@kb-labs/studio-app
KB Labs Studio application
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/main.ccfa9d7c.js | AI (source-diff): Bundled frontend app naturally contains fetch + eval-like patterns from deps; no concrete malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/main.ccfa9d7c.js | AI (source-diff): Standard webpack/rspack minified bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.5ab9b765.js | AI (source-diff): Webpack-bundled frontend app code, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.5ab9b765.js | AI (source-diff): Pattern match on bundled build output, not a dropper. | ai | |
| source-diff | net-exec-file:dist/main.6d74fbe7.js | AI (source-diff): Bundled frontend app code; network+eval patterns are from UI libs, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/main.6d74fbe7.js | AI (source-diff): Webpack/rspack bundle of antd+UI deps, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.c282c309.js | AI (source-diff): Pattern hit on large legit bundle (antd/rspack app), no dropper behavior shown. | ai | |
| source-diff | obfuscated-file:dist/main.c282c309.js | AI (source-diff): Webpack-bundled minified frontend code, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.9bcc599c.js | AI (source-diff): Generic pattern match on bundled SPA code, no fetched/executed payload found. | ai | |
| source-diff | obfuscated-file:dist/main.9bcc599c.js | AI (source-diff): Webpack-bundled frontend app output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.98f0cac0.js | AI (source-diff): Bundled webpack/rspack build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.98f0cac0.js | AI (source-diff): False positive on bundled frontend app code, no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/main.8ce0f6be.js | AI (source-diff): Webpack/rspack bundled output, not true obfuscation (sample is standard antd color utils). | ai | |
| source-diff | net-exec-file:dist/main.8ce0f6be.js | AI (source-diff): Bundled frontend app code; no exfil/dropper behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/main.e2dd3ec0.js | AI (source-diff): Webpack/rspack bundle output (antd theming code visible), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.e2dd3ec0.js | AI (source-diff): Bundled frontend app code; no concrete malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/main.90e4945f.js | AI (source-diff): Bundled webpack/rspack output for a large React/antd app, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.90e4945f.js | AI (source-diff): Bundled frontend chunk; network+eval patterns are from bundled libs, not malicious code. | ai | |
| source-diff | obfuscated-file:dist/main.20db6ed1.js | AI (source-diff): Webpack bundle of antd/react app; long minified lines, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.20db6ed1.js | AI (source-diff): Bundled frontend app naturally contains fetch + eval-like patterns from deps; no malicious target found. | ai | |
| source-diff | net-exec-file:dist/main.e845eb60.js | AI (source-diff): Bundled frontend app code, net+exec pattern from normal libs, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/main.e845eb60.js | AI (source-diff): Webpack/rspack bundle of antd UI code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.c46233f9.js | AI (source-diff): Webpack-minified antd/react bundle, not true obfuscation — confirmed via sample. | ai | |
| source-diff | net-exec-file:dist/main.c46233f9.js | AI (source-diff): Bundled frontend app code, no fetched-binary/dropper behavior evident. | ai | |
| source-diff | net-exec-file:dist/main.64272114.js | AI (source-diff): Bundled frontend app code, not a dropper/loader. | ai | |
| source-diff | obfuscated-file:dist/main.64272114.js | AI (source-diff): Bundled webpack output (antd/rc-util code), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.21c70340.js | AI (source-diff): Bundled UI code (antd colors etc.), no dropper/loader behavior present. | ai | |
| source-diff | obfuscated-file:dist/main.21c70340.js | AI (source-diff): Webpack-bundled frontend app output, not true obfuscation (no _0x/eval-atob patterns). | ai | |
| source-diff | obfuscated-file:dist/main.37c37ea4.js | AI (source-diff): Webpack/rspack bundle output, not true obfuscation; sample shows plain minified color utils. | ai | |
| source-diff | net-exec-file:dist/main.37c37ea4.js | AI (source-diff): Same bundled dist file, false positive from minified code density, not a dropper. | ai | |
| source-diff | net-exec-file:dist/main.98dc4449.js | AI (source-diff): Minified frontend bundle; network+eval patterns are normal in UI framework code. | ai | |
| source-diff | obfuscated-file:dist/main.98dc4449.js | AI (source-diff): Bundled webpack/rspack build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.be6a405e.js | AI (source-diff): Webpack-bundled frontend chunk (antd/react-query), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.be6a405e.js | AI (source-diff): Bundled app code, not a dropper; matches package's React/antd stack. | ai | |
| source-diff | net-exec-file:dist/main.231198dd.js | AI (source-diff): Same bundled frontend file; network+eval patterns from bundler runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/main.231198dd.js | AI (source-diff): Rspack/webpack bundle output (antd/module-federation code visible), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.f0e7ecfd.js | AI (source-diff): Webpack-bundled minified output, not true obfuscation; sample shows benign color utils. | ai | |
| source-diff | net-exec-file:dist/main.f0e7ecfd.js | AI (source-diff): Bundled frontend app code, pattern-matches on minified bundle not real net+exec. | ai | |
| source-diff | obfuscated-file:dist/main.0d3d4b7a.js | AI (source-diff): Bundled webpack/rspack output (antd theme code), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.0d3d4b7a.js | AI (source-diff): Bundled minified frontend code, no fetched-binary or credential-exfil behavior observed. | ai | |
| source-diff | obfuscated-file:dist/main.563fdfce.js | AI (source-diff): Standard webpack/rspack minified bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.563fdfce.js | AI (source-diff): Bundled frontend app code; sample shows antd color utils, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/main.093308e3.js | AI (source-diff): Webpack/rspack bundle of antd/react UI code, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.093308e3.js | AI (source-diff): Bundled frontend app code, no concrete exfil/exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/main.f8efdc05.js | AI (source-diff): Minified rspack/webpack bundle output, not true obfuscation; sample shows standard antd utility code. | ai | |
| source-diff | net-exec-file:dist/main.f8efdc05.js | AI (source-diff): Bundled frontend app code, not a dropper; pattern-matches on minified network/eval usage in vendored libs. | ai | |
| source-diff | obfuscated-file:dist/main.0f9bfdbe.js | AI (source-diff): Webpack-bundled frontend output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.0f9bfdbe.js | AI (source-diff): Bundled React/antd app code, no evidence of dropper behavior. | ai | |
| source-diff | net-exec-file:dist/main.73bbb774.js | AI (source-diff): Bundled frontend app code (antd/react), no malicious network+exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/main.73bbb774.js | AI (source-diff): Minified webpack/rspack bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.a1cfecb6.js | AI (source-diff): Same bundled file; pattern-match on minified code, no actual network+exec malicious behavior shown. | ai | |
| source-diff | obfuscated-file:dist/main.a1cfecb6.js | AI (source-diff): Bundled antd/rspack output, not true obfuscation; sample shows standard minified color utility code. | ai | |
| source-diff | net-exec-file:dist/main.55d1b43e.js | AI (source-diff): Bundled frontend app code, network calls are normal app fetch/router logic, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/main.55d1b43e.js | AI (source-diff): Bundled rspack/webpack output (antd/module-federation), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.dbb7476c.js | AI (source-diff): Webpack/rspack bundle output (visible module banner, antd code), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.dbb7476c.js | AI (source-diff): Bundled frontend app code; network+eval patterns are standard bundler/runtime artifacts. | ai | |
| source-diff | obfuscated-file:dist/main.d1c607ff.js | AI (source-diff): Bundled rspack/webpack output, not true obfuscation — sample is minified antd color utils. | ai | |
| source-diff | net-exec-file:dist/main.d1c607ff.js | AI (source-diff): Same bundled file; network+exec pattern from bundled deps, no malicious behavior shown. | ai | |
| source-diff | net-exec-file:dist/main.e975c83a.js | AI (source-diff): Bundled frontend chunk; network+eval patterns are bundler artifacts, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/main.e975c83a.js | AI (source-diff): Webpack/rspack bundle output (antd chunk), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.1d68e922.js | AI (source-diff): Bundled frontend chunk (antd utils), no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/main.1d68e922.js | AI (source-diff): Webpack/rspack bundled output with sourcemap, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.548ebad3.js | AI (source-diff): Standard webpack/rspack bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.548ebad3.js | AI (source-diff): Bundled frontend app code, no actual dropper/loader behavior in sample. | ai | |
| source-diff | net-exec-file:dist/main.5e93a5f0.js | AI (source-diff): Bundled frontend code, sample shows standard UI library logic. | ai | |
| source-diff | obfuscated-file:dist/main.5e93a5f0.js | AI (source-diff): Webpack/rspack bundled output for a React app, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.4c7b580a.js | AI (source-diff): Minified bundle of a web app; fetch+eval patterns are framework runtime, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/main.4c7b580a.js | AI (source-diff): Webpack/rspack bundled React app output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.226fbdb1.js | AI (source-diff): Bundled webpack/rspack output (antd/react libs), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.226fbdb1.js | AI (source-diff): Frontend bundle chunk, no actual network+exec malicious behavior found. | ai | |
| source-diff | obfuscated-file:dist/main.08802988.js | AI (source-diff): Webpack/rspack bundle output, readable library code (antd color utils), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.08802988.js | AI (source-diff): Bundled frontend app code; network+eval patterns are from bundled libs, not injected malware. | ai | |
| source-diff | obfuscated-file:dist/main.68d6f0f6.js | AI (source-diff): Webpack-bundled minified output (antd/theme code), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.68d6f0f6.js | AI (source-diff): Same bundled dist file; sample shows minified UI lib code, no exfil/exec behavior. | ai | |
| source-diff | obfuscated-file:dist/main.1093c5b5.js | AI (source-diff): Webpack/rspack bundle output (antd source visible), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.1093c5b5.js | AI (source-diff): Bundled frontend app code, no malicious network/exec payload found in sample. | ai | |
| source-diff | net-exec-file:dist/main.6dfdb044.js | AI (source-diff): Same bundled file; no concrete malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:dist/main.6dfdb044.js | AI (source-diff): Webpack-bundled build output (antd/rspack), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.b49e2680.js | AI (source-diff): Webpack-bundled minified output (antd/react libs), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.b49e2680.js | AI (source-diff): Bundled frontend app code, no evidence of dropper/loader behavior. | ai | |
| source-diff | obfuscated-file:dist/main.c1f3c947.js | AI (source-diff): Bundled rspack/webpack output, not true obfuscation; sample shows normal antd color utils. | ai | |
| source-diff | net-exec-file:dist/main.c1f3c947.js | AI (source-diff): False positive on bundled frontend app code, no malicious network/exec behavior shown. | ai | |
| source-diff | net-exec-file:dist/main.aa907bf2.js | AI (source-diff): Bundled frontend app code, no hostile network/exec behavior observed. | ai | |
| source-diff | obfuscated-file:dist/main.aa907bf2.js | AI (source-diff): Webpack/rspack bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.f53bedf8.js | AI (source-diff): Webpack-bundled antd/UI code, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.f53bedf8.js | AI (source-diff): False positive on minified bundle, no malicious payload found. | ai | |
| provenance | missing-githead | AI (provenance): Provenance direction unchanged; consistent with prior publishes for this package. | ai | |
| source-diff | obfuscated-file:dist/main.86485e47.js | AI (source-diff): Webpack/rspack bundle output (ant-design color utils visible), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.86485e47.js | AI (source-diff): Same bundled frontend chunk; no malicious network/exec behavior found in sample. | ai | |
| source-diff | obfuscated-file:dist/main.ba55ee8f.js | AI (source-diff): Webpack/rspack bundled frontend output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.ba55ee8f.js | AI (source-diff): Bundled UI code (antd/reactflow), no evidence of dropper behavior. | ai | |
| source-diff | net-exec-file:dist/main.4608c1a9.js | AI (source-diff): Bundled frontend app code, sample shows legit UI lib code not a dropper. | ai | |
| source-diff | obfuscated-file:dist/main.4608c1a9.js | AI (source-diff): Webpack/rspack bundle output (antd/plots), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.0c51fbec.js | AI (source-diff): Bundled frontend app code, no evidence of dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/main.0c51fbec.js | AI (source-diff): Webpack-bundled antd/react code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.f818c531.js | AI (source-diff): Bundled webpack/rspack output (antd/color utils), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.f818c531.js | AI (source-diff): Bundled frontend chunk; no concrete malicious network/exec behavior shown. | ai | |
| source-diff | net-exec-file:dist/main.d0234626.js | AI (source-diff): Bundled frontend app code, no evidence of dropper/exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/main.d0234626.js | AI (source-diff): Webpack/rspack bundle output (antd color helpers), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.18bf5235.js | AI (source-diff): False positive from bundled network/UI libs (react-query, router) in minified build. | ai | |
| source-diff | obfuscated-file:dist/main.18bf5235.js | AI (source-diff): Bundled webpack/rspack output (antd theme utils), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.d2d0fd74.js | AI (source-diff): Bundled frontend app code; sample shows normal UI lib code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/main.d2d0fd74.js | AI (source-diff): Standard webpack/rspack minified bundle, not true obfuscation (no _0x/eval-atob patterns). | ai | |
| source-diff | net-exec-file:dist/main.19aa8c57.js | AI (source-diff): Network+exec pattern in a React SPA webpack bundle is expected; no hostile destination or dropper behavior visible. | ai | |
| source-diff | obfuscated-file:dist/main.19aa8c57.js | AI (source-diff): Standard webpack/rspack bundle output; sample shows antd color utilities, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.ce22bb43.js | AI (source-diff): Standard webpack bundle (Ant Design/React app); long lines are minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.ce22bb43.js | AI (source-diff): Network calls and dynamic execution are expected in a React SPA webpack bundle; no hostile destination or dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/main.dba1b580.js | AI (source-diff): Standard webpack bundle output; sample shows Ant Design color utilities, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.dba1b580.js | AI (source-diff): Network+exec pattern in a frontend app bundle is expected; no hostile destination or dropper behavior visible. | ai | |
| source-diff | obfuscated-file:dist/main.ab7bbf79.js | AI (source-diff): Standard webpack/rspack bundle output for a React+antd app; not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.ab7bbf79.js | AI (source-diff): Network+eval pattern is normal for webpack runtime module loading in a bundled SPA. | ai | |
| source-diff | net-exec-file:dist/main.97660e1d.js | AI (source-diff): Network calls and dynamic execution in a React SPA bundle are expected; no hostile destination or dropper behavior visible. | ai | |
| source-diff | obfuscated-file:dist/main.97660e1d.js | AI (source-diff): Standard webpack/rspack bundle output; long lines are minified React app code, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.c260f39a.js | AI (source-diff): Network calls and dynamic requires are normal in a React SPA webpack bundle; no hostile destination or dropper behavior visible. | ai | |
| source-diff | obfuscated-file:dist/main.c260f39a.js | AI (source-diff): Standard webpack bundle output; __webpack_modules__ preamble confirms bundled artifact, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.65c9d0bc.js | AI (source-diff): Network calls and dynamic execution are expected in a React SPA bundle; no hostile destination or dropper behavior visible. | ai | |
| source-diff | obfuscated-file:dist/main.65c9d0bc.js | AI (source-diff): Standard webpack/rspack bundle output for a React SPA; long lines are minified build artifacts, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/main.c14f35f3.js | AI (source-diff): Webpack bundle output with clear module structure; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/main.c14f35f3.js | AI (source-diff): Bundled React app with network calls and dynamic imports; normal for this package. | ai | |
| source-diff | net-exec-file:dist/main.ad42ef4a.js | AI (source-diff): Webpack bundle naturally contains network calls and dynamic requires; no hostile payload. | ai | |
| source-diff | obfuscated-file:dist/main.ad42ef4a.js | AI (source-diff): Webpack bundle output (rspack build); not obfuscation. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Full app bundle shipped in dist/; size consistent with React+Ant Design app. | ai | |
| source-diff | net-exec-file:dist/main.270b6745.js | AI (source-diff): Network+exec pattern fires on webpack bundle; no concrete malicious behavior visible in sample. | ai | |
| source-diff | obfuscated-file:dist/main.270b6745.js | AI (source-diff): Standard webpack bundle output; sample shows Ant Design color palette logic, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:@kb-labs/core-contracts | AI (phantom-deps): Same-org contract package; consistent with other @kb-labs/* phantom deps in this package. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-federation | AI (phantom-deps): Same-org package; consistent pattern with other @kb-labs/* phantom deps. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-plugin-tools | AI (phantom-deps): Same-org package; consistent pattern with other @kb-labs/* phantom deps. | ai | |
| source-diff | net-exec-file:dist/main.9d8162c2.js | AI (source-diff): Bundled React app with fetch calls and eval-like patterns from webpack runtime; not malicious. | ai | |
| source-diff | obfuscated-file:dist/main.9d8162c2.js | AI (source-diff): Webpack/rspack production bundle; minification is expected for this frontend app. | ai | |
| phantom-deps | phantom-dep:dayjs | AI (phantom-deps): Well-known date library; phantom-dep heuristic false positive for this bundled app package. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): Well-known icon library; phantom-dep heuristic false positive for this bundled app package. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Legitimate routing dep; phantom-dep heuristic false positive for this bundled app package. | ai | |
| phantom-deps | phantom-dep:@ant-design/icons | AI (phantom-deps): Legitimate Ant Design dep; phantom-dep heuristic false positive for this bundled app package. | ai | |
| phantom-deps | phantom-dep:@ant-design/plots | AI (phantom-deps): Legitimate Ant Design dep; phantom-dep heuristic false positive for this bundled app package. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-hooks | AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-ui-kit | AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-event-bus | AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-ui-core | AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-devtools | AI (phantom-deps): Same-org sibling package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): Well-known utility; phantom-dep heuristic false positive for this bundled app package. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Declared runtime dep in a UI app; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/rest-api-contracts | AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/quality-contracts | AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@types/react-grid-layout | AI (phantom-deps): Type definitions; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/agent-contracts | AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/qa-contracts | AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@ant-design/charts | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react-grid-layout | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react-resizable | AI (phantom-deps): Peer dep of react-grid-layout; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Build config pattern: only forwards KB_-prefixed env vars into the bundle, not a credential leak. | ai | |
| phantom-deps | phantom-dep:@kb-labs/release-manager-contracts | AI (phantom-deps): Same-org contract package; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Bundled app ships compiled output; peer deps declared but not directly imported is expected. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Same as react — bundled app pattern. | ai | |
| phantom-deps | phantom-dep:antd | AI (phantom-deps): Bundled app; antd used in compiled output, not directly imported in analyzed entry. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Bundled app pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query-devtools | AI (phantom-deps): Bundled app pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Bundled app pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:zustand | AI (phantom-deps): Bundled app pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:reactflow | AI (phantom-deps): Bundled app pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@kb-labs/workflow-contracts | AI (phantom-deps): Same-org monorepo dep; bundled app pattern. | ai | |
| phantom-deps | phantom-dep:@kb-labs/studio-data-client | AI (phantom-deps): Same-org monorepo dep; bundled app pattern. | ai |
Versions (showing 71 of 71)
| Version | Deps | Published |
|---|---|---|
| 2.96.0 | 35 / 23 | |
| 2.94.0 | 34 / 19 | |
| 2.93.0 | 34 / 19 | |
| 2.89.0 | 34 / 19 | |
| 2.88.0 | 34 / 19 | |
| 2.87.0 | 34 / 19 | |
| 2.82.0 | 34 / 19 | |
| 2.81.0 | 34 / 19 | |
| 2.80.0 | 34 / 19 | |
| 2.79.0 | 34 / 19 | |
| 2.78.0 | 34 / 19 | |
| 2.77.0 | 34 / 19 | |
| 2.75.0 | 34 / 19 | |
| 2.74.0 | 34 / 19 | |
| 2.73.0 | 34 / 19 | |
| 2.72.0 | 34 / 19 | |
| 2.69.0 | 34 / 19 | |
| 2.68.0 | 34 / 19 | |
| 2.67.0 | 34 / 19 | |
| 2.66.0 | 34 / 19 | |
| 2.65.0 | 34 / 19 | |
| 2.64.0 | 34 / 19 | |
| 2.63.0 | 34 / 19 | |
| 2.62.0 | 34 / 19 | |
| 2.61.0 | 34 / 19 | |
| 2.60.0 | 34 / 19 | |
| 2.59.0 | 34 / 19 | |
| 2.58.0 | 34 / 19 | |
| 2.57.0 | 34 / 19 | |
| 2.56.0 | 34 / 19 | |
| 2.55.0 | 34 / 19 | |
| 2.54.0 | 34 / 19 | |
| 2.53.0 | 34 / 19 | |
| 2.47.0 | 34 / 19 | |
| 2.46.0 | 34 / 19 | |
| 2.45.0 | 34 / 19 | |
| 2.44.0 | 34 / 19 | |
| 2.43.0 | 34 / 19 | |
| 2.42.0 | 34 / 19 | |
| 2.41.0 | 34 / 19 | |
| 2.40.0 | 34 / 19 | |
| 2.39.0 | 34 / 19 | |
| 2.38.0 | 34 / 19 | |
| 2.37.0 | 34 / 19 | |
| 2.36.0 | 34 / 19 | |
| 2.35.0 | 34 / 19 | |
| 2.34.0 | 34 / 19 | |
| 2.33.0 | 34 / 19 | |
| 2.32.0 | 34 / 19 | |
| 2.31.0 | 34 / 19 | |
| 2.30.0 | 34 / 19 | |
| 2.29.0 | 34 / 19 | |
| 2.28.0 | 34 / 19 | |
| 2.25.0 | 34 / 19 | |
| 2.23.0 | 34 / 19 | |
| 2.22.0 | 34 / 19 | |
| 2.20.0 | 34 / 19 | |
| 2.19.0 | 34 / 19 | |
| 2.18.0 | 34 / 19 | |
| 2.17.0 | 34 / 19 | |
| 2.16.0 | 34 / 19 | |
| 2.15.0 | 34 / 19 | |
| 2.14.0 | 34 / 19 | |
| 2.13.0 | 34 / 19 | |
| 2.12.0 | 34 / 19 | |
| 2.11.0 | 34 / 19 | |
| 2.10.0 | 34 / 19 | |
| 2.9.0 | 34 / 19 | |
| 2.8.0 | 34 / 19 | |
| 0.7.0 | 34 / 18 | |
| 0.6.0 | 34 / 18 |
v2.96.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: k.baranov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.61.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: k.baranov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.