← Home

@juspay/shooter

Bidirectional communication server for Claude Code and iOS — push notifications, remote terminal, session viewing

17
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

balaganesh_juspayitadminmurdoregeorgejamessahil_sinhadhineshrksswaroopvarma2359

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.g02G0hlL.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.rri2K7zq.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/D8sAtVC-.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.COrzaySY.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.sGijgjBd.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.DfVtwT6x.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.DFkQ9bmS.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.BkFDeNg9.js AI (source-diff): Standard SvelteKit/Vite minified build output; expected artifact for this package. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.Deb3vtJl.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.Bfisx3a0.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/C2yx8lo8.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.CbIw97FV.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.DGStHrkF.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.CEiUUm74.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.CS_KYbQ7.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.DVFe_SN2.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscated malware. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.DetO0mOw.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.yF5DyySX.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.BiyoREYq.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.CYSmE4eH.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.YxEM6HVV.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.Bj2gzFb0.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.DzMPM9CG.js AI (source-diff): Standard SvelteKit/Vite minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.BvjUfHnH.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.CTqUQKSN.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.Bqul0XyM.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/0.B_E4j3MX.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.zJvbFXsj.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.1fMlGdqv.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.Bs1DrW0_.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.5K7Od8ba.js AI (source-diff): Standard SvelteKit minified build output; not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.C9533L9p.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/BX6TUKUr.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.nFNxeHLO.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.LI1n0A_s.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.BBF3ti4G.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.BW3qRNSj.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.BJ2KZBR0.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.Vq2hU4jC.js AI (source-diff): Standard SvelteKit/Vite minified build output; readable component logic visible in samples. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.bF7rX0-f.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/C9URPhwn.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.BRJS3bSR.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9._gEbLeEN.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.DtjRdVVT.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.cNNZm7gF.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.DSMOdSb2.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.DW-JPzyt.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/0.5I21KR7K.js AI (source-diff): Standard SvelteKit/Vite minified build output; readable UI component logic visible in samples. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/CrVuYlkB.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.CWzZbNpA.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.CgvPBG9m.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.CUnGGKik.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.Co1ngwGh.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/4.pRflZhvu.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.CKjSEOom.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/0.Bi3XYMSu.js AI (source-diff): Standard SvelteKit/Vite minified build output; readable HTML/CSS content visible in samples. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.CU7KVZja.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/BIaXC2t9.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.BPL-HzUX.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.DIkXVP4q.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/4.C25c5hMg.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.IgEqce53.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.Cm269yzt.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/DZvnhU_8.js AI (source-diff): Standard SvelteKit/Vite minified chunk output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/DYuMZGL5.js AI (source-diff): Standard SvelteKit/Vite minified chunk output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/Cg3dlX05.js AI (source-diff): Standard SvelteKit/Vite minified chunk output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/BFXEYMV8.js AI (source-diff): Standard SvelteKit/Vite minified chunk output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.BSleOtKF.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.Dp9YhfEg.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.YJZruh1H.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.VV-tRemY.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/4.BSVqdrrD.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.Cfj35gpY.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.CDJA8Na9.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.BX9znBYU.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.CmdrNdfj.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.CjYdYDhF.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.BSGzQPKE.js AI (source-diff): Standard SvelteKit minified build output; not obfuscated malware. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.CVaviSxa.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/4.DgZG6DiA.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.BsPQpbNC.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.DqlYBRxO.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.C-mKfSQ6.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/780RSrro.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.CWs7RaU8.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.ueUUTVo4.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/B-aj0tWo.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/BDcFu3l7.js AI (source-diff): Standard SvelteKit minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.Y_8EIs9h.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.DijtBcpt.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.DDMVIiVk.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.BN2SM61w.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.rBWJMWFr.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.dWYUfDXP.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/Dfn9ME_a.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.C23A4_LP.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.BoJIHqox.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.C6bLGWQR.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/4.DEAcwl7l.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.3yohCM25.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/0.D2YR8tTD.js AI (source-diff): Standard SvelteKit/Vite minified build output; readable UI code visible in samples. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.CyRB2euU.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/DVkn4r72.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/CZHsSL_X.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/CQjSATpv.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/B5NAKyil.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/B-K5Sh65.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.Z3zMnuSx.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.BPMfwzd2.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.ByTzlA2D.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/4.B_pbOZoD.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.DLyiS7a7.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.BDETv_rs.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.jzwOIQUM.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.Cuv-AoHz.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.C_uZdnK8.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.CdLPNo5-.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.CYU2wJvk.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.BAtXcLWF.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/0.B76xpgU3.js AI (source-diff): Standard SvelteKit/Vite minified build output; readable UI component logic visible in sample. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2._DiTJ6NZ.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.JmYAqwbO.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.CT86dtkE.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.C9odxWmO.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.BnaLvG49.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/5.DRvLQ5NR.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/4.BcK1571T.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/3MMtouT7.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.BpFIHCgE.js AI (source-diff): Standard SvelteKit/Vite minified bundle output, not obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/2.CzexDbwp.js AI (source-diff): Standard SvelteKit/Vite minified build output; not malicious obfuscation. ai
source-diff obfuscated-file:build/client/_app/immutable/chunks/BEa4nlMF.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/entry/app.CP7226A7.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/9.gV8oJWv_.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/8.D4AzZWcq.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/7.DfniCleW.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/6.C4aXlZQd.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
source-diff obfuscated-file:build/client/_app/immutable/nodes/3.DC3WghxB.js AI (source-diff): Standard SvelteKit/Vite minified build output. ai
install-scripts install-script:preinstall AI (install-scripts): npx only-allow pnpm is a standard package manager enforcement pattern, not malicious. ai
semgrep semgrep:child-process-import AI (semgrep): Terminal emulator tool legitimately needs child_process to spawn shells and run commands. ai
phantom-deps phantom-dep:@juspay/svelte-ui-components AI (phantom-deps): Same-org Svelte component library used in Svelte templates; phantom-dep heuristic misses template imports. ai
phantom-deps phantom-dep:jsonwebtoken AI (phantom-deps): JWT library likely used indirectly via config/server; stable false positive for this package. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): tsx is used in the start script (tsx server.ts); phantom-dep heuristic misses script-only usage. ai
semgrep semgrep:base64-decode AI (semgrep): Image paste endpoint decodes base64 with explicit round-trip validation; benign use case. ai
install-scripts install-script:postinstall AI (install-scripts): Rebuilds node-pty and better-sqlite3 native bindings — standard pattern for terminal/SQLite packages. ai
semgrep semgrep:dynamic-require AI (semgrep): Loads own package.json via path.join — not arbitrary user input; stable false positive for this package. ai
semgrep semgrep:env-spread AI (semgrep): Spreading process.env when spawning child processes is expected for a terminal/server tool passing environment to subprocesses. ai

Versions (showing 17 of 17)

Version Deps Published
1.13.0 16 / 32
1.11.0 16 / 32
1.10.0 16 / 32
1.9.3 16 / 32
1.9.2 16 / 32
1.9.1 16 / 32
1.9.0 17 / 32
1.8.0 17 / 32
1.7.1 17 / 32
1.7.0 17 / 32
1.6.2 17 / 32
1.5.0 17 / 30
1.4.0 17 / 30
1.3.0 17 / 30
1.2.0 17 / 30
1.1.0 17 / 30
1.0.0 17 / 24

v1.13.0

14 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.Vq2hU4jC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.C9533L9p.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.BSVqdrrD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.Cfj35gpY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.BJ2KZBR0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.BW3qRNSj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.BBF3ti4G.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.LI1n0A_s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.nFNxeHLO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BDcFu3l7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BX6TUKUr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/Cg3dlX05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DYuMZGL5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.11.0

14 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.DW-JPzyt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.bF7rX0-f.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.BSVqdrrD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.Cfj35gpY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.DSMOdSb2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.cNNZm7gF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.DtjRdVVT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9._gEbLeEN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.BRJS3bSR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BDcFu3l7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/C9URPhwn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/Cg3dlX05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DYuMZGL5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.0

15 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.YJZruh1H.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.VV-tRemY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.BSVqdrrD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.Cfj35gpY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.CDJA8Na9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.BX9znBYU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.CmdrNdfj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.BSleOtKF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.Dp9YhfEg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BDcFu3l7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BFXEYMV8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/Cg3dlX05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DYuMZGL5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DZvnhU_8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.3

14 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.DzMPM9CG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.Bj2gzFb0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.BSVqdrrD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.Cfj35gpY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.YxEM6HVV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.CYSmE4eH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.BiyoREYq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.DetO0mOw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.yF5DyySX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BDcFu3l7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/Cg3dlX05.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DYuMZGL5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DZvnhU_8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.2

13 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.BSGzQPKE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.CVaviSxa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.DgZG6DiA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.BsPQpbNC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.DqlYBRxO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.C-mKfSQ6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/780RSrro.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.CWs7RaU8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.CjYdYDhF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.ueUUTVo4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/B-aj0tWo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BDcFu3l7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.1

10 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.dWYUfDXP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.rBWJMWFr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.BN2SM61w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.DDMVIiVk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.DijtBcpt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.Y_8EIs9h.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.BoJIHqox.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.C23A4_LP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/Dfn9ME_a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.0

10 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.DVFe_SN2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.Deb3vtJl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.BN2SM61w.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.CS_KYbQ7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.CEiUUm74.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.DGStHrkF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.CbIw97FV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.Bfisx3a0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/C2yx8lo8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.0

9 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2.CzexDbwp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.DC3WghxB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.C4aXlZQd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.DfniCleW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.D4AzZWcq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.gV8oJWv_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.CP7226A7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BEa4nlMF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.1

8 findings
HIGH Package has 'postinstall' script install-scripts

Script: node-gyp rebuild --directory=node_modules/node-pty --loglevel=silent > /dev/null 2>&1 || echo '⚠ node-pty build failed — terminal features will not work. Install build tools: macOS: xcode-select --install | Linux: apt install python3 make g++'; node-gyp rebuild --directory=node_modules/better-sqlite3 --loglevel=silent > /dev/null 2>&1 || echo '⚠ better-sqlite3 build failed — terminal persistence will not work.'

HIGH env-spread: bin/shooter.cjs:257 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/juspay/shooter/blob/143727452b22ce5288375150e76e643bc7aae697/bin/shooter.cjs#L257 255 | detached: true, 256 | stdio: ['ignore', logFd, logFd], > 257 | env: { 258 | ...process.env, 259 | SHOOTER_PKG_ROOT: PKG_ROOT,

HIGH env-spread: bin/shooter.cjs:293 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/juspay/shooter/blob/143727452b22ce5288375150e76e643bc7aae697/bin/shooter.cjs#L293 291 | cwd: PKG_ROOT, 292 | stdio: 'inherit', > 293 | env: { 294 | ...process.env, 295 | SHOOTER_PKG_ROOT: PKG_ROOT,

HIGH env-spread: bin/shooter.cjs:665 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/juspay/shooter/blob/143727452b22ce5288375150e76e643bc7aae697/bin/shooter.cjs#L665 663 | cwd: process.cwd(), 664 | stdio: 'inherit', > 665 | env: { 666 | ...process.env, 667 | SHOOTER_PKG_ROOT: PKG_ROOT,

HIGH env-spread: scripts/dev.mjs:129 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/juspay/shooter/blob/143727452b22ce5288375150e76e643bc7aae697/scripts/dev.mjs#L129 127 | cwd: PKG_ROOT, 128 | stdio: 'inherit', > 129 | env: { ...process.env }, 130 | }); 131 | proc.on('exit', (code) => {

HIGH env-spread: scripts/dev.mjs:169 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/juspay/shooter/blob/143727452b22ce5288375150e76e643bc7aae697/scripts/dev.mjs#L169 167 | cwd: PKG_ROOT, 168 | stdio: 'inherit', > 169 | env: { 170 | ...process.env, 171 | PORT: String(PORT),

HIGH env-spread: src/lib/modules/server/terminal/pty-holder.cjs:107 semgrep

Spreading entire process.env into an object — may capture all secrets Source: https://github.com/juspay/shooter/blob/143727452b22ce5288375150e76e643bc7aae697/src/lib/modules/server/terminal/pty-holder.cjs#L107 105 | const SHELL_COMMANDS = ['zsh', 'bash', 'sh', 'fish']; 106 | const commandBase = command.split('/').pop() || command; > 107 | const ptyEnv = { ...process.env }; 108 | 109 | // Clipboard image paste support: per-terminal clipboard directory

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

10 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/2._DiTJ6NZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.BpFIHCgE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/3MMtouT7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.BcK1571T.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.DRvLQ5NR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.BnaLvG49.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.C9odxWmO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.CT86dtkE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.JmYAqwbO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.2

11 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/0.B76xpgU3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/2.BAtXcLWF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.CYU2wJvk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.B_pbOZoD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.CdLPNo5-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.C_uZdnK8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.Cuv-AoHz.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/8.jzwOIQUM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/9.BDETv_rs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.DLyiS7a7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

14 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/0.Bi3XYMSu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/2.Cm269yzt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.3yohCM25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.C25c5hMg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.DIkXVP4q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.BPL-HzUX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.IgEqce53.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.CU7KVZja.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/B5NAKyil.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BIaXC2t9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CQjSATpv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CZHsSL_X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DVkn4r72.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

14 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/0.ejabgzDQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/2.DV3saFiY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.3yohCM25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.D6NIf10D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.g3R-QfIW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.DSpd_nYK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.F9WBFTz2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.DwWiuoEC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/B5NAKyil.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/BN1NjBrw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CQjSATpv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CZHsSL_X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DVkn4r72.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

14 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/0.5I21KR7K.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/2.CKjSEOom.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.3yohCM25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.pRflZhvu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.Co1ngwGh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.CUnGGKik.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.CgvPBG9m.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.CWzZbNpA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/B5NAKyil.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CQjSATpv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CrVuYlkB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CZHsSL_X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DVkn4r72.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

14 findings
HIGH New obfuscated file: build/client/_app/immutable/nodes/0.D2YR8tTD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/2.CyRB2euU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/3.3yohCM25.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/4.DEAcwl7l.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/5.C6bLGWQR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/6.ByTzlA2D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/nodes/7.BPMfwzd2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/entry/app.Z3zMnuSx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/B-K5Sh65.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/B5NAKyil.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CQjSATpv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/CZHsSL_X.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/client/_app/immutable/chunks/DVkn4r72.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

2 findings
HIGH Package has 'preinstall' script install-scripts

Script: npx only-allow pnpm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.