@kong/kongponents
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/kongponents335.cjs | AI (source-diff): Minified Vue build chunk, not true obfuscation; consistent with vendor bundling. | ai | |
| source-diff | obfuscated-file:dist/kongponents105.cjs | AI (source-diff): Minified Vite/Rollup build chunk, not true obfuscation; readable Vue component source. | ai | |
| source-diff | obfuscated-file:dist/kongponents124.cjs | AI (source-diff): Same bundled build-output pattern as other flagged chunks. | ai | |
| source-diff | obfuscated-file:dist/kongponents128.cjs | AI (source-diff): Same bundled build-output pattern as other flagged chunks. | ai | |
| source-diff | obfuscated-file:dist/kongponents135.cjs | AI (source-diff): Same bundled build-output pattern as other flagged chunks. | ai | |
| source-diff | obfuscated-file:dist/kongponents141.cjs | AI (source-diff): Same bundled build-output pattern as other flagged chunks. | ai | |
| source-diff | obfuscated-file:dist/kongponents168.cjs | AI (source-diff): Same bundled build-output pattern as other flagged chunks. | ai | |
| source-diff | obfuscated-file:dist/kongponents166.cjs | AI (source-diff): Same bundled build-output pattern as other flagged chunks. | ai | |
| source-diff | obfuscated-file:dist/kongponents152.cjs | AI (source-diff): Same bundled build-output pattern as other flagged chunks. | ai | |
| source-diff | obfuscated-file:dist/kongponents27.cjs | AI (source-diff): Bundled Vite/Rollup chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents151.cjs | AI (source-diff): Bundled Vite/Rollup chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents266.cjs | AI (source-diff): Bundled Vite/Rollup chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents268.cjs | AI (source-diff): Bundled/minified Vite output, not obfuscation; matches package build. | ai | |
| source-diff | obfuscated-file:dist/kongponents339.cjs | AI (source-diff): Bundled/minified Vite output (date-fns bundle), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents378.cjs | AI (source-diff): Minified Vite/Rollup chunk output, not true obfuscation; standard bundler pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/kongponents234.cjs | AI (source-diff): Minified Vite/Rollup chunk output, not true obfuscation; standard bundler pattern for this package. | ai | |
| phantom-deps | phantom-dep:vue-bind-once | AI (phantom-deps): Platform-specific optional dependency; stable pattern for this component library. | ai | |
| phantom-deps | phantom-dep:swrv | AI (phantom-deps): Config-referenced optional dependency; stable pattern for this component library. | ai | |
| phantom-deps | phantom-dep:focus-trap | AI (phantom-deps): Config-referenced optional dependency; stable pattern for this component library. | ai | |
| phantom-deps | phantom-dep:v-calendar | AI (phantom-deps): Config-referenced optional dependency; stable pattern for this component library. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): lefthook install is a standard git-hooks dev tool, not code execution risk. | ai | |
| source-diff | obfuscated-file:dist/kongponents113.cjs | AI (source-diff): Minified build chunk. | ai | |
| source-diff | obfuscated-file:dist/kongponents107.cjs | AI (source-diff): Minified build chunk. | ai | |
| source-diff | obfuscated-file:dist/kongponents104.cjs | AI (source-diff): Minified Vite/Rollup build chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents115.cjs | AI (source-diff): Minified build chunk. | ai | |
| source-diff | obfuscated-file:dist/kongponents117.cjs | AI (source-diff): Minified build chunk. | ai | |
| source-diff | obfuscated-file:dist/kongponents130.cjs | AI (source-diff): Minified build chunk. | ai | |
| source-diff | obfuscated-file:dist/kongponents132.cjs | AI (source-diff): Minified build chunk. | ai | |
| source-diff | obfuscated-file:dist/kongponents134.cjs | AI (source-diff): Minified build chunk. | ai | |
| source-diff | obfuscated-file:dist/kongponents248.cjs | AI (source-diff): Minified Vite/Rollup CJS chunk; bundled output pattern, not obfuscation. Stable for this package. | ai | |
| source-diff | net-exec-file:dist/kongponents376.es.js | AI (source-diff): Same lodash globalThis polyfill pattern in ESM bundle; not malicious. | ai | |
| source-diff | net-exec-file:dist/kongponents376.cjs | AI (source-diff): Function('return this')() is lodash globalThis polyfill; no actual network+exec malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/kongponents376.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents195.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents288.cjs | AI (source-diff): Standard Rollup/Vite minified CJS chunk; not true obfuscation. Stable pattern for this package's build output. | ai | |
| source-diff | obfuscated-file:dist/kongponents230.cjs | AI (source-diff): Minified Vite/Rollup chunk (floating-ui DOM code); not obfuscation. Pattern is stable for this package's build output. | ai | |
| source-diff | obfuscated-file:dist/kongponents212.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk output; not true obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/kongponents262.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; normal build output for this component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents359.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; normal build output for this component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents349.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; normal build output for this component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents260.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; expected build output for this Vue component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents264.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; expected build output for this Vue component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents277.cjs | AI (source-diff): Standard Vite/Rollup minified build output for a Vue component library; not malicious obfuscation. | ai | |
| source-diff | net-exec-file:dist/kongponents355.cjs | AI (source-diff): Function('return this')() is lodash-es global detection; no actual network+exec dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/kongponents355.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; lodash-es environment detection pattern, not malware. | ai | |
| source-diff | net-exec-file:dist/kongponents.es355.js | AI (source-diff): Same lodash-es global detection in ESM build chunk; not a dropper. | ai | |
| source-diff | obfuscated-file:dist/kongponents274.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; readable Vue component logic visible in sample. | ai | |
| source-diff | obfuscated-file:dist/kongponents261.cjs | AI (source-diff): Minified Vite/Rollup CJS bundle output; normal for this package's build process across all versions. | ai | |
| source-diff | obfuscated-file:dist/kongponents204.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; normal build output for this Vue component library. | ai | |
| source-diff | net-exec-file:dist/kongponents369.cjs | AI (source-diff): Function('return this') is a lodash globalThis polyfill pattern, not a dropper; no actual network calls. | ai | |
| source-diff | net-exec-file:dist/kongponents.es369.js | AI (source-diff): Same lodash globalThis polyfill in ES module build; legitimate bundled dependency. | ai | |
| source-diff | obfuscated-file:dist/kongponents369.cjs | AI (source-diff): Contains lodash/focus-trap minified; legitimate build artifact from Vite bundling. | ai | |
| source-diff | obfuscated-file:dist/kongponents171.cjs | AI (source-diff): Vite/Rollup minified build output for a Vue component library; sample shows SVG/component code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents357.cjs | AI (source-diff): Vite-generated minified chunk; normal build output for this Vue component library. | ai | |
| source-diff | net-exec-file:dist/kongponents357.cjs | AI (source-diff): Minified Vue/lodash bundle; network refs are fetch API usage in UI components, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/kongponents.es357.js | AI (source-diff): ESM chunk from Vite build; same pattern as CJS chunk, no malicious indicators. | ai | |
| source-diff | obfuscated-file:dist/kongponents250.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; CalendarWrapper component code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/kongponents255.cjs | AI (source-diff): Standard Vite CJS chunk containing focus-trap library with MIT license header. | ai | |
| source-diff | obfuscated-file:dist/kongponents186.cjs | AI (source-diff): Standard Vite CJS chunk; readable Vue component code, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/kongponents259.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk with bundled focus-trap; not obfuscated. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/kongponents271.cjs | AI (source-diff): Contains recognizable floating-ui positioning logic; minified CJS chunk from Vite build, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents265.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents144.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents133.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents129.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents120.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents116.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents110.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents108.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents106.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents100.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library; minified but not malicious. | ai | |
| source-diff | obfuscated-file:dist/kongponents300.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents148.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents127.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents125.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents123.cjs | AI (source-diff): Standard Vite CJS build chunk for Kong component library. | ai | |
| source-diff | obfuscated-file:dist/kongponents249.cjs | AI (source-diff): Standard Vite CJS chunk output; readable Vue component (ColumnVisibilityMenu) logic. | ai | |
| source-diff | obfuscated-file:dist/kongponents306.cjs | AI (source-diff): Standard Vite CJS chunk output; floating-ui DOM utilities, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/kongponents241.cjs | AI (source-diff): Standard Vite CJS chunk output; CalendarWrapper component code, not malicious. | ai | |
| source-diff | obfuscated-file:dist/kongponents263.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; readable Vue component code, not obfuscated. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Component library with many Vite build chunks; large file count is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/kongponents280.cjs | AI (source-diff): Standard Vite CJS chunk; contains readable tabbable 6.4.0 source, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents362.cjs | AI (source-diff): Standard Vite CJS chunk; contains readable date-fns parsing code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents332.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk containing vue-draggable-next/sortablejs; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/kongponents246.cjs | AI (source-diff): Standard Vite minified CJS chunk; readable Vue component code. | ai | |
| source-diff | obfuscated-file:dist/kongponents257.cjs | AI (source-diff): Standard Vite minified CJS chunk; focus-trap library code with MIT license header. | ai | |
| source-diff | obfuscated-file:dist/kongponents22.cjs | AI (source-diff): Standard Vite minified CJS chunk; readable Vue component code. | ai | |
| source-diff | obfuscated-file:dist/kongponents164.cjs | AI (source-diff): Standard Vite minified CJS chunk; readable Vue component code. | ai | |
| source-diff | obfuscated-file:dist/kongponents161.cjs | AI (source-diff): Standard Vite minified CJS chunk; readable Vue component code. | ai | |
| source-diff | obfuscated-file:dist/kongponents159.cjs | AI (source-diff): Standard Vite minified CJS chunk; readable Vue component code. | ai | |
| source-diff | obfuscated-file:dist/kongponents157.cjs | AI (source-diff): Standard Vite minified CJS chunk; readable Vue component code, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/kongponents258.cjs | AI (source-diff): Minified Vite/Rollup CJS build chunk; standard for this component library's build output. | ai | |
| provenance | publisher-changed | AI (provenance): Kong migrated to GitHub Actions CI publishing with SLSA attestation; this is the expected publisher going forward. | ai | |
| source-diff | obfuscated-file:dist/kongponents327.cjs | AI (source-diff): Minified Rollup/Vite bundle of declared deps (vue-draggable-next, sortablejs); not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents267.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; not obfuscated. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/kongponents252.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; not obfuscated. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/kongponents285.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; content is date-fns formatting logic, not malicious. | ai | |
| source-diff | obfuscated-file:dist/kongponents201.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; content is Vue component + SVG icon code, not malicious. | ai | |
| source-diff | obfuscated-file:dist/kongponents244.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; content is readable floating-ui DOM utilities, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/kongponents269.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk output for a Vue component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents273.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk output for a Vue component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents254.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output; focus-trap attribution visible in file header. Normal for this package. | ai | |
| source-diff | obfuscated-file:dist/kongponents251.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; readable Vue component code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents253.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; readable Vue component code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/kongponents247.cjs | AI (source-diff): Standard Vite/Rollup minified CJS chunk; readable Vue component code, not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:virtua | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:vue-draggable-next | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:@floating-ui/vue | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:focus-trap-vue | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:@popperjs/core | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:date-fns-tz | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:@kong/icons | AI (phantom-deps): Same org scope; used indirectly in component library. | ai | |
| phantom-deps | phantom-dep:sortablejs | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): Large component library; deps used indirectly or via config/build tooling, not direct imports. | ai |
Versions (showing 51 of 361)
| Version | Deps | Published |
|---|---|---|
| 9.61.6 | 14 / 60 | |
| 9.61.5 | 14 / 60 | |
| 9.61.4 | 14 / 60 | |
| 9.61.3 | 14 / 60 | |
| 9.61.2 | 14 / 60 | |
| 9.61.1 | 14 / 60 | |
| 9.61.0 | 14 / 60 | |
| 9.60.10 | 14 / 58 | |
| 9.60.9 | 14 / 58 | |
| 9.60.8 | 14 / 58 | |
| 9.60.7 | 14 / 58 | |
| 9.60.6 | 14 / 58 | |
| 9.60.5 | 14 / 58 | |
| 9.60.4 | 14 / 58 | |
| 9.60.3 | 14 / 58 | |
| 9.60.2 | 14 / 58 | |
| 9.60.1 | 14 / 57 | |
| 9.60.0 | 14 / 57 | |
| 9.59.0 | 14 / 57 | |
| 9.58.0 | 14 / 57 | |
| 9.57.0 | 14 / 57 | |
| 9.56.2 | 14 / 57 | |
| 9.56.1 | 14 / 57 | |
| 9.56.0 | 14 / 57 | |
| 9.55.3 | 14 / 57 | |
| 9.55.2 | 14 / 57 | |
| 9.55.1 | 14 / 57 | |
| 9.55.0 | 14 / 57 | |
| 9.54.3 | 14 / 57 | |
| 9.54.2 | 14 / 57 | |
| 9.54.1 | 14 / 57 | |
| 9.54.0 | 14 / 57 | |
| 9.53.3 | 14 / 57 | |
| 9.53.2 | 14 / 57 | |
| 9.53.1 | 14 / 57 | |
| 9.53.0 | 14 / 57 | |
| 9.52.13 | 14 / 57 | |
| 9.52.12 | 14 / 57 | |
| 9.52.11 | 14 / 57 | |
| 9.52.10 | 14 / 57 | |
| 9.52.9 | 14 / 57 | |
| 9.52.8 | 14 / 57 | |
| 9.52.7 | 14 / 57 | |
| 9.52.6 | 14 / 57 | |
| 9.52.5 | 14 / 57 | |
| 9.52.4 | 14 / 57 | |
| 9.52.3 | 14 / 57 | |
| 9.52.2 | 14 / 57 | |
| 9.52.1 | 14 / 57 | |
| 9.52.0 | 14 / 57 | |
| 9.51.2 | 14 / 57 |
v9.61.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.61.5
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.61.4
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.61.3
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.61.2
13 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.61.1
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.61.0
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.60.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.60.9
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.60.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.60.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.