@inkeep/open-knowledge
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/public/assets/config-validation-events-D83pJzu8.js | AI (source-diff): Bundled build output for embedded webapp, no malicious code. | ai | |
| source-diff | obfuscated-file:dist/public/assets/checkbox-DurEHAAx.js | AI (source-diff): Minified UI component chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/calendar-Cpuc24Im.js | AI (source-diff): Minified UI component chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/c4Diagram-AHTNJAMY-lOxwQVJ2.js | AI (source-diff): Minified mermaid diagram chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/blockDiagram-DXYQGD6D-DK-9tYVp.js | AI (source-diff): Minified mermaid diagram chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/auth-state-cache-CZRVpVW6.js | AI (source-diff): Vite-bundled app chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/architectureDiagram-Q4EWVU46-BRnvRY5Q.js | AI (source-diff): Minified mermaid diagram chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/arc-lAkd3r-L.js | AI (source-diff): Minified d3 chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/agent-presence-DOgDiPgh.js | AI (source-diff): Vite-bundled icon/component chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityPanelDiffView-B6QdoucA.js | AI (source-diff): Vite-bundled app chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-C0_GSBuC.js | AI (source-diff): Vite-bundled app chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/_baseFor-CCfTEsdD.js | AI (source-diff): Standard minified lodash bundle chunk, not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Publishing moved to GitHub Actions CI, consistent with provenance improvement. | ai | |
| source-diff | net-exec-file:dist/public/assets/chunk-KEIR6QF5-YxiaonDF.js | AI (source-diff): Bundled library chunk (diagram lib), not a dropper. | ai | |
| source-diff | obfuscated-file:dist/public/assets/agent-presence-3QXefn1F.js | AI (source-diff): Vite-bundled frontend asset (icon library). | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityPanelDiffView-COM6jgM6.js | AI (source-diff): Vite-bundled frontend asset. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-OPy7COSt.js | AI (source-diff): Vite-bundled frontend asset, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/public/assets/prop-types-BZGYw9Lv.js | AI (source-diff): React internals (fetch/preload APIs), not dropper code. | ai | |
| source-diff | obfuscated-file:dist/public/assets/prop-types-BZGYw9Lv.js | AI (source-diff): Bundled React/vendor chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-BWmb9zCZ.js | AI (source-diff): Vite-bundled frontend chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/public/assets/prop-types-COA7UVY9.js | AI (source-diff): React/fetch bundled UI code, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/public/assets/prop-types-BLvAnH2n.js | AI (source-diff): Vite-bundled frontend vendor chunk, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/public/assets/prop-types-BLvAnH2n.js | AI (source-diff): Bundled theme/localStorage code, no exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-DGw5iUid.js | AI (source-diff): Vite-bundled app chunk, standard minification. | ai | |
| source-diff | obfuscated-file:dist/public/assets/index-B7eqx3hL.js | AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/dist-Cgm7vMFl.mjs | AI (source-diff): Bundled library code, no concrete malicious destination identified. | ai | |
| source-diff | net-exec-file:dist/public/assets/dist-COgUpCH8.js | AI (source-diff): Bundled yaml/library code with fetch+eval-like constructs, no exfil destination shown. | ai | |
| source-diff | obfuscated-file:dist/public/assets/DocumentContext-CVfa457X.js | AI (source-diff): Vite-bundled frontend chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/server-lock-CN2YHwpP-DiysUpvV.mjs | AI (source-diff): Bundled server lock module; consistent with CLI server component. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Minor metadata omission, not a security signal for this established package. | ai | |
| source-diff | obfuscated-file:dist/public/assets/dist-Bs-tW6G8.js | AI (source-diff): Bundled Vite chunk (theme/UI helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/public/assets/dist-Bs-tW6G8.js | AI (source-diff): Bundled UI code with fetch + normal JS eval-like patterns from bundler, not a loader. | ai | |
| source-diff | net-exec-file:dist/dist-CXugONRr.mjs | AI (source-diff): Bundled CLI/server code; part of stated app functionality, no exfil destination shown. | ai | |
| source-diff | obfuscated-file:dist/public/assets/button-CmLxDlCv.js | AI (source-diff): Bundled React runtime chunk. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-BKkulMQY.js | AI (source-diff): Vite-bundled app UI chunk, standard build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/agent-presence-DYKkeiBZ.js | AI (source-diff): Bundled React/icon chunk, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/public/assets/checkbox-BlEgF5ZV.js | AI (source-diff): Bundled UI component chunk. | ai | |
| source-diff | obfuscated-file:dist/public/assets/collapsible-BzkAcCLq.js | AI (source-diff): Bundled UI component chunk. | ai | |
| source-diff | obfuscated-file:dist/public/assets/config-validation-events-sausWRtn.js | AI (source-diff): Bundled app UI chunk. | ai | |
| source-diff | obfuscated-file:dist/public/assets/c4Diagram-AHTNJAMY-CGJ_dXh7.js | AI (source-diff): Bundled mermaid diagram module. | ai | |
| source-diff | obfuscated-file:dist/public/assets/calendar-D62otKE3.js | AI (source-diff): Bundled UI calendar component. | ai | |
| source-diff | obfuscated-file:dist/public/assets/checkbox-P04sbGVQ.js | AI (source-diff): Bundled UI checkbox component. | ai | |
| source-diff | obfuscated-file:dist/public/assets/_baseFor-D774tcxR.js | AI (source-diff): Minified lodash internals bundled via vite; no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-mJH5LtOR.js | AI (source-diff): Bundled app UI component (vite), no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityPanelDiffView-BPrpOwiv.js | AI (source-diff): Bundled React component code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/public/assets/agent-presence-C79Orlhd.js | AI (source-diff): Bundled icon/UI library code. | ai | |
| source-diff | obfuscated-file:dist/public/assets/arc-CbtK-u7K.js | AI (source-diff): Minified d3-shape arc module, standard bundling. | ai | |
| source-diff | obfuscated-file:dist/public/assets/architectureDiagram-Q4EWVU46-BEI0DR2f.js | AI (source-diff): Bundled mermaid diagram module. | ai | |
| source-diff | obfuscated-file:dist/public/assets/auth-state-cache-CaiWuhtJ.js | AI (source-diff): Bundled app module, no exfil behavior found. | ai | |
| source-diff | obfuscated-file:dist/public/assets/blockDiagram-DXYQGD6D-CvhaR3v1.js | AI (source-diff): Bundled mermaid parser code. | ai | |
| source-diff | obfuscated-file:dist/public/assets/button-cneJOVxD.js | AI (source-diff): Bundled UI component. | ai | |
| source-diff | obfuscated-file:dist/public/assets/config-validation-events-DbjF6isi.js | AI (source-diff): Vite-bundled minified output; no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/public/assets/collapsible-CiYR1NR5.js | AI (source-diff): Vite-bundled minified UI component output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/clike-DrSwTBuw.js | AI (source-diff): Vite-bundled minified syntax highlighter output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/checkbox-DcMpayVo.js | AI (source-diff): Vite-bundled minified UI component output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/c4Diagram-AHTNJAMY-CTuRG6XQ.js | AI (source-diff): Vite-bundled mermaid c4 diagram chunk. | ai | |
| source-diff | obfuscated-file:dist/public/assets/button-CNAPefQE.js | AI (source-diff): Vite-bundled React DOM minified output; Minified React error URL visible. | ai | |
| source-diff | obfuscated-file:dist/public/assets/blockDiagram-DXYQGD6D-CvqzFRrs.js | AI (source-diff): Vite-bundled mermaid block diagram chunk. | ai | |
| source-diff | obfuscated-file:dist/public/assets/architectureDiagram-Q4EWVU46-CGfN8F1x.js | AI (source-diff): Vite-bundled mermaid diagram chunk; standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/arc-B0M4cKTB.js | AI (source-diff): Vite-bundled minified d3-arc output; readable math identifiers. | ai | |
| source-diff | obfuscated-file:dist/public/assets/agent-presence-CarzuseD.js | AI (source-diff): Vite-bundled minified output; Claude icon SVG paths visible. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityPanelDiffView-InYkbArk.js | AI (source-diff): Vite-bundled minified output; standard ES module pattern. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-CLgsnxvy.js | AI (source-diff): Vite-bundled minified output with __vite__mapDeps banner. | ai | |
| source-diff | obfuscated-file:dist/public/assets/_baseFor-BB4KANPr.js | AI (source-diff): Vite-bundled minified output; readable lodash identifiers, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/arc-ByJ8e9TF.js | AI (source-diff): d3-arc minified bundle; standard data-viz library output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/agent-presence-CPRnxEOl.js | AI (source-diff): Vite-bundled app chunk with SVG icon definitions; clearly legitimate. | ai | |
| phantom-deps | phantom-dep:jsonc-parser | AI (phantom-deps): jsonc-parser is declared in package.json dependencies and used in bundled CLI; phantom-dep heuristic false positive. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Platform-specific .node files are napi-rs native config bindings built in the workspace; consistent with build:native script. | ai | |
| source-diff | obfuscated-file:dist/public/assets/clike-C8wyRRyC.js | AI (source-diff): Prism/highlight.js clike grammar bundle; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/checkbox-DBdFRrZg.js | AI (source-diff): Vite-bundled UI component; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/calendar-ExjQo5qX.js | AI (source-diff): Vite-bundled UI component; standard minified output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/c4Diagram-AHTNJAMY-Ciz_9wte.js | AI (source-diff): Mermaid C4 diagram chunk; standard minified library output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/button-DGf25ccp.js | AI (source-diff): Lucide-react + tailwind-merge bundle; standard minified UI library output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/blockDiagram-DXYQGD6D-DhI4yaUm.js | AI (source-diff): Mermaid block diagram chunk; standard minified library output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/architectureDiagram-Q4EWVU46-BBif8L3G.js | AI (source-diff): Mermaid architecture diagram chunk; standard minified library output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/_baseFor-D_g0Vaw_.js | AI (source-diff): Standard Vite-minified frontend bundle output; lodash internals visible in sample. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-D247jYIx.js | AI (source-diff): Vite-bundled app chunk; imports from named local chunks, no obfuscation. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityPanelDiffView-BXoGtJMu.js | AI (source-diff): Vite-bundled app chunk; standard minified JS, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityPanelDiffView-DgtknSgX.js | AI (source-diff): Vite-bundled app component; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/architectureDiagram-Q4EWVU46-Du5oNRD5.js | AI (source-diff): Vite-bundled mermaid architecture diagram chunk; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/blockDiagram-DXYQGD6D-CuxUJ8VP.js | AI (source-diff): Vite-bundled mermaid block diagram chunk; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/c4Diagram-AHTNJAMY-D58kKzW4.js | AI (source-diff): Vite-bundled mermaid C4 diagram chunk; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/checkbox-Co7Tjlri.js | AI (source-diff): Vite-bundled Radix UI checkbox component; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/config-validation-events-BDwfLsPI.js | AI (source-diff): Vite-bundled app chunk; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ConsentDialogBody-CM1Lm4n9.js | AI (source-diff): Vite-bundled app component; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/cose-bilkent-S5V4N54A-6FB6GAoi.js | AI (source-diff): Vite-bundled cytoscape layout algorithm; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/cytoscape.esm-4jw_vW_Q.js | AI (source-diff): Vite-bundled cytoscape.js library; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/dagre-D2_448Gx.js | AI (source-diff): Vite-bundled dagre graph layout library; standard minified build output. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): CLI tool with many deps used at runtime via dynamic dispatch; phantom-dep heuristic unreliable here. | ai | |
| phantom-deps | phantom-dep:yazl | AI (phantom-deps): Same as above — CLI tool pattern. | ai | |
| phantom-deps | phantom-dep:@inquirer/select | AI (phantom-deps): Same as above — CLI tool pattern. | ai | |
| source-diff | obfuscated-file:dist/public/assets/_baseFor-CVV1DSgL.js | AI (source-diff): Vite-bundled lodash chunk; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-B3qvj_3C.js | AI (source-diff): Vite-bundled app component; standard minified build output. | ai | |
| source-diff | obfuscated-file:dist/public/assets/arc-DoxD41WW.js | AI (source-diff): Vite-bundled d3-arc chunk; standard minified build output. | ai | |
| phantom-deps | phantom-dep:@hocuspocus/provider | AI (phantom-deps): Bundled by tsdown; declared dep used at build time. | ai | |
| phantom-deps | phantom-dep:picomatch | AI (phantom-deps): Bundled by tsdown; declared dep used at build time. | ai | |
| phantom-deps | phantom-dep:just-bash | AI (phantom-deps): Bundled by tsdown; declared dep used at build time. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Bundled by tsdown; declared dep used at build time. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): CLI tool bundles deps via tsdown; declared deps referenced at build time. | ai | |
| phantom-deps | phantom-dep:simple-git | AI (phantom-deps): Bundled by tsdown; declared dep used at build time. | ai | |
| phantom-deps | phantom-dep:shell-quote | AI (phantom-deps): Bundled by tsdown; declared dep used at build time. | ai | |
| phantom-deps | phantom-dep:@clack/prompts | AI (phantom-deps): Bundled by tsdown; declared dep used at build time. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityModeContent-B8J4OFHO.js | AI (source-diff): Vite-bundled frontend asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ActivityPanelDiffView-d4ec9M69.js | AI (source-diff): Vite-bundled frontend asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/agent-presence-8VSgL2U2.js | AI (source-diff): Vite-bundled frontend asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/arc-GOD6SLHR.js | AI (source-diff): Vite-bundled frontend asset (d3 arc); minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/architectureDiagram-Q4EWVU46-CIVh0TLx.js | AI (source-diff): Vite-bundled mermaid/cytoscape asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/blockDiagram-DXYQGD6D-Cg-UHasz.js | AI (source-diff): Vite-bundled mermaid asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/button-DBLnjjvQ.js | AI (source-diff): Vite-bundled React DOM asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/c4Diagram-AHTNJAMY-KFeHAAOO.js | AI (source-diff): Vite-bundled mermaid asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/checkbox-kroC1jEP.js | AI (source-diff): Vite-bundled frontend asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/collapsible-L2bca9Ur.js | AI (source-diff): Vite-bundled frontend asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/config-validation-events-BtPgkHlf.js | AI (source-diff): Vite-bundled frontend asset; minification expected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/ConsentDialogBody-Dfx6N7pC.js | AI (source-diff): Vite-bundled frontend asset; minification expected. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package bundles a full web app (dist/public); large file count is structural, not injected. | ai | |
| source-diff | obfuscated-file:dist/public/assets/_baseFor-B3FCzyNW.js | AI (source-diff): Vite-bundled frontend asset (lodash); minification is expected for this package's web app dist. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@octokit/auth-oauth-device | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@modelcontextprotocol/sdk | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@inquirer/password | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@inquirer/checkbox | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@octokit/request | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@napi-rs/keyring | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:smol-toml | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:sirv | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:cli-boxes | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:@octokit/rest | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| phantom-deps | phantom-dep:picocolors | AI (phantom-deps): CLI tool with bundled dist; deps referenced in config/build files, not direct imports. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Simple `node scripts/postinstall.mjs` invocation in a SLSA-attested CLI package; consistent with legitimate setup. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 0.34.0 | 19 / 10 | |
| 0.30.0 | 19 / 10 | |
| 0.26.0 | 19 / 10 | |
| 0.25.1 | 19 / 10 | |
| 0.22.0 | 19 / 10 | |
| 0.21.0 | 19 / 10 | |
| 0.20.0 | 18 / 9 | |
| 0.19.1 | 18 / 9 | |
| 0.19.0 | 18 / 9 | |
| 0.18.0 | 18 / 9 | |
| 0.17.0 | 18 / 9 | |
| 0.16.1 | 18 / 9 | |
| 0.16.0 | 18 / 9 | |
| 0.15.0 | 18 / 9 | |
| 0.14.0 | 18 / 9 | |
| 0.13.0 | 18 / 9 | |
| 0.12.0 | 18 / 9 | |
| 0.11.0 | 18 / 9 | |
| 0.10.0 | 18 / 9 | |
| 0.9.0 | 18 / 9 | |
| 0.8.1 | 17 / 9 | |
| 0.8.0 | 17 / 9 | |
| 0.7.0 | 15 / 8 | |
| 0.6.0 | 15 / 8 | |
| 0.5.0 | 15 / 8 | |
| 0.4.1 | 15 / 8 | |
| 0.4.0 | 15 / 8 | |
| 0.2.0 | 19 / 9 | |
| 0.1.1 | 15 / 9 |
v0.34.0
13 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.0
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.0
40 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.25.1
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.0
32 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.21.0
14 findingsPackage contains compiled binaries that could be backdoors: • dist/native/native-config.darwin-arm64.node • dist/native/native-config.darwin-x64.node • dist/native/native-config.linux-arm64-gnu.node • dist/native/native-config.linux-arm64-musl.node • dist/native/native-config.linux-x64-gnu.node • dist/native/native-config.linux-x64-musl.node • dist/native/native-config.win32-arm64-msvc.node • dist/native/native-config.win32-x64-msvc.node
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.0
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.