@mulmoclaude/markdown-plugin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/marp-bgsuXK7p.cjs | AI (source-diff): Vite chunk with hash suffix; sample shows legitimate Marp/markdown plugin logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/marp-Dka_qcBN.cjs | AI (source-diff): Vite-bundled CJS chunk with readable identifiers; not true obfuscation. Consistent with package's marp/markdown build output. | ai | |
| source-diff | obfuscated-file:dist/defaultLocale-u9yUoUmE.cjs | AI (source-diff): Minified locale bundle from mermaid dep. | ai | |
| source-diff | obfuscated-file:dist/arc-CXuhvIlr.cjs | AI (source-diff): Minified d3/mermaid bundle output; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/architectureDiagram-ZJ3FMSHR-CWhELDsM.cjs | AI (source-diff): Minified mermaid/cytoscape bundle; recognizable layout algorithm code. | ai | |
| source-diff | obfuscated-file:dist/blockDiagram-677ZJIJ3-BqQ4RrTF.cjs | AI (source-diff): Minified mermaid bundle output. | ai | |
| source-diff | obfuscated-file:dist/c4Diagram-LMCZKHZV-Vqhw9Ulw.cjs | AI (source-diff): Minified mermaid bundle output. | ai | |
| source-diff | net-exec-file:dist/chunk-KEIR6QF5-CNjhxe7N.cjs | AI (source-diff): LSP protocol types bundle; no actual network calls or dynamic exec in the sample. | ai | |
| source-diff | obfuscated-file:dist/cose-bilkent-JH36ORCC-BRiBazsj.cjs | AI (source-diff): Minified cytoscape layout bundle. | ai | |
| source-diff | obfuscated-file:dist/cynefinDiagram-TSTJHNR4-ROF60FZX.cjs | AI (source-diff): Minified mermaid diagram bundle. | ai | |
| source-diff | obfuscated-file:dist/dagre-BBlCxSvR.cjs | AI (source-diff): Minified dagre graph layout bundle. | ai | |
| source-diff | obfuscated-file:dist/diagram-FQU43EPY-BtcyjoA2.cjs | AI (source-diff): Minified mermaid diagram bundle. | ai | |
| source-diff | obfuscated-file:dist/diagram-G47NLZAW-CpV8D5Yq.cjs | AI (source-diff): Minified mermaid diagram bundle. | ai | |
| source-diff | obfuscated-file:dist/diagram-NH7WQ7WH-RJG4gay2.cjs | AI (source-diff): Minified mermaid diagram bundle. | ai | |
| source-diff | obfuscated-file:dist/diagram-OA4YK3LP-BnLoZPrB.cjs | AI (source-diff): Minified mermaid diagram bundle. | ai | |
| source-diff | obfuscated-file:dist/diagram-WEI45ONY-IDm-YqNz.cjs | AI (source-diff): Minified mermaid diagram bundle. | ai | |
| source-diff | obfuscated-file:dist/dist-Byq47Rfs.cjs | AI (source-diff): Minified mermaid core bundle. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 205 new files explained by bundling mermaid+cytoscape+katex+dagre transitive deps. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 61x size increase fully explained by bundling mermaid and its large transitive deps. | ai | |
| source-diff | obfuscated-file:dist/cytoscape.esm-BJfLlyzE.cjs | AI (source-diff): Minified cytoscape.js bundle; recognizable iterator/class patterns. | ai | |
| source-diff | obfuscated-file:dist/dagre-VKFMJZFB-Bzn4-rJL.cjs | AI (source-diff): Minified dagre bundle. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.1.10 | 4 / 16 | |
| 0.1.7 | 3 / 17 | |
| 0.1.6 | 3 / 17 | |
| 0.1.4 | 3 / 17 | |
| 0.1.3 | 3 / 17 | |
| 0.1.2 | 3 / 17 | |
| 0.1.0 | 3 / 17 |
v0.1.10
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.7
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.