@medplum/app
Medplum App
9
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
codyebbersonreshmakhrahul1
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/assets/index-dIkoxLMl.js | AI (source-diff): Network calls and dynamic patterns are standard React SPA bundle behavior, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/assets/index-dIkoxLMl.js | AI (source-diff): Vite-minified frontend bundle; expected artifact for @medplum/app across all versions. | ai | |
| source-diff | obfuscated-file:dist/assets/index-C4C5QSCX.js | AI (source-diff): Vite-minified SPA bundle; expected output for this package on every release. | ai | |
| source-diff | net-exec-file:dist/assets/index-C4C5QSCX.js | AI (source-diff): fetch() is the Vite modulepreload polyfill; no dynamic code execution beyond normal SPA routing. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BD57ELip.js | AI (source-diff): Standard Vite minified bundle output; expected for this frontend app package across all versions. | ai | |
| source-diff | net-exec-file:dist/assets/index-BD57ELip.js | AI (source-diff): fetch() in modulepreload polyfill is normal browser app behavior, not dropper malware. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): SLSA provenance attestation confirms legitimate CI/CD publish; dormancy flag is a false positive here. | ai | |
| source-diff | obfuscated-file:dist/assets/index-0vogre2K.js | AI (source-diff): Standard Vite minified SPA bundle with accompanying source map; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-0vogre2K.js | AI (source-diff): fetch() in modulepreload polyfill + dynamic module loading is normal Vite SPA bundle behavior. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): Scoped @medplum package; Levenshtein match to 'hapi' is coincidental, not a typosquat. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped @medplum package; Levenshtein match to 'ajv' is coincidental, not a typosquat. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @medplum package; Levenshtein match to 'yup' is coincidental, not a typosquat. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @medplum package; Levenshtein match to 'pg' is coincidental, not a typosquat. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 5.1.13 | 0 / 23 | |
| 5.1.12 | 0 / 23 | |
| 5.1.11 | 0 / 23 | |
| 5.1.10 | 0 / 23 | |
| 5.1.9 | 0 / 23 | |
| 5.1.8 | 0 / 23 | |
| 5.1.7 | 0 / 23 | |
| 5.0.2 | 0 / 22 | |
| 5.0.1 | 0 / 22 |
v5.0.2
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.0.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.