← Home

@microsoft/sp-lodash-subset

10
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

microsoft1esmicrosoft-oss-releasesodspnpm

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
bogus-package bogus-package AI (bogus-package): Legit Microsoft internal utility package; sparse README is normal for this package. ai
source-diff obfuscated-file:dist/sp-lodash-subset_661c68f94c8635739235.js AI (source-diff): Minified lodash bundle, standard build output for this package across versions. ai
source-diff obfuscated-file:dist/sp-lodash-subset_c0be9fd6f4716f5c5cd4.js AI (source-diff): Minified lodash bundle output, standard build artifact for this package, not obfuscation. ai
source-diff obfuscated-file:dist/sp-lodash-subset_180f0143e4e97c1f64fd.js AI (source-diff): Minified AMD/webpack bundle of lodash subset, not true obfuscation; consistent build pattern. ai
source-diff obfuscated-file:lib-commonjs/index.js AI (source-diff): AMD-bundled minified lodash subset, standard build output for this package. ai
source-diff obfuscated-file:lib-esm/index.js AI (source-diff): AMD-bundled minified lodash subset, standard build output for this package. ai
publish-pattern new-deps-added AI (publish-pattern): @swc/helpers is a well-known compiler runtime dep, consistent with SPFx build tooling updates. ai
source-diff obfuscated-file:dist/sp-lodash-subset_6fa3573e3e62ffc536f8.js AI (source-diff): Bundled dist file, standard minified build output. ai
source-diff obfuscated-file:dist/sp-lodash-subset_25a86407e39cabb0157a.js AI (source-diff): Standard minified lodash bundle output from Microsoft SPFx build pipeline; not obfuscation. ai
publish-pattern dormant-publish AI (publish-pattern): Microsoft SPFx versioned release; publisher has strong track record with 3773 approved packages. ai
source-diff obfuscated-file:dist/sp-lodash-subset_90044476422a825ce2cb.js AI (source-diff): Standard SPFx AMD-format minified lodash bundle; consistent with this package's build pipeline across all versions. ai
phantom-deps phantom-dep:@swc/helpers AI (phantom-deps): Implicit runtime dependency for SWC transpilation; stable pattern for this package. ai
phantom-deps phantom-dep:@types/lodash AI (phantom-deps): Type definitions loaded by convention; stable for TypeScript utility library. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): Implicit runtime dependency for TypeScript transpilation; stable pattern for this package. ai

Versions (showing 10 of 10)

Version Deps Published
1.23.2 3 / 10
1.23.1 3 / 10
1.23.0 3 / 10
1.22.2 3 / 10
1.22.1 3 / 10
1.22.0 3 / 10
1.21.1 3 / 11
1.21.0 3 / 11
1.20.0 2 / 11
1.19.0 2 / 11

v1.23.2

2 findings
HIGH New obfuscated file: dist/sp-lodash-subset_661c68f94c8635739235.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.21.0

5 findings
HIGH New obfuscated file: lib-commonjs/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib-esm/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sp-lodash-subset_6fa3573e3e62ffc536f8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: odspnpm → microsoft1es (on 2025-04-23, known maintainer) provenance

This version was published by a different npm account (microsoft1es) than the most recent previously approved version (odspnpm) on 2025-04-23, but microsoft1es is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.20.0

3 findings
HIGH New obfuscated file: dist/sp-lodash-subset_180f0143e4e97c1f64fd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: odspnpm → microsoft1es (on 2024-09-26, known maintainer) provenance

This version was published by a different npm account (microsoft1es) than the most recent previously approved version (odspnpm) on 2024-09-26, but microsoft1es is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.