← Home

@forsakringskassan/docs-generator

Documentation generator

48
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

extfk-jonatan-haqgglundtomasbjerreoloff

Keywords

documentation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/vendor-DV7BHNMM.mjs AI (source-diff): Bundled vendor chunk from build tooling (vue-docgen-api/babel), not a loader/dropper. ai
source-diff net-exec-file:dist/vendor-DWCXj2K2.mjs AI (source-diff): Bundled vendor chunk (bundler output) with node builtin imports, not a malicious dropper. ai
source-diff net-exec-file:dist/vendor-DjC7coI1.mjs AI (source-diff): Bundled vendor chunk with generic Node builtin imports; no concrete exfil/exec payload shown. ai
source-diff net-exec-file:dist/vendor-DO1GigtJ.mjs AI (source-diff): Bundled vendor chunk with node builtin imports; pattern matches bundler output, not a dropper. ai
source-diff net-exec-file:dist/vendor-B-ki54MB.mjs AI (source-diff): Bundled vendor chunk using Node builtins (fs/http/tls) for docgen tooling; no malicious payload evidenced. ai
source-diff net-exec-file:dist/vendor-DgbU8VP_.mjs AI (source-diff): Bundled build output of legit deps (vue-docgen-api etc.), no obfuscation/malicious payload. ai
source-diff net-exec-file:dist/vendor-BnFYrp5U.mjs AI (source-diff): Bundled vendor chunk with stdlib imports, not a loader/dropper; expected bundler output. ai
source-diff net-exec-file:dist/vendor-BK-uA6Uv.mjs AI (source-diff): Bundled vendor chunk with node-builtin imports for build tooling deps, not a loader/dropper payload. ai
source-diff net-exec-file:dist/vendor-Bk5vSW_n.mjs AI (source-diff): Bundled vendor chunk (rollup/vite output) with node builtins, not a loader/dropper. ai
source-diff net-exec-file:dist/vendor-Cgx8NlVP.mjs AI (source-diff): Bundled vendor chunk with Node builtin imports; build output, not a dropper. ai
source-diff net-exec-file:dist/vendor-DMxJoCDS.mjs AI (source-diff): Bundled vendor chunk with core-module imports; no concrete malicious behavior in sample. ai
source-diff net-exec-file:dist/vendor-Q6b0E6UP.mjs AI (source-diff): Bundled vendor chunk (rollup/vite output) with Node builtin imports, not a loader/dropper. ai
source-diff net-exec-file:dist/vendor-BPf0gRBB.mjs AI (source-diff): Bundled vendor chunk containing standard fs/network Node builtins, not a dropper/loader. ai
source-diff net-exec-file:dist/vendor-CMa7Qsb1.mjs AI (source-diff): Bundled vendor chunk with node builtin imports for docs generator, not a dropper/loader. ai
source-diff net-exec-file:dist/vendor-BAYn8diL.mjs AI (source-diff): Bundled vendor chunk with node builtin imports; build artifact, not injected malware. ai
source-diff net-exec-file:dist/vendor-ClKMZWQO.mjs AI (source-diff): Bundled vendor chunk with node builtin imports, not a dropper; standard bundler output. ai
source-diff net-exec-file:dist/vendor-Ct1QNfWX.mjs AI (source-diff): Bundled vendor chunk with Node builtin imports; build output, not a dropper. ai
source-diff net-exec-file:dist/vendor-D4BVkQg8.mjs AI (source-diff): Bundled vendor chunk (rollup output) with Node builtins, not a loader/dropper; consistent with docs tooling. ai
source-diff net-exec-file:dist/vendor-DR1Vkbzf.mjs AI (source-diff): Bundled vendor chunk with standard Node builtin imports, not a loader/dropper. ai
source-diff net-exec-file:dist/vendor-KZo5HqAF.mjs AI (source-diff): Bundled vendor chunk from build tooling, not injected malicious code. ai
maintainer-change maintainer-added AI (maintainer-change): Consistent with legitimate CI/CD provenance-attested publish pipeline. ai
source-diff net-exec-file:dist/vendor-Dd3EDAs1.mjs AI (source-diff): Bundled vendor chunk with Node core imports (http/fs/etc), not a dropper; standard bundler output. ai
source-diff net-exec-file:dist/vendor-BtGCZQy4.mjs AI (source-diff): Bundled vendor chunk with Node builtin imports, not a dropper; large rollup bundle for docs tooling. ai
source-diff net-exec-file:dist/vendor-s-84ehgc.mjs AI (source-diff): Bundled vendor chunk with node builtins/network+eval APIs from transitive deps, not a loader/dropper. ai
source-diff net-exec-file:dist/vendor-BVmnvb-f.mjs AI (source-diff): Bundled vendor chunk with standard Node builtin imports, not a dropper; consistent with docs tool bundling babel/vue-docgen deps. ai
source-diff net-exec-file:dist/vendor-DLyCCfC4.mjs AI (source-diff): Large bundled vendor file with source map; imports are standard Node built-ins consistent with a docs generator tool, not malware. ai
source-diff net-exec-file:dist/vendor-CyiP4ufo.mjs AI (source-diff): Vite-bundled vendor chunk for a docs generator; Node built-in imports are expected, not dropper behavior. ai
source-diff net-exec-file:dist/vendor-C0JAkCK-.mjs AI (source-diff): Large Vite/Rollup vendor bundle for a docs-generator tool; Node built-in imports are expected, not malicious. ai
source-diff net-exec-file:dist/vendor-B7bJ2okl.mjs AI (source-diff): Standard Vite/Rollup vendor bundle; network imports are Node built-ins (http/https), not external fetches. Pattern is stable for this docs-generator package. ai
source-diff net-exec-file:dist/vendor-BoRn-ubH.mjs AI (source-diff): Vite-bundled vendor chunk for a docs-generator; network imports are livereload/dev-server tooling, not dropper behavior. SLSA provenance confirms CI build. ai
source-diff net-exec-file:dist/vendor-DX88DJvo.mjs AI (source-diff): Large vendor bundle is standard Vite/Rollup output for a docs-generator; node built-in imports are expected, not malicious. ai
source-diff net-exec-file:dist/vendor-BhMQq6vU.mjs AI (source-diff): Large vendor bundle from Vite/Rollup build; imports are Node built-ins consistent with docs-generator tooling, not malware. ai
phantom-deps phantom-dep:@fontsource-variable/inter AI (phantom-deps): Font asset referenced in build config, not directly imported in JS — stable false positive. ai
phantom-deps phantom-dep:livereload-js AI (phantom-deps): Asset dependency referenced in build config, not directly imported in JS — stable false positive. ai
publish-pattern dormant-publish AI (publish-pattern): Package has 145 versions and SLSA provenance; dormancy flag is a false positive for this active project. ai
source-diff net-exec-file:dist/vendor-tIJeYoyt.mjs AI (source-diff): Standard Vite vendor bundle for a docs-generator; imports are Node built-ins and bundled deps, not malware. ai

Versions (showing 48 of 48)

Version Deps Published
3.3.1 9 / 0
3.3.0 9 / 0
3.2.0 9 / 0
3.1.2 9 / 0
3.1.1 9 / 0
3.1.0 9 / 0
3.0.4 9 / 0
3.0.3 9 / 0
3.0.2 9 / 0
3.0.1 9 / 0
3.0.0 9 / 0
2.43.0 9 / 0
2.42.0 7 / 0
2.41.1 7 / 0
2.41.0 7 / 0
2.40.3 7 / 0
2.40.2 7 / 0
2.40.1 7 / 0
2.40.0 7 / 0
2.39.3 7 / 0
2.39.2 7 / 0
2.39.1 7 / 0
2.39.0 7 / 0
2.38.6 7 / 0
2.38.5 7 / 0
2.38.4 7 / 0
2.38.3 7 / 0
2.38.2 7 / 0
2.38.1 7 / 0
2.38.0 7 / 0
2.37.1 7 / 0
2.37.0 7 / 0
2.36.0 7 / 0
2.35.8 7 / 0
2.35.7 7 / 0
2.35.6 7 / 0
2.35.5 7 / 0
2.35.4 7 / 0
2.35.3 7 / 0
2.35.2 7 / 0
2.35.1 7 / 0
2.35.0 7 / 0
2.34.0 7 / 0
2.33.1 7 / 0
2.33.0 7 / 0
2.32.2 7 / 0
2.32.1 7 / 0
2.32.0 7 / 0

v3.3.1

2 findings
HIGH New file with network + code execution: dist/vendor-DjC7coI1.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.39.3

3 findings
HIGH New file with network + code execution: dist/vendor-KZo5HqAF.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.39.2

3 findings
HIGH New file with network + code execution: dist/vendor-KZo5HqAF.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-25, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-25, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.39.1

3 findings
HIGH New file with network + code execution: dist/vendor-KZo5HqAF.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-25, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-25, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.39.0

3 findings
HIGH New file with network + code execution: dist/vendor-B-ki54MB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.38.6

3 findings
HIGH New file with network + code execution: dist/vendor-DgbU8VP_.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.38.5

3 findings
HIGH New file with network + code execution: dist/vendor-BnFYrp5U.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.38.4

3 findings
HIGH New file with network + code execution: dist/vendor-BnFYrp5U.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.38.3

3 findings
HIGH New file with network + code execution: dist/vendor-BK-uA6Uv.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.38.2

3 findings
HIGH New file with network + code execution: dist/vendor-BK-uA6Uv.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.38.1

3 findings
HIGH New file with network + code execution: dist/vendor-BK-uA6Uv.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.38.0

3 findings
HIGH New file with network + code execution: dist/vendor-DV7BHNMM.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-06, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.37.1

3 findings
HIGH New file with network + code execution: dist/vendor-Bk5vSW_n.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.37.0

3 findings
HIGH New file with network + code execution: dist/vendor-Cgx8NlVP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-02-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.36.0

3 findings
HIGH New file with network + code execution: dist/vendor-BVmnvb-f.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-02-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.8

3 findings
HIGH New file with network + code execution: dist/vendor-BVmnvb-f.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-02-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.7

3 findings
HIGH New file with network + code execution: dist/vendor-Ct1QNfWX.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-02-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.6

3 findings
HIGH New file with network + code execution: dist/vendor-D4BVkQg8.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-01-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-01-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.5

3 findings
HIGH New file with network + code execution: dist/vendor-Q6b0E6UP.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2026-01-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-01-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.4

3 findings
HIGH New file with network + code execution: dist/vendor-Dd3EDAs1.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2025-12-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.3

3 findings
HIGH New file with network + code execution: dist/vendor-BtGCZQy4.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2025-12-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.2

3 findings
HIGH New file with network + code execution: dist/vendor-BtGCZQy4.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2025-12-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.1

3 findings
HIGH New file with network + code execution: dist/vendor-DMxJoCDS.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2025-12-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.35.0

3 findings
HIGH New file with network + code execution: dist/vendor-CMa7Qsb1.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: ext → GitHub Actions (on 2025-12-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.34.0

2 findings
HIGH New file with network + code execution: dist/vendor-BPf0gRBB.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.33.1

2 findings
HIGH New file with network + code execution: dist/vendor-BAYn8diL.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.33.0

2 findings
HIGH New file with network + code execution: dist/vendor-ClKMZWQO.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.32.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.