@karmaniverous/jeeves-server
Secure file browser, markdown viewer, and webhook gateway with PDF/DOCX export and expiring share links
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/assets/dist-0pOBo8wt.js | AI (source-diff): Vite-bundled client asset (CodeMirror PHP parser); minification not obfuscation. | ai | |
| dependencies | unvetted-dep:handlebars | AI (dependencies): Handlebars is a well-known templating library; appropriate for a document/webhook server. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-C_PQpm_N.js | AI (source-diff): Vite-bundled main client entry; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-rUfypgix.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-EPHCOYNX.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DOKNVU_k.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DKSus5Ak.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DHNNYcn4.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DfL6l3pM.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-Ddlbpt-q.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DCWNwDe0.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-D35I7-CB.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-D0sOHJnp.js | AI (source-diff): Vite-bundled client asset; minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CnX9mGMh.js | AI (source-diff): Vite-bundled client asset (CodeMirror core); minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CEElqQqJ.js | AI (source-diff): Vite-bundled client asset (CodeMirror JS parser); minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-Cb80Np1x.js | AI (source-diff): Vite-bundled client asset (CodeMirror Java parser); minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BXnUhIwe.js | AI (source-diff): Vite-bundled client asset (CodeMirror Markdown parser); minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BHz8En0G.js | AI (source-diff): Vite-bundled client asset (CodeMirror CSS parser); minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BgscYTmP.js | AI (source-diff): Vite-bundled client asset (CodeMirror HTML parser); minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-B1640Z3y.js | AI (source-diff): Vite-bundled client asset (CodeMirror style system); minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DPDX8dxi.js | AI (source-diff): Standard Vite-minified React bundle; content matches documented React+Fastify client build output. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DBaNIFAP.js | AI (source-diff): Vite-bundled React client asset; minification is expected for this package's shipped client dist. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is a same-author sibling package (@karmaniverous/jeeves); not a suspicious third-party addition. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BmxPZIsp.js | AI (source-diff): Standard Vite-bundled React/CodeMirror client assets; minification is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-R1YbG5X7.js | AI (source-diff): Standard Vite-minified React bundle produced by documented postbuild step; not obfuscated malware. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a widely-used, well-maintained markdown renderer; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-RwiCz0wb.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-B4fmv26e.js | AI (source-diff): Vite-bundled CodeMirror/language-parser asset; minified but not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BbOYtySm.js | AI (source-diff): Vite-bundled client asset; recognizable Markdown parser code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BeJ8Lcpr.js | AI (source-diff): Vite-bundled client asset; YAML/Markdown parser code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-Bi7C8V-_.js | AI (source-diff): Vite-bundled client asset; HTML/XML parser code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BT15GdV5.js | AI (source-diff): Vite-bundled client asset; CodeMirror autocomplete code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BT6vvByO.js | AI (source-diff): Vite-bundled client asset; C++ syntax highlighter code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CCvzAXK7.js | AI (source-diff): Vite-bundled client asset; HTML completion/highlighting code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-Cli7IcpG.js | AI (source-diff): Vite-bundled client asset; Rust syntax highlighter code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-ClPtz7W4.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CUCLbnLi.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CzcHBL37.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-D1JyKg7T.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-D71D0lqY.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DJLqtADZ.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DMq_L4jh.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-JhQb_aSZ.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-n_fXZzWj.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-2nylQ6Hn.js | AI (source-diff): Vite-bundled client asset; standard minified library code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/theme-BJIt9WPo.js | AI (source-diff): Vite-bundled client asset; theme/styling code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large file count reflects bundled client assets from Vite build; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Cb0HtDxh.js | AI (source-diff): Vite-bundled React client asset; minified output is expected for this package's frontend build. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DQ5S2sJA.js | AI (source-diff): Standard Vite/React build output; minified client bundle, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-Bhum1fVN.js | AI (source-diff): Standard Vite/Rolldown minified client bundle (CodeMirror/Lezer); not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BNhDitvH.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CGmVjpPP.js | AI (source-diff): Standard Vite/Rolldown minified client bundle (style system); not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CFhlg0iW.js | AI (source-diff): Standard Vite/Rolldown minified client bundle (SQL/CSS language support); not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BWpIzcK-.js | AI (source-diff): Standard Vite/Rolldown minified client bundle (CodeMirror core); not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-BOeB7NpC.js | AI (source-diff): Standard Vite/Rolldown minified client bundle (HTML/XML parser); not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/theme-CEIf0yXG.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-B_3DMMfP.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-zhtf0_E3.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-v4ldl60X.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-uOmIiM1j.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-N2RRhqy_.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-McE6hh4E.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-kdbCzTMg.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DyCdF_s2.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DXr9H_CI.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-DP58nQuj.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CUARWWK7.js | AI (source-diff): Standard Vite/Rolldown minified client bundle; not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CR-I_L9i.js | AI (source-diff): Standard Vite/Rolldown minified client bundle (Lezer parser); not malicious. | ai | |
| source-diff | obfuscated-file:dist/client/assets/dist-CORpuw2V.js | AI (source-diff): Standard Vite/Rolldown minified client bundle (CodeMirror commands); not malicious. | ai | |
| phantom-deps | phantom-dep:puppeteer | AI (phantom-deps): puppeteer is a runtime dep used indirectly via mermaid-cli/headless rendering; stable false positive. | ai | |
| phantom-deps | phantom-dep:@commander-js/extra-typings | AI (phantom-deps): Type-only augmentation package; not directly imported but used via commander types. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall downloads PlantUML JAR via a named script; consistent with documented diagram-rendering functionality. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): All raw-IP references are in test files asserting localhost (127.0.0.1) URLs — not production network calls. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 3.13.1 | 24 / 19 | |
| 3.13.0 | 24 / 19 | |
| 3.10.15 | 22 / 18 | |
| 3.10.12 | 22 / 18 | |
| 3.10.9 | 22 / 18 | |
| 3.10.8 | 23 / 12 | |
| 3.10.7 | 23 / 12 | |
| 3.10.6 | 23 / 13 | |
| 3.10.4 | 23 / 13 | |
| 3.10.2 | 21 / 13 | |
| 3.10.1 | 21 / 13 | |
| 3.9.0 | 21 / 13 | |
| 3.8.5 | 19 / 12 | |
| 3.8.4 | 19 / 12 | |
| 3.8.2 | 19 / 12 | |
| 3.8.1 | 19 / 12 | |
| 3.8.0 | 19 / 12 | |
| 3.6.5 | 19 / 12 | |
| 3.6.4 | 19 / 12 | |
| 3.6.3 | 18 / 12 | |
| 3.6.2 | 19 / 12 | |
| 3.6.1 | 19 / 12 | |
| 3.6.0 | 19 / 12 | |
| 3.5.2 | 20 / 12 | |
| 3.5.1 | 21 / 12 |
v3.13.1
20 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.