@haklex/rich-kit-shiro
Production bundle for Shiroi blog
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/style-BdEDjsBT.js | AI (source-diff): File is a minified CSS-in-JS bundle (cssText string); long lines are CSS, not obfuscation. Stable pattern for this build tool. | ai | |
| source-diff | obfuscated-file:dist/style-AKvuf1wf.js | AI (source-diff): File is a minified CSS-in-JS bundle (design tokens/CSS vars), not obfuscated malicious code; stable pattern for this build tool. | ai | |
| source-diff | obfuscated-file:dist/style-DF_-78dC.js | AI (source-diff): File is a minified CSS-in-JS bundle (vanilla-extract); long lines are CSS strings, not obfuscated code. | ai | |
| phantom-deps | phantom-dep:@haklex/rich-ext-chat | AI (phantom-deps): Same-org dependency declared as runtime dep but bundled/re-exported; not a real phantom dep for this package. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 0.4.0 | 18 / 10 | |
| 0.1.1 | 20 / 11 | |
| 0.1.0 | 20 / 11 | |
| 0.0.101 | 20 / 11 | |
| 0.0.99 | 20 / 11 | |
| 0.0.98 | 20 / 11 | |
| 0.0.97 | 20 / 11 | |
| 0.0.95 | 20 / 11 | |
| 0.0.94 | 20 / 11 | |
| 0.0.93 | 20 / 11 | |
| 0.0.92 | 20 / 11 | |
| 0.0.91 | 20 / 11 |
v0.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.93
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.92
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.91
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.