← Home

@harness-engineering/dashboard

Local web dashboard for harness project health and roadmap visualization

33
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

intense.visions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/client/assets/index-C3ESTpM4.js AI (source-diff): Vite bundled app entry chunk, minified not obfuscated. ai
phantom-deps phantom-dep:@harness-engineering/orchestrator AI (phantom-deps): Same-org monorepo sibling dependency. ai
source-diff obfuscated-file:dist/client/assets/index-CdH2BIMQ.js AI (source-diff): Vite/tsup bundled client output, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/syntax-highlighter-CLbRg883.js AI (source-diff): Bundled react-syntax-highlighter dep, minified not obfuscated. ai
source-diff obfuscated-file:dist/client/assets/index-Ck3Vyo2I.js AI (source-diff): Vite-bundled minified app chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/client/assets/framer-motion-9tJahuRu.js AI (source-diff): Vite-bundled minified vendor chunk, not true obfuscation. ai
dependencies unvetted-dep:@harness-engineering/signals AI (dependencies): First-party same-org package, expected addition. ai
source-diff net-exec-file:dist/client/assets/syntax-highlighter-CLbRg883.js AI (source-diff): fetch() is standard Vite modulepreload polyfill, no malicious exec. ai
phantom-deps phantom-dep:@tremor/react AI (phantom-deps): UI component library bundled into client dist; stable false positive for this package. ai
phantom-deps phantom-dep:zustand AI (phantom-deps): State management lib consumed in bundled client code. ai
phantom-deps phantom-dep:react-syntax-highlighter AI (phantom-deps): Consumed via JSX bundling. ai
phantom-deps phantom-dep:@harness-engineering/types AI (phantom-deps): Same-org types package; used for type imports stripped at build. ai
phantom-deps phantom-dep:@tailwindcss/typography AI (phantom-deps): Tailwind plugin referenced in config. ai
phantom-deps phantom-dep:react-virtuoso AI (phantom-deps): Consumed via JSX bundling. ai
phantom-deps phantom-dep:react-markdown AI (phantom-deps): Consumed via JSX bundling. ai
phantom-deps phantom-dep:framer-motion AI (phantom-deps): Animation lib consumed via JSX bundling. ai
phantom-deps phantom-dep:react-router AI (phantom-deps): Consumed via JSX bundling in Vite build. ai
phantom-deps phantom-dep:lucide-react AI (phantom-deps): Icon lib consumed via JSX bundling. ai
phantom-deps phantom-dep:remark-gfm AI (phantom-deps): Used as remark plugin in config; not a direct import pattern. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Peer of react; consumed via Vite bundling. ai
phantom-deps phantom-dep:react AI (phantom-deps): React is consumed via JSX/Vite bundling; not directly imported in dist output. ai

Versions (showing 33 of 33)

Version Deps Published
0.11.2 20 / 15
0.11.1 20 / 15
0.11.0 19 / 15
0.10.1 19 / 15
0.10.0 19 / 15
0.9.0 19 / 15
0.8.2 19 / 15
0.8.1 19 / 15
0.8.0 19 / 15
0.7.0 19 / 15
0.6.7 19 / 15
0.6.6 19 / 15
0.6.5 19 / 15
0.6.4 19 / 15
0.6.3 19 / 15
0.6.2 17 / 15
0.6.1 17 / 15
0.6.0 17 / 15
0.5.2 17 / 15
0.5.1 17 / 15
0.5.0 17 / 15
0.4.1 17 / 15
0.4.0 17 / 15
0.3.0 17 / 15
0.2.2 16 / 15
0.2.1 16 / 15
0.2.0 16 / 15
0.1.9 16 / 15
0.1.7 16 / 15
0.1.6 16 / 15
0.1.5 16 / 15
0.1.4 10 / 14
0.1.2 10 / 14

v0.11.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.1

5 findings
HIGH New obfuscated file: dist/client/assets/framer-motion-9tJahuRu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/index-Ck3Vyo2I.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/syntax-highlighter-CLbRg883.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/syntax-highlighter-CLbRg883.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.11.0

5 findings
HIGH New obfuscated file: dist/client/assets/framer-motion-9tJahuRu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/index-C3ESTpM4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/client/assets/syntax-highlighter-CLbRg883.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/client/assets/syntax-highlighter-CLbRg883.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.