@forsakringskassan/docs-generator
Documentation generator
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/vendor-DV7BHNMM.mjs | AI (source-diff): Bundled vendor chunk from build tooling (vue-docgen-api/babel), not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-DWCXj2K2.mjs | AI (source-diff): Bundled vendor chunk (bundler output) with node builtin imports, not a malicious dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-DjC7coI1.mjs | AI (source-diff): Bundled vendor chunk with generic Node builtin imports; no concrete exfil/exec payload shown. | ai | |
| source-diff | net-exec-file:dist/vendor-DO1GigtJ.mjs | AI (source-diff): Bundled vendor chunk with node builtin imports; pattern matches bundler output, not a dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-B-ki54MB.mjs | AI (source-diff): Bundled vendor chunk using Node builtins (fs/http/tls) for docgen tooling; no malicious payload evidenced. | ai | |
| source-diff | net-exec-file:dist/vendor-DgbU8VP_.mjs | AI (source-diff): Bundled build output of legit deps (vue-docgen-api etc.), no obfuscation/malicious payload. | ai | |
| source-diff | net-exec-file:dist/vendor-BnFYrp5U.mjs | AI (source-diff): Bundled vendor chunk with stdlib imports, not a loader/dropper; expected bundler output. | ai | |
| source-diff | net-exec-file:dist/vendor-BK-uA6Uv.mjs | AI (source-diff): Bundled vendor chunk with node-builtin imports for build tooling deps, not a loader/dropper payload. | ai | |
| source-diff | net-exec-file:dist/vendor-Bk5vSW_n.mjs | AI (source-diff): Bundled vendor chunk (rollup/vite output) with node builtins, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-Cgx8NlVP.mjs | AI (source-diff): Bundled vendor chunk with Node builtin imports; build output, not a dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-DMxJoCDS.mjs | AI (source-diff): Bundled vendor chunk with core-module imports; no concrete malicious behavior in sample. | ai | |
| source-diff | net-exec-file:dist/vendor-Q6b0E6UP.mjs | AI (source-diff): Bundled vendor chunk (rollup/vite output) with Node builtin imports, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-BPf0gRBB.mjs | AI (source-diff): Bundled vendor chunk containing standard fs/network Node builtins, not a dropper/loader. | ai | |
| source-diff | net-exec-file:dist/vendor-CMa7Qsb1.mjs | AI (source-diff): Bundled vendor chunk with node builtin imports for docs generator, not a dropper/loader. | ai | |
| source-diff | net-exec-file:dist/vendor-BAYn8diL.mjs | AI (source-diff): Bundled vendor chunk with node builtin imports; build artifact, not injected malware. | ai | |
| source-diff | net-exec-file:dist/vendor-ClKMZWQO.mjs | AI (source-diff): Bundled vendor chunk with node builtin imports, not a dropper; standard bundler output. | ai | |
| source-diff | net-exec-file:dist/vendor-Ct1QNfWX.mjs | AI (source-diff): Bundled vendor chunk with Node builtin imports; build output, not a dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-D4BVkQg8.mjs | AI (source-diff): Bundled vendor chunk (rollup output) with Node builtins, not a loader/dropper; consistent with docs tooling. | ai | |
| source-diff | net-exec-file:dist/vendor-DR1Vkbzf.mjs | AI (source-diff): Bundled vendor chunk with standard Node builtin imports, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-KZo5HqAF.mjs | AI (source-diff): Bundled vendor chunk from build tooling, not injected malicious code. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Consistent with legitimate CI/CD provenance-attested publish pipeline. | ai | |
| source-diff | net-exec-file:dist/vendor-Dd3EDAs1.mjs | AI (source-diff): Bundled vendor chunk with Node core imports (http/fs/etc), not a dropper; standard bundler output. | ai | |
| source-diff | net-exec-file:dist/vendor-BtGCZQy4.mjs | AI (source-diff): Bundled vendor chunk with Node builtin imports, not a dropper; large rollup bundle for docs tooling. | ai | |
| source-diff | net-exec-file:dist/vendor-s-84ehgc.mjs | AI (source-diff): Bundled vendor chunk with node builtins/network+eval APIs from transitive deps, not a loader/dropper. | ai | |
| source-diff | net-exec-file:dist/vendor-BVmnvb-f.mjs | AI (source-diff): Bundled vendor chunk with standard Node builtin imports, not a dropper; consistent with docs tool bundling babel/vue-docgen deps. | ai | |
| source-diff | net-exec-file:dist/vendor-DLyCCfC4.mjs | AI (source-diff): Large bundled vendor file with source map; imports are standard Node built-ins consistent with a docs generator tool, not malware. | ai | |
| source-diff | net-exec-file:dist/vendor-CyiP4ufo.mjs | AI (source-diff): Vite-bundled vendor chunk for a docs generator; Node built-in imports are expected, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/vendor-C0JAkCK-.mjs | AI (source-diff): Large Vite/Rollup vendor bundle for a docs-generator tool; Node built-in imports are expected, not malicious. | ai | |
| source-diff | net-exec-file:dist/vendor-B7bJ2okl.mjs | AI (source-diff): Standard Vite/Rollup vendor bundle; network imports are Node built-ins (http/https), not external fetches. Pattern is stable for this docs-generator package. | ai | |
| source-diff | net-exec-file:dist/vendor-BoRn-ubH.mjs | AI (source-diff): Vite-bundled vendor chunk for a docs-generator; network imports are livereload/dev-server tooling, not dropper behavior. SLSA provenance confirms CI build. | ai | |
| source-diff | net-exec-file:dist/vendor-DX88DJvo.mjs | AI (source-diff): Large vendor bundle is standard Vite/Rollup output for a docs-generator; node built-in imports are expected, not malicious. | ai | |
| source-diff | net-exec-file:dist/vendor-BhMQq6vU.mjs | AI (source-diff): Large vendor bundle from Vite/Rollup build; imports are Node built-ins consistent with docs-generator tooling, not malware. | ai | |
| phantom-deps | phantom-dep:@fontsource-variable/inter | AI (phantom-deps): Font asset referenced in build config, not directly imported in JS — stable false positive. | ai | |
| phantom-deps | phantom-dep:livereload-js | AI (phantom-deps): Asset dependency referenced in build config, not directly imported in JS — stable false positive. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Package has 145 versions and SLSA provenance; dormancy flag is a false positive for this active project. | ai | |
| source-diff | net-exec-file:dist/vendor-tIJeYoyt.mjs | AI (source-diff): Standard Vite vendor bundle for a docs-generator; imports are Node built-ins and bundled deps, not malware. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 3.3.1 | 9 / 0 | |
| 3.3.0 | 9 / 0 | |
| 3.2.0 | 9 / 0 | |
| 3.1.2 | 9 / 0 | |
| 3.1.1 | 9 / 0 | |
| 3.1.0 | 9 / 0 | |
| 3.0.4 | 9 / 0 | |
| 3.0.3 | 9 / 0 | |
| 3.0.2 | 9 / 0 | |
| 3.0.1 | 9 / 0 | |
| 3.0.0 | 9 / 0 | |
| 2.43.0 | 9 / 0 | |
| 2.42.0 | 7 / 0 | |
| 2.41.1 | 7 / 0 | |
| 2.41.0 | 7 / 0 | |
| 2.40.3 | 7 / 0 | |
| 2.40.2 | 7 / 0 | |
| 2.40.1 | 7 / 0 | |
| 2.40.0 | 7 / 0 | |
| 2.39.3 | 7 / 0 | |
| 2.39.2 | 7 / 0 | |
| 2.39.1 | 7 / 0 | |
| 2.39.0 | 7 / 0 | |
| 2.38.6 | 7 / 0 | |
| 2.38.5 | 7 / 0 | |
| 2.38.4 | 7 / 0 | |
| 2.38.3 | 7 / 0 | |
| 2.38.2 | 7 / 0 | |
| 2.38.1 | 7 / 0 | |
| 2.38.0 | 7 / 0 | |
| 2.37.1 | 7 / 0 | |
| 2.37.0 | 7 / 0 | |
| 2.36.0 | 7 / 0 | |
| 2.35.8 | 7 / 0 | |
| 2.35.7 | 7 / 0 | |
| 2.35.6 | 7 / 0 | |
| 2.35.5 | 7 / 0 | |
| 2.35.4 | 7 / 0 | |
| 2.35.3 | 7 / 0 | |
| 2.35.2 | 7 / 0 | |
| 2.35.1 | 7 / 0 | |
| 2.35.0 | 7 / 0 | |
| 2.34.0 | 7 / 0 | |
| 2.33.1 | 7 / 0 | |
| 2.33.0 | 7 / 0 | |
| 2.32.2 | 7 / 0 | |
| 2.32.1 | 7 / 0 | |
| 2.32.0 | 7 / 0 |
v3.3.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.39.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.39.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-25, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.39.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-25, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.39.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.38.6
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.38.5
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.38.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.38.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.38.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.38.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.38.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.37.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.37.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.36.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.8
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.7
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-02-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.6
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-01-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.5
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2026-01-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.35.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (ext) on 2025-12-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v2.34.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.33.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.33.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.32.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.32.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.