← Home

@mercurjs/core

Core plugin for MercurJS.

8
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mercurjs

Keywords

marketplacemulti-vendormedusajsecommerceopen-source-marketplaceheadless-commerceai-readymarketplace-frameworkmedusa-pluginmedusa-v2

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:.medusa/server/src/workflows/product-attribute/workflows/update-product-attributes-on-product.js AI (source-diff): Compiled TS build output, not obfuscation; readable code in sample. ai
phantom-deps phantom-dep:@orama/orama AI (phantom-deps): Likely used in generated/build output not scanned by import heuristic. ai
semgrep semgrep:dynamic-require AI (semgrep): Internal plugin-loader/codegen utility, not attacker-controlled input. ai
typosquat typosquat.levenshtein:cors AI (typosquat): Scoped package @mercurjs/core is a MercurJS marketplace plugin, not a typosquat of cors; cors is even a devDependency. ai
semgrep semgrep:child-process-import AI (semgrep): child_process used in a codegen service for build-time code generation; expected for this type of plugin. ai

Versions (showing 8 of 8)

Version Deps Published
2.2.0 3 / 29
2.1.6 0 / 29
2.1.5 0 / 29
2.1.4 0 / 29
2.1.3 0 / 29
2.1.2 0 / 29
2.1.1 0 / 29
2.1.0 0 / 29

v2.2.0

50 findings
HIGH New obfuscated file: .medusa/server/src/workflows/product-attribute/workflows/update-product-attributes-on-product.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/order/workflows/create-order-fulfillment.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-attribute/workflows/add-product-attributes-to-product.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/utils/offers.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/modules/product-attribute/service.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/order/workflows/confirm-order-edit-request.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/order/workflows/confirm-return-receive.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/store/offers/helpers.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-edit/workflows/apply-product-change-actions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/offer/workflows/create-offers.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/order/workflows/cancel-order-fulfillment.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/offer/workflows/update-offers.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product/workflows/create-products.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/admin/product-attributes/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/offers/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/order/workflows/confirm-exchange-request.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/order/workflows/confirm-claim-request.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-edit/workflows/product-edit-update-variants.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/offer/workflows/batch-offer-inventory-items.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/claims/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/offer/utils/prepare-offer-inventory-input.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/cart/hooks/validate.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/admin/offers/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/utils/format-product-attributes.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/claims/middlewares.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/modules/offer/service.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/admin/product-categories/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-attribute/workflows/create-product-attributes.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/cart/hooks/set-pricing-context.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/product-attributes/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-edit/workflows/product-edit-update-product.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/exchanges/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/exchanges/middlewares.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-attribute/workflows/remove-product-attributes-from-product.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/media/workflows/set-collection-images.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/media/workflows/set-category-images.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/orders/resolve-offer-items.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/admin/products/middlewares.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-attribute/workflows/create-product-attribute-values.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-attribute/workflows/delete-product-attribute-values.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/admin/products/[id]/route.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/offer/steps/add-offer-prices.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/subscribers/link-order-line-items-to-offers.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/product-attribute/workflows/update-product-attribute-values.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/admin/products/[id]/variants/[variant_id]/route.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/vendor/order-edits/validators.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/utils/disable-medusa-middlewares.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/workflows/offer/steps/ensure-variant-price-sets.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: .medusa/server/src/api/admin/exchanges/[id]/outbound/items/route.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.