated malware. ai
source-diff obfuscated-file:dist/MessagingScreen-0iAzXjtW.mjs AI (source-diff): Standard bundled ESM output for MessagingScreen; no malicious patterns. ai
source-diff obfuscated-file:dist/FluidProvider-C00Px_ej.mjs AI (source-diff): Standard bundled ESM output; imports are named widget/provider modules consistent with SDK structure. ai
source-diff obfuscated-file:dist/FluidProvider-BQjPCP_2.cjs AI (source-diff): Sample shows standard CJS bundler re-export wrappers, not obfuscation; consistent with tsdown build output for this SDK. ai
source-diff net-exec-file:dist/FluidProvider-BQjPCP_2.cjs AI (source-diff): Network calls and dynamic requires are part of the SDK's widget/API client architecture, not dropper behavior. ai
source-diff obfuscated-file:dist/MessagingScreen-CZddjqma.mjs AI (source-diff): Standard Vite/tsdown ESM bundle output; sample shows readable React code, not obfuscation. ai
source-diff obfuscated-file:dist/MessagingScreen-D3S230Ba.cjs AI (source-diff): Standard Vite/tsdown CJS bundle output; sample shows readable React code, not obfuscation. ai
source-diff obfuscated-file:dist/FluidProvider-C9DPE1F0.cjs AI (source-diff): Long lines are Vite/tsdown CJS bundle barrel requires, not obfuscation. Stable pattern for this build toolchain. ai
source-diff net-exec-file:dist/FluidProvider-C9DPE1F0.cjs AI (source-diff): Network calls and dynamic requires in a portal SDK bundle are expected; no dropper pattern visible in sample. ai
source-diff obfuscated-file:dist/MessagingScreen-CwzSY_G8.mjs AI (source-diff): Standard tsdown/Vite bundle output; samples show readable React code, not obfuscation. ai
phantom-deps phantom-dep:use-sync-external-store AI (phantom-deps): Bundled transitive dep; phantom-dep false positive for this package. ai
source-diff obfuscated-file:dist/MessagingScreen-2M2ETWXp.cjs AI (source-diff): Standard tsdown/Vite bundle output; samples show readable React code, not obfuscation. ai
phantom-deps phantom-dep:tw-animate-css AI (phantom-deps): CSS-only package; not imported via JS but used via config/CSS — phantom-dep heuristic is a stable false positive here. ai
phantom-deps phantom-dep:embla-carousel-react AI (phantom-deps): Carousel lib likely consumed via re-export or config; phantom-dep heuristic is a stable false positive for this SDK. ai
source-diff obfuscated-file:dist/MessagingScreen-CCbgNRp1.cjs AI (source-diff): Standard Vite/tsdown bundle output; long lines from minification, not obfuscation. Code is fully readable in sample. ai

Versions (showing 100 of 335)

Version Deps Published
0.1.254 10 / 67
0.1.253 10 / 67
0.1.252 10 / 67
0.1.251 10 / 67
0.1.250 10 / 67
0.1.249 10 / 67
0.1.244 10 / 63
0.1.243 10 / 63
0.1.242 10 / 63
0.1.241 10 / 63
0.1.240 10 / 63
0.1.239 10 / 63
0.1.238 10 / 63
0.1.237 10 / 63
0.1.236 10 / 63
0.1.235 10 / 63
0.1.234 10 / 63
0.1.233 10 / 63
0.1.232 10 / 63
0.1.231 10 / 63
0.1.230 10 / 63
0.1.229 10 / 63
0.1.228 10 / 63
0.1.227 10 / 63
0.1.226 10 / 63
0.1.225 10 / 63
0.1.224 10 / 63
0.1.223 10 / 63
0.1.222 10 / 63
0.1.221 10 / 63
0.1.220 10 / 63
0.1.219 10 / 63
0.1.218 10 / 63
0.1.217 10 / 63
0.1.216 10 / 63
0.1.215 10 / 63
0.1.214 10 / 63
0.1.213 10 / 63
0.1.212 10 / 63
0.1.211 10 / 63
0.1.210 10 / 63
0.1.209 10 / 63
0.1.208 10 / 63
0.1.207 10 / 63
0.1.206 10 / 63
0.1.205 10 / 63
0.1.204 10 / 63
0.1.203 10 / 63
0.1.202 10 / 63
0.1.201 10 / 63
0.1.200 10 / 63
0.1.199 10 / 63
0.1.198 10 / 63
0.1.197 10 / 63
0.1.196 10 / 63
0.1.195 10 / 63
0.1.194 10 / 63
0.1.193 10 / 63
0.1.192 10 / 63
0.1.191 10 / 63
0.1.190 10 / 63
0.1.189 10 / 63
0.1.188 10 / 63
0.1.187 10 / 63
0.1.186 10 / 63
0.1.185 10 / 63
0.1.184 10 / 63
0.1.183 10 / 63
0.1.182 10 / 63
0.1.181 10 / 63
0.1.180 10 / 63
0.1.179 10 / 63
0.1.178 10 / 63
0.1.177 10 / 63
0.1.176 10 / 63
0.1.175 10 / 62
0.1.174 10 / 65
0.1.173 10 / 65
0.1.172 10 / 65
0.1.171 10 / 65
0.1.170 10 / 65
0.1.169 10 / 65
0.1.168 10 / 65
0.1.167 10 / 65
0.1.166 10 / 65
0.1.165 10 / 65
0.1.164 10 / 65
0.1.163 10 / 65
0.1.162 10 / 65
0.1.161 10 / 65
0.1.160 10 / 65
0.1.159 10 / 65
0.1.158 10 / 66
0.1.157 10 / 66
0.1.156 10 / 66
0.1.155 10 / 66
0.1.154 10 / 66
0.1.153 10 / 66
0.1.152 10 / 65
0.1.151 10 / 65
Showing 100 of 335 Next page →

v0.1.254

3 findings
HIGH New obfuscated file: dist/FluidProvider-IFbNov8P.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/FluidProvider-IFbNov8P.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.253

4 findings
HIGH New obfuscated file: dist/FluidProvider-BLri8EGR.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/FluidProvider-BLri8EGR.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/MessagingScreen-CLcsshRX.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.252

4 findings
HIGH New obfuscated file: dist/FluidProvider-Ca_m3XxG.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/FluidProvider-Ca_m3XxG.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/MessagingScreen-xdkxwXU-.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.249

2 findings
HIGH New obfuscated file: dist/MessagingScreen-DeYSVcMd.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.239

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.238

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.235

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.234

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.233

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.232

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.231

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.230

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.229

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.228

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.227

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.226

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.225

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.224

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.223

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.222

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.221

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.220

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.219

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.218

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.217

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.216

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.215

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.214

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.213

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.212

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.211

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.210

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.209

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.208

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.207

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.206

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.205

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.204

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.203

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.202

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.201

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.200

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.199

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.198

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.197

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.196

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.195

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.194

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.193

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.192

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.191

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.190

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.189

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.188

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.187

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.186

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.185

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.184

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.183

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.182

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.181

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.180

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.179

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.178

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.177

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.176

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.175

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.174

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.173

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.172

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.171

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.170

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.169

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.168

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.167

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.166

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.165

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.164

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.163

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.162

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.161

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.160

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.159

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.158

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.157

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.156

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.155

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.154

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.153

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.152

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.151

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.