← Home

@lexical/react

36
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

fantactukazurfyxacywatsonipavlov001trueadmetrepum

Keywords

reactlexicaleditorrich-text

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Monorepo build output growth; expected for this package. ai
source-diff obfuscated-file:LexicalCheckListPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalCharacterLimitPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalHashtagPlugin.dev.mjs AI (source-diff): Dev build output; benign for this package. ai
source-diff obfuscated-file:LexicalCollaborationPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalAutoLinkPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalNodeMenuPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalContextMenuPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalTypeaheadMenuPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalTreeView.prod.mjs AI (source-diff): Minified prod build output with Meta header/readable imports; not obfuscation. ai
provenance publisher-changed-stale AI (provenance): 2022 publisher change unremoved 1565d; inconsistent with takeover. ai
source-diff obfuscated-file:LexicalHashtagPlugin.prod.js AI (source-diff): Minified Rollup build output with Meta license header; not obfuscation. ai
source-diff obfuscated-file:LexicalHashtagPlugin.dev.js AI (source-diff): Long lines are Unicode regex tables in build output, not obfuscation. ai
maintainer-change maintainer-added AI (maintainer-change): Legit org handoff to acywatson, stable on npm for years. ai
dependencies unvetted-dep:@lexical/helpers AI (dependencies): Same-org sibling package in the Lexical monorepo, not an unvetted third party. ai
phantom-deps phantom-dep:@lexical/helpers AI (phantom-deps): Same-org monorepo dependency; heuristic false positive. ai
phantom-deps phantom-dep:react-error-boundary AI (phantom-deps): Config-referenced error boundary; stable for this package. ai
phantom-deps phantom-dep:@lexical/code AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@lexical/clipboard AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@lexical/selection AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. ai
dependencies unvetted-dep:@lexical/a11y AI (dependencies): Same-org sibling package, same version, part of lexical monorepo lockstep release. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party @lexical/* sibling, not an external/unrelated package. ai
provenance missing-githead AI (provenance): gitHead dropped as part of CI/CD migration; SLSA attestation provides stronger provenance. ai
provenance publisher-changed AI (provenance): Transition from manual publish (zurfyx) to GitHub Actions CI/CD is expected for facebook/lexical. ai
source-diff obfuscated-file:dist/LexicalDraggableBlockPlugin.prod.js AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. ai
source-diff obfuscated-file:dist/LexicalCollaborationPlugin.prod.js AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. ai
source-diff obfuscated-file:dist/LexicalCharacterLimitPlugin.prod.js AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. ai
source-diff large-new-source-files AI (source-diff): Monorepo build restructuring; all files are expected dist outputs. ai
dependencies unvetted-dep:@lexical/plain-text AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/rich-text AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/extension AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/overflow AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/markdown AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/history AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/hashtag AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/dragon AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/utils AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/table AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/text AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/mark AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/list AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/yjs AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. Not a third-party dependency. ai
dependencies unvetted-dep:@lexical/link AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
provenance no-provenance AI (provenance): Lexical does not publish with Sigstore provenance; this is consistent across all versions and is not a security disqualifier for this established package. ai
phantom-deps phantom-dep:@lexical/mark AI (phantom-deps): Same-org sibling dependency; phantom import is a packaging detail, not a security concern for this monorepo package. ai
dependencies unvetted-dep:@lexical/devtools-core AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai

Versions (showing 36 of 136)

Version Deps Published
0.3.3 17 / 1
0.3.2 17 / 0
0.3.1 17 / 0
0.3.0 17 / 0
0.2.9 17 / 0
0.2.8 17 / 0
0.2.7 17 / 0
0.2.6 17 / 0
0.2.5 16 / 0
0.2.4 16 / 0
0.2.3 16 / 0
0.2.2 16 / 0
0.2.1 16 / 0
0.2.0 16 / 0
0.1.21 16 / 0
0.1.20 15 / 0
0.1.19 15 / 0
0.1.18 15 / 0
0.1.17 15 / 0
0.1.16 8 / 0
0.1.15 7 / 0
0.1.14 5 / 0
0.1.13 5 / 0
0.1.12 0 / 0
0.1.11 0 / 0
0.1.10 0 / 0
0.1.9 0 / 0
0.1.8 0 / 0
0.1.7 0 / 0
0.1.6 0 / 0
0.1.5 0 / 0
0.1.4 0 / 0
0.1.3 3 / 0
0.1.2 3 / 0
0.1.1 3 / 0
0.1.0 3 / 0

v0.3.3

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → fantactuka (on 2022-06-10, unremoved on npm for 1502d) provenance

This version was published by a different npm account (fantactuka) than the most recent previously approved version (trueadm) on 2022-06-10. It has since remained available on npm for 1502 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.2

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-06-06, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-06-06, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.3.1

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → fantactuka (on 2022-06-03, unremoved on npm for 1508d) provenance

This version was published by a different npm account (fantactuka) than the most recent previously approved version (trueadm) on 2022-06-03. It has since remained available on npm for 1508 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

3 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → thegreatercurve (on 2022-05-11, unremoved on npm for 1531d) provenance

This version was published by a different npm account (thegreatercurve) than the most recent previously approved version (trueadm) on 2022-05-11. It has since remained available on npm for 1531 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-05-11, unremoved on npm for 1531d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-05-11. It has since remained available on npm for 1531 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → fantactuka (on 2022-05-10, unremoved on npm for 1533d) provenance

This version was published by a different npm account (fantactuka) than the most recent previously approved version (trueadm) on 2022-05-10. It has since remained available on npm for 1533 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → fantactuka (on 2022-05-09, unremoved on npm for 1533d) provenance

This version was published by a different npm account (fantactuka) than the most recent previously approved version (trueadm) on 2022-05-09. It has since remained available on npm for 1533 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-04-28, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-04-28, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.2.4

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → fantactuka (on 2022-04-21, unremoved on npm for 1551d) provenance

This version was published by a different npm account (fantactuka) than the most recent previously approved version (trueadm) on 2022-04-21. It has since remained available on npm for 1551 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-04-19, unremoved on npm for 1553d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-04-19. It has since remained available on npm for 1553 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-04-18, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-04-18, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.2.1

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-04-14, unremoved on npm for 1558d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-04-14. It has since remained available on npm for 1558 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-04-13, unremoved on npm for 1559d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-04-13. It has since remained available on npm for 1559 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.21

3 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.20

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-04-07, unremoved on npm for 1565d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-04-07. It has since remained available on npm for 1565 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.19

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-04-07, unremoved on npm for 1565d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-04-07. It has since remained available on npm for 1565 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.18

3 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.17

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-04-06, unremoved on npm for 1566d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-04-06. It has since remained available on npm for 1566 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.16

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-03-17, unremoved on npm for 1586d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-03-17. It has since remained available on npm for 1586 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.15

5 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2022-03-16, unremoved on npm for 1587d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2022-03-16. It has since remained available on npm for 1587 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: acywatson.

v0.1.14

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-03-04, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-03-04, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.13

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-03-02, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-03-02, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.12

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-02-28, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-02-28, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.11

3 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.10

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-02-22, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-02-22, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.9

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-02-18, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-02-18, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.8

4 findings
HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: trueadm → zurfyx (on 2022-02-11, known maintainer) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-02-11, but zurfyx is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.7

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zurfyx → trueadm (on 2022-02-10, known maintainer) provenance

This version was published by a different npm account (trueadm) than the most recent previously approved version (zurfyx) on 2022-02-10, but trueadm is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.6

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zurfyx → trueadm (on 2022-02-08, known maintainer) provenance

This version was published by a different npm account (trueadm) than the most recent previously approved version (zurfyx) on 2022-02-08, but trueadm is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.1.5

2 findings
MEDIUM Publisher changed: trueadm → zurfyx (on 2022-02-04, unremoved on npm for 1627d) provenance

This version was published by a different npm account (zurfyx) than the most recent previously approved version (trueadm) on 2022-02-04. It has since remained available on npm for 1627 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.