← Home

@jait/gateway

Jait AI gateway — local-first AI coding agent with terminal, filesystem, and browser control

100
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

jakobwl

Keywords

aiagentcodinggatewayterminallocal-first

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:web-dist/assets/blockDiagram-WCTKOSBZ-CNLmGpHu.js AI (source-diff): Minified mermaid block diagram bundle; standard build artifact. ai
source-diff obfuscated-file:web-dist/assets/graph-BDokxLqo.js AI (source-diff): Minified graph library bundle; standard build artifact. ai
source-diff net-exec-file:web-dist/assets/index-B3efWHMg.js AI (source-diff): Network+exec pattern is mermaid's dynamic diagram renderer in bundled frontend, not malware. ai
source-diff obfuscated-file:web-dist/assets/index-B3efWHMg.js AI (source-diff): Standard Vite-bundled frontend output; minified open-source libs (mermaid, d3, etc.). ai
source-diff obfuscated-file:web-dist/assets/architectureDiagram-2XIMDMQ5-Dc-KsYhx.js AI (source-diff): Minified mermaid architecture diagram renderer; standard build output. ai
source-diff obfuscated-file:web-dist/assets/cose-bilkent-S5V4N54A-DKSvV8VX.js AI (source-diff): Minified cose-bilkent cytoscape layout library; standard build output. ai
source-diff obfuscated-file:web-dist/assets/dagre-KLK3FWXG-DJ0xtDkx.js AI (source-diff): Minified dagre graph layout library; standard build output. ai
source-diff large-new-source-files AI (source-diff): Large file count reflects first inclusion of bundled web-dist frontend assets. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP is 127.0.0.1 (localhost) health check — not an external exfiltration endpoint. ai
phantom-deps phantom-dep:zod AI (phantom-deps): zod is a declared runtime dep used in config/schema files; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:pino AI (phantom-deps): pino is a declared runtime dep; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@fastify/websocket AI (phantom-deps): @fastify/websocket is a declared runtime dep; phantom-dep heuristic false positive. ai
semgrep semgrep:dll-hijacking-commands AI (semgrep): Fires on frozen JSON grammar definition blob in bundled web asset; no actual DLL loading commands present. ai
semgrep semgrep:env-spread AI (semgrep): env spread is used to pass current env plus a flag to a background child process — standard daemon-launch pattern, not exfiltration. ai

Versions (showing 100 of 243)

Version Deps Published
0.1.349 17 / 4
0.1.348 17 / 4
0.1.347 17 / 4
0.1.346 17 / 4
0.1.345 17 / 4
0.1.344 17 / 4
0.1.343 17 / 4
0.1.342 17 / 4
0.1.341 17 / 4
0.1.340 17 / 4
0.1.339 17 / 4
0.1.338 17 / 4
0.1.337 17 / 4
0.1.334 17 / 4
0.1.333 17 / 4
0.1.332 17 / 4
0.1.331 17 / 4
0.1.330 17 / 4
0.1.329 17 / 4
0.1.328 17 / 4
0.1.327 17 / 4
0.1.326 17 / 4
0.1.325 17 / 4
0.1.324 17 / 4
0.1.323 17 / 4
0.1.322 17 / 4
0.1.321 17 / 4
0.1.320 17 / 4
0.1.319 17 / 4
0.1.318 16 / 4
0.1.317 16 / 4
0.1.316 16 / 4
0.1.315 16 / 4
0.1.314 16 / 4
0.1.313 16 / 4
0.1.312 16 / 4
0.1.311 16 / 4
0.1.310 16 / 4
0.1.309 16 / 4
0.1.308 16 / 4
0.1.307 16 / 4
0.1.306 16 / 4
0.1.305 16 / 4
0.1.304 16 / 4
0.1.303 16 / 4
0.1.302 16 / 4
0.1.301 16 / 4
0.1.300 16 / 4
0.1.299 16 / 4
0.1.298 16 / 4
0.1.297 16 / 4
0.1.296 16 / 4
0.1.295 16 / 4
0.1.294 16 / 4
0.1.292 16 / 4
0.1.291 16 / 4
0.1.290 16 / 4
0.1.289 16 / 4
0.1.288 16 / 4
0.1.287 16 / 4
0.1.286 16 / 4
0.1.285 16 / 4
0.1.284 16 / 4
0.1.283 16 / 4
0.1.282 16 / 4
0.1.281 16 / 4
0.1.280 16 / 4
0.1.279 16 / 4
0.1.278 16 / 4
0.1.277 16 / 4
0.1.276 16 / 4
0.1.275 16 / 4
0.1.274 16 / 4
0.1.273 16 / 4
0.1.272 16 / 4
0.1.270 16 / 4
0.1.269 16 / 4
0.1.268 16 / 4
0.1.267 16 / 4
0.1.266 16 / 4
0.1.265 16 / 4
0.1.264 16 / 4
0.1.262 16 / 4
0.1.68 17 / 4
0.1.67 17 / 4
0.1.66 17 / 4
0.1.65 17 / 4
0.1.64 17 / 4
0.1.63 17 / 4
0.1.62 17 / 4
0.1.61 17 / 4
0.1.59 17 / 4
0.1.58 17 / 4
0.1.57 17 / 4
0.1.56 17 / 4
0.1.55 17 / 4
0.1.54 17 / 4
0.1.53 17 / 4
0.1.49 18 / 4
0.1.48 18 / 4
Showing 100 of 243 Next page →

v0.1.349

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/cf555fbfda4f5eddbd7cf0e746e53d21cb690c32/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.348

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/ac192df870021ad4b96f2bdeeb1499fe10fad6ce/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.347

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/5bec2363247ff1cabc3f7ee97d78fe4ee28d0dad/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.346

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/0e49e97ecfaf4ce37c63dddaf2a3769231075463/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.345

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/13f2f4760035d1c3d7571dcf31ab1ed7e29c29ee/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.344

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/367bbbe9c85e8888e2e20453a90f8be25f38aa8e/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.343

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/6d25f731d684282227159090766363920ed859e7/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.342

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/e35f07606e7637ad35318fa68ab21fea859d6ed7/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.341

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/ddbc971028c1f580f6b6d010de10e701485182cd/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.340

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/8fd4cd1362bc21f46a00f634b02f2aab53801e9e/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.339

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/288061c647cea32461bdf3481c5e1a31928f64f4/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.338

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/511eff41a6fdcb563745f11e5ab1d59a68b27e72/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.337

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/0c452df2af33e5bf59ebbec3aa79c44fe5fada20/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.334

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/3dea71492dc15f6f783a26592d16c5e03e2b63cc/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.333

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/d534aa37a759571cd55e82e5d355e91dbebc9ba4/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.332

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/30775c0064ebf1c1d7f936369e313447eb5b1c4b/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.331

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/ef08d762c6918b7cd56576ddb1b02e24edee1d37/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.330

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/1e7dc826f80b09f37d304b764e2e42a9b85d10a7/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.329

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/b520fd4b3fa6881e100f38dbfbfb64c43e10d24f/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.328

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/166541976d2ac594f34994c20cbaf06031e537fd/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.327

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/fcd8c6d7d8676e9a4a69ae46f48a228df5e78cdd/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.326

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/87d760e02dac02d617adc230c0c4067a6a284ea0/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.325

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/74a7308fc9045c1ee5f6c552dce1c070b32c8ba8/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.324

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/0b0b8215733f40eb76ddeec39a0600d8a983ff7d/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.323

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/0223716a1aa2e167dfffd2129ceb6352cd1dfcc9/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.322

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/8ab6c4531c88b40274a077ce111e24c23baebc80/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.321

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/b1ad8cfabb095af02c6ee33a5ffffbbb1ae6c76f/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.320

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/63bed0908c33d479b780e07c4eb71deeef153d19/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.319

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/b3b49fdf0ec6f03b50a80107a6d9b554f1b71cf5/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.318

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/9086264beb0035c4ebd13e56c834ca1fc0223341/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.317

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/370f22b9421c4df3d46a080b84e3c1a6b577972c/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.316

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/b0a3abd0dc9c2115c940214b4dff1661e0e1a844/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.315

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/3576effb4f9016a1ecc682275f75411fbd1a9a63/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.314

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/59af5fcaf94d211eae4f2f18c57684a15fbd0552/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.313

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/0ced663aa517709c8f98fe9b7085a4e7e39757f9/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.312

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/c9786f02911af8a67dc82d9f157ffd564a9e28ba/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.311

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/ce3d260e5ef130f0813bb5527ece545a4d50a2a8/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.310

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/85e464f1b223804145c23002577d06b333da2e6c/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.309

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/7c1cb87a3acd0b7218a2b75d24c3dcf010b3a0c3/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.308

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/f9b83b56eb1fb1a29ab86c8931a57ad1a5c8d88c/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.307

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/0a05bf16f4bc4370410d1ee3e4ee0b7fcd60213b/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.306

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/41a6ef2d932be21e0b4b621c36f5f8ea9887b62a/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.305

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/37cdecff958276d7bc3e6c158f24fd2c442b4c48/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.304

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/5dc3c62e434e4710344b41cb575414e6f06b324f/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.303

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/4f0e3a331da7d6dfe277ed52bb7ffca7c1ff85ed/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.302

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/58d8a7c59ffe07d82062cf3de509b91f0cf09062/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.301

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/8d2d8a62d1648e4bcba78ecc59396a24c67f271f/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.300

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/e802330a26f2a68b48b2203140601edd6e1edbc9/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.299

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/24a3c3b633a1bb159ce7e39c443f3729c3f69638/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.298

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/bec4ab0da1ec05e17697819e38dbae2009349c25/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.297

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/f0ef55d6fffa81f79dafd6510ae81088b6848957/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.296

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/d1d787a986b6fef4e7e978d4733d6cfe1b6aa8cb/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.295

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/ac28ea73eb5dab2c51869df3c00598931671740a/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.294

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/f0683ee4cd5a98565a7928fe2d3575e2c4d3d9c2/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.292

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/831314742f518c686462716973cfda2186bf0bb0/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.291

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/60067e8d2c9e1a6fa443f2437a69739a42d87a44/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.290

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/d8d08d829e250c9af6d31e641180c1adbcc36eb6/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.289

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/d134cd9f9b6c2385edc30fa35898327a4beb0878/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.288

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/62e84a18c1feae62460d084e5edee7cca75d7f8f/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.287

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/ca650a588aa8f49107911abfafef9632ddcb5e5f/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.286

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/423c62dfe4b0abe5004fdb5183707ce2fab8ae56/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.285

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/d17fc0260d082cecf14c2db02250b32cb0184f12/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.284

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/9365ab22b32733e52602573d72a73262c3a4e9ad/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.283

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/a0677175f763d6e49c253434c95bff8102293d1f/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.282

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/b6123434a23bcf852160c44bd6f94c2127692693/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.281

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/cb4e47f9345f56e09a6b83f408a3b011b9f2622a/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.280

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/5d09833e62b7b51d9e83d85736f6e5ef1109968c/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.279

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/5bd0c7002d1f7ad38d0db5147aba8150f30bb1f3/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.278

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/83b58a212cd9d0aa16723d4e10385acc2c1e88f7/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.277

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/04ac01c7484a9c87e9921b34ae6916133164c4cf/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.276

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/40a7e2b9b15541550619f40146722ba2f52cb447/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.275

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/0c46405f98d4a377e7713d41b0b5ef3bc3b3e6a6/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.274

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/d7a90d78f27b4b2781fcb42de2d2109aff5fd17c/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.273

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/449fc0ed0d0c7ec8153012301e8537ebd9898c91/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.272

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/ece1f99d7c33d71e99a44fed1f63cb3495d236a4/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.270

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/042ceb71dd2d5780c88c376de124fded6f831205/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.269

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/774e7cad3a83ed9041275e8f3032b5be647f2824/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.268

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/514f3f9f9c5e7f5c5382e15af3d5cb82b7eacd75/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.267

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/a74b379dc35a29718b761f7b90dfc2690627066a/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.266

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/6a2e09450e724dd9d58a6d9b1ed219833723fa9b/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.265

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/2ed0d8519cad9b0b9e3b5180e8104f0bdb915718/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.264

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/9d14c353a96d0bdef614237526e86876b04b97db/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.262

2 findings
HIGH env-spread: bin/jait.mjs:269 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/Widev-e-U/Jait/blob/2aa4e3ae3fc805b73da700b10ff1bbc230741087/bin/jait.mjs#L269 267 | detached: true, 268 | stdio: ["ignore", logFd, errFd], > 269 | env: { ...process.env, __JAIT_BACKGROUND: "1" }, 270 | windowsHide: true, 271 | });

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.68

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.67

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.66

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.65

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.64

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.63

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.62

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.49

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.48

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.