@nestia/editor
Swagger-UI + Cloud TypeScript Editor
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/assets/index-D0p46kEY.js | AI (source-diff): Standard vite modulepreload fetch polyfill, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-D0p46kEY.js | AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CazOgca4.js | AI (source-diff): Vite-bundled frontend asset, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-CazOgca4.js | AI (source-diff): fetch+eval pattern is standard vite modulepreload polyfill in bundled output. | ai | |
| source-diff | net-exec-file:dist/assets/index-BfCvApiB.js | AI (source-diff): Bundler modulepreload fetch polyfill, not a network dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BfCvApiB.js | AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-DORxj52S.js | AI (source-diff): Standard modulepreload fetch polyfill in bundled frontend code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DORxj52S.js | AI (source-diff): Vite/Rollup bundled SPA output, not true obfuscation; matches stated build pipeline. | ai | |
| source-diff | net-exec-file:dist/assets/index-B4dcJE1c.js | AI (source-diff): fetch() calls are Vite's modulepreload polyfill, not a dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/assets/index-B4dcJE1c.js | AI (source-diff): Vite-bundled frontend output, not true obfuscation; standard modulepreload polyfill code. | ai | |
| source-diff | net-exec-file:dist/assets/index-IJ9szrWO.js | AI (source-diff): fetch() calls are standard Vite modulepreload polyfill, not exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-IJ9szrWO.js | AI (source-diff): Vite/rollup bundle output, minified not obfuscated; consistent with build scripts. | ai | |
| source-diff | net-exec-file:dist/assets/index-mRHc7mME.js | AI (source-diff): fetch() calls are Vite modulepreload polyfill boilerplate, not a dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/assets/index-mRHc7mME.js | AI (source-diff): Vite/Rollup bundled frontend asset, not obfuscation; standard build output for this editor package. | ai | |
| source-diff | net-exec-file:dist/assets/index-BkCuFHhN.js | AI (source-diff): Standard Vite modulepreload fetch polyfill, not dropper/loader code. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BkCuFHhN.js | AI (source-diff): Vite/Rollup bundled browser asset, not true obfuscation; matches editor UI bundle output. | ai | |
| source-diff | net-exec-file:dist/assets/index-6I93ebLy.js | AI (source-diff): fetch/eval boilerplate from Vite module-preload polyfill, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-6I93ebLy.js | AI (source-diff): Vite bundle output, not true obfuscation; matches package's static editor build. | ai | |
| phantom-deps | phantom-dep:@trivago/prettier-plugin-sort-imports | AI (phantom-deps): Used in prettier config, not direct import; false positive. | ai | |
| provenance | missing-githead | AI (provenance): Expected artifact of CI/CD trusted-publisher flow alongside valid SLSA provenance. | ai | |
| source-diff | net-exec-file:dist/assets/index-DUWBgT-P.js | AI (source-diff): Standard Vite modulepreload fetch polyfill in bundled output, no exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DUWBgT-P.js | AI (source-diff): Vite/rollup bundled frontend asset for this editor package, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-hH7j9X1k.js | AI (source-diff): Vite-bundled frontend asset, consistent with declared build:static script. | ai | |
| source-diff | obfuscated-file:dist/assets/index-ZOrwlfeV.js | AI (source-diff): Vite-bundled dist asset, not obfuscation; consistent with build:static script. | ai | |
| source-diff | obfuscated-file:dist/assets/index-C7wAZ2B2.js | AI (source-diff): Vite-bundled frontend asset, not true obfuscation; consistent with package's build tooling. | ai | |
| source-diff | net-exec-file:dist/assets/index-BCljFOyw.js | AI (source-diff): Standard Vite modulepreload polyfill fetch, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BCljFOyw.js | AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/index-BJmWRAsv.js | AI (source-diff): fetch() calls are standard vite modulepreload polyfill, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BJmWRAsv.js | AI (source-diff): Vite/Rollup bundled output for the editor frontend, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-By6TnR5x.js | AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation — long minified lines expected. | ai | |
| source-diff | net-exec-file:dist/assets/index-By6TnR5x.js | AI (source-diff): fetch() is vite's modulepreload polyfill in bundled SPA output, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/assets/index-6nt9fjbB.js | AI (source-diff): Vite/Rollup bundled dist asset, not obfuscation; consistent with build:static script. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Bundle size fluctuation from Vite build output, no stub/redirect behavior evident. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): fflate is a well-known compression lib, benign build-time swap for @stackblitz/sdk. | ai | |
| source-diff | obfuscated-file:dist/assets/index-D7-O5u45.js | AI (source-diff): Vite/rolldown bundled static asset, not obfuscation; standard for this editor package's dist build. | ai | |
| dependencies | unvetted-dep:@nestia/migrate | AI (dependencies): Sibling package in the same nestia monorepo; stable false positive for this package. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 12.0.0 | 8 / 20 | |
| 11.3.4 | 8 / 23 | |
| 11.3.3 | 8 / 23 | |
| 11.3.2 | 8 / 23 | |
| 11.3.1 | 8 / 23 | |
| 11.3.0 | 8 / 23 | |
| 11.2.1 | 8 / 23 | |
| 11.2.0 | 8 / 23 | |
| 11.1.0 | 8 / 23 | |
| 11.0.2 | 8 / 23 | |
| 11.0.1 | 8 / 23 | |
| 11.0.0 | 8 / 23 | |
| 10.0.2 | 10 / 23 | |
| 10.0.1 | 10 / 23 | |
| 10.0.0 | 10 / 23 | |
| 9.1.1 | 10 / 23 | |
| 9.1.0 | 10 / 23 | |
| 9.0.3 | 10 / 23 | |
| 9.0.2 | 10 / 23 | |
| 9.0.1 | 10 / 23 | |
| 9.0.0 | 10 / 23 |
v12.0.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v11.0.1
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v11.0.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v10.0.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-01-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v10.0.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-01-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v10.0.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2025-12-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v9.1.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.1.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v9.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.