@holoscript/core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@holoscript/meaning | AI (dependencies): First-party scoped package within the same org/monorepo. | ai | |
| source-diff | bulk-net-exec-files:dist | AI (source-diff): Bundled build chunks match heuristic but contain no malicious behavior. | ai | |
| source-diff | bulk-obfuscated-files:dist | AI (source-diff): tsup/esbuild bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-PHLNABJD.cjs | AI (source-diff): Bundled compiler chunk (tsup/esbuild output), requires local chunks not fetched binaries. | ai | |
| dependencies | unvetted-dep:@holoscript/platform | AI (dependencies): First-party sibling package within the same monorepo/org. | ai | |
| source-diff | obfuscated-file:dist/dist-YGATNURH.cjs | AI (source-diff): Minified bundled build output (webpack-style helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-FEFHPUEM.cjs | AI (source-diff): Bundled compiler module (Native2DCompiler), benign. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Explained by playwright/three.js/tree-sitter style bundling for a major feature release. | ai | |
| source-diff | net-exec-file:dist/chunk-RT7LJRSF.cjs | AI (source-diff): Bundled engine/runtime chunk pulling in sibling @holoscript packages, benign. | ai | |
| source-diff | net-exec-file:dist/chunk-A6GO3DPZ.cjs | AI (source-diff): Bundled runtime stdlib policy code, not a dropper; net/exec guarded by allowlist config. | ai | |
| source-diff | net-exec-file:dist/chunk-6S6TKNEA.cjs | AI (source-diff): Bundled runtime chunk implementing sandboxed stdlib policy; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/chunk-2YSNA2F2.cjs | AI (source-diff): Path-confined policy engine with network/shell disabled by default; benign capability. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Standard Proxy/Reflect reactive-state pattern, not API evasion. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Core interpreter feature of this DSL runtime, not eval of remote/untrusted input. | ai | |
| source-diff | net-exec-file:dist/chunk-3HYYMEXI.cjs | AI (source-diff): Bundled compiler/trait runtime output; net+exec pattern is build-artifact noise, no hostile destination. | ai | |
| provenance | no-provenance | AI (provenance): No attestation is a request, not a risk; stable for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected diff artifact vs stale sibling version; large monorepo restructure, not injected code. | ai | |
| phantom-deps | phantom-dep:@holoscript/assimp-plugin | AI (phantom-deps): Same-org workspace plugin, common phantom-dep FP pattern. | ai | |
| source-diff | net-exec-file:dist/chunk-4Q7RKQQI.cjs | AI (source-diff): Bundled compiler chunk (tsup output); crypto+require usage is normal module code, not a loader. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is declared as a dependency and used in config/schema files; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@holoscript/agent-protocol | AI (phantom-deps): Internal monorepo workspace package; same-org scope, phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:holoscript-web-preview | AI (phantom-deps): Internal monorepo workspace package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@holoscript/core-types | AI (phantom-deps): Internal monorepo type package; same-org scope, likely used via TypeScript path resolution. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped package @holoscript/core; 'core' is a common suffix, not an impersonation of the 'cors' package. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 8.0.17 | 11 / 16 | |
| 8.0.16 | 10 / 16 | |
| 8.0.15 | 10 / 16 | |
| 8.0.14 | 10 / 16 | |
| 8.0.9 | 10 / 16 | |
| 8.0.6 | 9 / 13 | |
| 8.0.0 | 10 / 13 | |
| 6.1.4 | 10 / 13 | |
| 6.0.4 | 41 / 12 | |
| 6.0.3 | 5 / 10 | |
| 6.0.2 | 5 / 10 | |
| 2.1.0 | 0 / 5 | |
| 2.0.2 | 0 / 4 | |
| 2.0.1 | 0 / 4 | |
| 2.0.0 | 0 / 4 |
v8.0.17
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.16
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.15
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.14
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.9
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.3
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.2
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brianonbased.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.