@frontify/app-bridge
Package to establish communication between Frontify and marketplace apps
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-BTn661P9.js | AI (source-diff): Bundled file re-exports normal deps; no fetched-binary or exfil behavior present. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-n1Dijtlt.cjs | AI (source-diff): Bundled/minified build output (Vite/Rollup), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-BTn661P9.js | AI (source-diff): Bundled/minified build output (Vite/Rollup), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-n1Dijtlt.cjs | AI (source-diff): Bundled file re-exports normal deps; no fetched-binary or exfil behavior present. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-B_d7naPh.cjs | AI (source-diff): Bundled file extension/type enums, no malicious net+exec behavior. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-C4CvQ6G_.js | AI (source-diff): Bundled file extension/type enums, no malicious net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-C4CvQ6G_.js | AI (source-diff): Vite/esbuild bundled dist output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-B_d7naPh.cjs | AI (source-diff): Vite/esbuild bundled dist output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-BP5IaZag.js | AI (source-diff): Bundled/minified Vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-BP5IaZag.js | AI (source-diff): Bundled dummy/test module, no dropper behavior found. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-CypPTxYh.cjs | AI (source-diff): Bundled dummy/test module, no dropper behavior found. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-CypPTxYh.cjs | AI (source-diff): Bundled/minified Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-D3HBW44O.js | AI (source-diff): Bundled/minified Vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-CDGYEqvZ.cjs | AI (source-diff): Standard enums/bundle; no dropper behavior found in sample. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-CDGYEqvZ.cjs | AI (source-diff): Bundled/minified Vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-D3HBW44O.js | AI (source-diff): Standard enums/bundle; no dropper behavior found in sample. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-BZuiB0Jj.cjs | AI (source-diff): Normal require/import calls in bundled code, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-BZuiB0Jj.cjs | AI (source-diff): Bundled build output (vite/rollup), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-CcnlgPq9.js | AI (source-diff): Bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-CcnlgPq9.js | AI (source-diff): Normal require/import calls in bundled code, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-dFQejYFu.js | AI (source-diff): Bundled dummy/testing module, no hostile network target found. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-DRbstUdV.cjs | AI (source-diff): Standard vite/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-dFQejYFu.js | AI (source-diff): Standard vite/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-DRbstUdV.cjs | AI (source-diff): Bundled dummy/testing module, no hostile network target found. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Long-established SDK package with thin README; not spam. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-C-YQhCSH.cjs | AI (source-diff): Bundled minified build output, not true obfuscation. | ai | |
| source-diff | encoded-string-file:dist/index.js | AI (source-diff): Base64 blob is worker code for chunked upload, matches package purpose. | ai | |
| source-diff | encoded-string-file:dist/index.cjs | AI (source-diff): Base64 blob is worker code for chunked upload, matches package purpose. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-DJ7MItev.js | AI (source-diff): Benign bundled dummy/test component, no malicious network+exec behavior. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-C-YQhCSH.cjs | AI (source-diff): Benign bundled dummy/test component, no malicious network+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-DJ7MItev.js | AI (source-diff): Bundled minified build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-Zj0k4cFw.js | AI (source-diff): Minified Vite build output for a testing dummy component; not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): lodash-es is a declared runtime dependency; phantom-dep heuristic fires because it's used indirectly via bundling. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-Zj0k4cFw.js | AI (source-diff): False positive; file is a bundled test dummy using sinon/react, no actual network+exec dropper pattern. | ai | |
| source-diff | net-exec-file:dist/DocumentNavigationTreeDummy-DiitD9tF.cjs | AI (source-diff): False positive; file is a bundled test dummy using sinon/react, no actual network+exec dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/DocumentNavigationTreeDummy-DiitD9tF.cjs | AI (source-diff): Minified Vite build output for a testing dummy component; not obfuscated malware. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 3.12.10 | 4 / 23 | |
| 3.12.9 | 4 / 23 | |
| 3.12.8 | 4 / 23 | |
| 3.12.7 | 4 / 23 | |
| 3.12.6 | 4 / 23 | |
| 3.12.5 | 4 / 23 | |
| 3.12.4 | 4 / 23 | |
| 3.12.3 | 4 / 23 | |
| 3.12.2 | 4 / 23 | |
| 3.12.1 | 4 / 23 | |
| 3.12.0 | 4 / 24 | |
| 3.11.2 | 4 / 24 | |
| 3.11.1 | 4 / 23 | |
| 3.11.0 | 4 / 23 | |
| 3.10.1 | 4 / 23 | |
| 3.10.0 | 4 / 23 | |
| 3.9.2 | 4 / 23 | |
| 3.9.1 | 4 / 23 | |
| 3.9.0 | 4 / 23 | |
| 3.8.0 | 4 / 23 | |
| 3.7.0 | 4 / 23 | |
| 3.6.3 | 4 / 23 |
v3.12.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.11.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.10.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.10.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.2
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.8.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.7.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.6.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.