@murumets-ee/content
Content management — localization, publishing workflows, versioning, drafts, and translation status.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/plugin-CG2tNeoG.mjs | AI (source-diff): Bundled ESM output from tsdown; readable identifiers, no true obfuscation patterns. Stable for this package. | ai | |
| source-diff | obfuscated-file:dist/plugin-IW9SM9iO.mjs | AI (source-diff): Bundled ESM build output (tsdown); long lines are minification, not obfuscation. No malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/plugin-DbK6FxTd.mjs | AI (source-diff): Minified ESM bundle from tsdown build; content is domain-appropriate schema/plugin code, not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:@murumets-ee/blocks | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for monorepo packages. | ai | |
| phantom-deps | phantom-dep:drizzle-orm | AI (phantom-deps): drizzle-orm is used in bundled dist output; phantom-dep is a false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/plugin-ppoIGq-c.mjs | AI (source-diff): Minified bundler output (tsdown); code is readable domain logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/plugin-DkmXJ7Qw.mjs | AI (source-diff): Standard tsdown/Rollup minified bundle output; content is readable domain logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/plugin-yijaaFS7.mjs | AI (source-diff): Minified tsdown build output with readable schema code; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/block-diff-BBH6FoFT.mjs | AI (source-diff): Minified ESM bundle from tsdown build tool; code is readable and benign. | ai | |
| phantom-deps | phantom-dep:@murumets-ee/db | AI (phantom-deps): Imported dynamically in dist/client.mjs bundle; same-org scoped dep used as expected. | ai | |
| source-diff | obfuscated-file:dist/client.mjs | AI (source-diff): Minified ESM bundle from tsdown build tool; code is readable CRUD/versioning logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/block-diff-H1AttKiz.mjs | AI (source-diff): Minified ESM bundle from tsdown build tool; code is readable business logic, no malicious patterns. | ai | |
| phantom-deps | phantom-dep:server-only | AI (phantom-deps): server-only is imported via type system; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@murumets-ee/logging | AI (phantom-deps): Same-org internal dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is imported via type system and config; stable false positive for this package. | ai |
Versions (showing 75 of 75)
| Version | Deps | Published |
|---|---|---|
| 0.36.0 | 9 / 4 | |
| 0.35.1 | 9 / 4 | |
| 0.35.0 | 9 / 4 | |
| 0.34.1 | 8 / 4 | |
| 0.34.0 | 8 / 4 | |
| 0.33.0 | 8 / 4 | |
| 0.32.3 | 8 / 4 | |
| 0.32.2 | 8 / 4 | |
| 0.32.1 | 8 / 4 | |
| 0.32.0 | 8 / 4 | |
| 0.31.0 | 8 / 4 | |
| 0.30.0 | 8 / 4 | |
| 0.29.2 | 8 / 4 | |
| 0.29.1 | 8 / 4 | |
| 0.29.0 | 8 / 4 | |
| 0.28.0 | 8 / 4 | |
| 0.27.0 | 8 / 4 | |
| 0.26.3 | 8 / 4 | |
| 0.26.2 | 8 / 4 | |
| 0.26.1 | 8 / 4 | |
| 0.26.0 | 8 / 4 | |
| 0.25.0 | 7 / 4 | |
| 0.24.1 | 7 / 4 | |
| 0.24.0 | 7 / 4 | |
| 0.23.2 | 7 / 4 | |
| 0.23.1 | 7 / 4 | |
| 0.23.0 | 7 / 4 | |
| 0.22.1 | 7 / 4 | |
| 0.22.0 | 7 / 4 | |
| 0.21.1 | 7 / 4 | |
| 0.21.0 | 7 / 4 | |
| 0.20.0 | 7 / 4 | |
| 0.19.0 | 7 / 4 | |
| 0.18.0 | 7 / 4 | |
| 0.17.1 | 7 / 4 | |
| 0.17.0 | 7 / 4 | |
| 0.16.5 | 7 / 4 | |
| 0.16.4 | 7 / 4 | |
| 0.16.3 | 7 / 4 | |
| 0.16.2 | 7 / 4 | |
| 0.16.1 | 7 / 4 | |
| 0.16.0 | 7 / 4 | |
| 0.15.4 | 7 / 4 | |
| 0.15.3 | 7 / 4 | |
| 0.15.2 | 7 / 4 | |
| 0.15.1 | 7 / 4 | |
| 0.15.0 | 7 / 4 | |
| 0.14.0 | 7 / 4 | |
| 0.13.3 | 7 / 4 | |
| 0.13.2 | 7 / 4 | |
| 0.13.1 | 7 / 4 | |
| 0.13.0 | 7 / 4 | |
| 0.12.0 | 7 / 4 | |
| 0.11.0 | 7 / 4 | |
| 0.10.0 | 7 / 4 | |
| 0.9.0 | 7 / 4 | |
| 0.8.0 | 7 / 4 | |
| 0.7.0 | 7 / 4 | |
| 0.6.1 | 7 / 4 | |
| 0.6.0 | 7 / 4 | |
| 0.5.1 | 7 / 4 | |
| 0.5.0 | 7 / 4 | |
| 0.4.8 | 7 / 4 | |
| 0.4.6 | 7 / 4 | |
| 0.4.5 | 7 / 4 | |
| 0.4.0 | 7 / 4 | |
| 0.3.0 | 7 / 4 | |
| 0.2.1 | 7 / 4 | |
| 0.2.0 | 7 / 4 | |
| 0.1.5 | 7 / 4 | |
| 0.1.4 | 7 / 4 | |
| 0.1.3 | 7 / 4 | |
| 0.1.2 | 7 / 4 | |
| 0.1.1 | 7 / 4 | |
| 0.1.0 | 7 / 4 |
v0.36.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.