← Home

@layers-app/shared

48
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

azlatov.bayman_vovasinupsdenindka

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/index-BawytWAK.js AI (source-diff): Bundler artifact; sample shows standard React/Mantine UI code, no dropper behavior. ai
source-diff obfuscated-file:dist/index-BawytWAK.js AI (source-diff): Bundled Vite output with readable imports, not true obfuscation. ai
source-diff obfuscated-file:dist/assets/fileTypes/archives.svg.js AI (source-diff): Same bundled SVG component pattern; benign. ai
source-diff obfuscated-file:dist/index-W83Evo8i.js AI (source-diff): Vite/Rollup bundle of Mantine/React component library, not obfuscation. ai
source-diff obfuscated-file:dist/icons.min-Chyr-bjL.js AI (source-diff): Minified icon dataset, bundled build output. ai
source-diff obfuscated-file:dist/emoji-categorized-DAOdcF53.js AI (source-diff): Bundled emoji dataset JSON, not obfuscation. ai
source-diff net-exec-file:dist/index-W83Evo8i.js AI (source-diff): False positive: bundled imports, no actual dropper/loader behavior. ai
source-diff obfuscated-file:dist/assets/svg/alertMan.svg.js AI (source-diff): Long-line bundled SVG/JSX component, not obfuscation; benign build output. ai
source-diff large-new-source-files AI (source-diff): Large icon/asset library ships many small generated SVG components; not injected code. ai
source-diff obfuscated-file:dist/assets/svg/noData/404.svg.js AI (source-diff): Long-line bundled SVG/JSX component, not obfuscation; benign build output. ai
source-diff encoded-string-file:dist/index.umd.cjs AI (source-diff): Minified UMD bundle output, no malicious payload evidence. ai
source-diff obfuscated-file:dist/emoji-categorized-CRsMUQyD.js AI (source-diff): Minified JSON data bundle (emoji list), not obfuscation. ai
source-diff obfuscated-file:dist/icons.min-wo13YUY4.js AI (source-diff): Minified icon metadata JSON, build output. ai
source-diff obfuscated-file:dist/index-BMtIEojG.js AI (source-diff): Vite/esbuild bundle of React/Mantine component library. ai
source-diff net-exec-file:dist/index-BMtIEojG.js AI (source-diff): Bundled UI library code, network calls are app API calls not exfil. ai
phantom-deps phantom-dep:@gfazioli/mantine-onboarding-tour AI (phantom-deps): Stable false positive; config-level reference consistent with this shared UI library pattern. ai
phantom-deps phantom-dep:@gfazioli/mantine-video AI (phantom-deps): Same pattern as mantine-audio; config-level reference is expected for this package. ai
phantom-deps phantom-dep:@gfazioli/mantine-audio AI (phantom-deps): UI component library; deps referenced in config/re-exports rather than direct imports is expected pattern. ai
phantom-deps phantom-dep:@emoji-mart/data AI (phantom-deps): Declared as runtime dependency; used transitively by emoji-mart. ai
npm-metadata no-description AI (npm-metadata): Shared library in established monorepo; description omission is benign. ai
bogus-package bogus-package AI (bogus-package): Internal shared library; missing repo/description/keywords is normal for monorepo packages. ai

Versions (showing 48 of 48)

Version Deps Published
0.4.9 3 / 0
0.4.8 3 / 0
0.4.7 1 / 0
0.4.6 1 / 0
0.4.5 1 / 0
0.4.4 0 / 0
0.4.3 0 / 0
0.4.2 0 / 0
0.4.1 0 / 0
0.3.9 0 / 0
0.3.8 0 / 0
0.3.7 0 / 0
0.3.2 0 / 0
0.3.1 0 / 0
0.3.0 0 / 0
0.2.7 0 / 0
0.2.6 0 / 0
0.2.5 0 / 0
0.2.4 0 / 0
0.2.3 0 / 0
0.2.2 0 / 0
0.2.1 0 / 0
0.1.5 1 / 1
0.1.4 1 / 1
0.1.3 1 / 0
0.0.45 1 / 6
0.0.43 1 / 0
0.0.42 1 / 0
0.0.36 1 / 0
0.0.34 1 / 0
0.0.33 1 / 0
0.0.30 1 / 0
0.0.19 1 / 0
0.0.18 1 / 0
0.0.17 1 / 0
0.0.16 1 / 0
0.0.15 1 / 0
0.0.14 1 / 0
0.0.13 1 / 0
0.0.12 1 / 0
0.0.11 2 / 0
0.0.10 2 / 0
0.0.9 2 / 0
0.0.8 2 / 0
0.0.7 2 / 0
0.0.5 2 / 0
0.0.3 2 / 0
0.0.2 2 / 0

v0.4.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: azlatov. → denindka (on 2026-05-19, known maintainer) provenance

This version was published by a different npm account (denindka) than the most recent previously approved version (azlatov.) on 2026-05-19, but denindka is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.0

3 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

3 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

3 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

3 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.4

4 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/fileTypes/archives.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

4 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/fileTypes/archives.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

4 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/fileTypes/archives.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

4 findings
HIGH New obfuscated file: dist/assets/svg/noData/404.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/svg/alertMan.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/assets/fileTypes/archives.svg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

3 findings
HIGH New obfuscated file: dist/index-BawytWAK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BawytWAK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

3 findings
HIGH New obfuscated file: dist/index-BawytWAK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BawytWAK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

3 findings
HIGH New obfuscated file: dist/index-BawytWAK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BawytWAK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.45

5 findings
HIGH New obfuscated file: dist/emoji-categorized-DAOdcF53.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icons.min-Chyr-bjL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-W83Evo8i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-W83Evo8i.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.42

6 findings
HIGH New obfuscated file: dist/emoji-categorized-CRsMUQyD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icons.min-wo13YUY4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BMtIEojG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BMtIEojG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/index.umd.cjs source-diff

Modified file contains 7 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.