← Home

@nestia/editor

Swagger-UI + Cloud TypeScript Editor

21
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

samchon

Keywords

openapiswaggergeneratorcloudtypescripteditorsdknestjsnestia

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/assets/index-D0p46kEY.js AI (source-diff): Standard vite modulepreload fetch polyfill, not a dropper. ai
source-diff obfuscated-file:dist/assets/index-D0p46kEY.js AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation. ai
source-diff obfuscated-file:dist/assets/index-CazOgca4.js AI (source-diff): Vite-bundled frontend asset, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-CazOgca4.js AI (source-diff): fetch+eval pattern is standard vite modulepreload polyfill in bundled output. ai
source-diff net-exec-file:dist/assets/index-BfCvApiB.js AI (source-diff): Bundler modulepreload fetch polyfill, not a network dropper. ai
source-diff obfuscated-file:dist/assets/index-BfCvApiB.js AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-DORxj52S.js AI (source-diff): Standard modulepreload fetch polyfill in bundled frontend code, not a dropper. ai
source-diff obfuscated-file:dist/assets/index-DORxj52S.js AI (source-diff): Vite/Rollup bundled SPA output, not true obfuscation; matches stated build pipeline. ai
source-diff net-exec-file:dist/assets/index-B4dcJE1c.js AI (source-diff): fetch() calls are Vite's modulepreload polyfill, not a dropper pattern. ai
source-diff obfuscated-file:dist/assets/index-B4dcJE1c.js AI (source-diff): Vite-bundled frontend output, not true obfuscation; standard modulepreload polyfill code. ai
source-diff net-exec-file:dist/assets/index-IJ9szrWO.js AI (source-diff): fetch() calls are standard Vite modulepreload polyfill, not exfil/dropper behavior. ai
source-diff obfuscated-file:dist/assets/index-IJ9szrWO.js AI (source-diff): Vite/rollup bundle output, minified not obfuscated; consistent with build scripts. ai
source-diff net-exec-file:dist/assets/index-mRHc7mME.js AI (source-diff): fetch() calls are Vite modulepreload polyfill boilerplate, not a dropper pattern. ai
source-diff obfuscated-file:dist/assets/index-mRHc7mME.js AI (source-diff): Vite/Rollup bundled frontend asset, not obfuscation; standard build output for this editor package. ai
source-diff net-exec-file:dist/assets/index-BkCuFHhN.js AI (source-diff): Standard Vite modulepreload fetch polyfill, not dropper/loader code. ai
source-diff obfuscated-file:dist/assets/index-BkCuFHhN.js AI (source-diff): Vite/Rollup bundled browser asset, not true obfuscation; matches editor UI bundle output. ai
source-diff net-exec-file:dist/assets/index-6I93ebLy.js AI (source-diff): fetch/eval boilerplate from Vite module-preload polyfill, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/index-6I93ebLy.js AI (source-diff): Vite bundle output, not true obfuscation; matches package's static editor build. ai
phantom-deps phantom-dep:@trivago/prettier-plugin-sort-imports AI (phantom-deps): Used in prettier config, not direct import; false positive. ai
provenance missing-githead AI (provenance): Expected artifact of CI/CD trusted-publisher flow alongside valid SLSA provenance. ai
source-diff net-exec-file:dist/assets/index-DUWBgT-P.js AI (source-diff): Standard Vite modulepreload fetch polyfill in bundled output, no exfil behavior. ai
source-diff obfuscated-file:dist/assets/index-DUWBgT-P.js AI (source-diff): Vite/rollup bundled frontend asset for this editor package, not obfuscation. ai
source-diff obfuscated-file:dist/assets/index-hH7j9X1k.js AI (source-diff): Vite-bundled frontend asset, consistent with declared build:static script. ai
source-diff obfuscated-file:dist/assets/index-ZOrwlfeV.js AI (source-diff): Vite-bundled dist asset, not obfuscation; consistent with build:static script. ai
source-diff obfuscated-file:dist/assets/index-C7wAZ2B2.js AI (source-diff): Vite-bundled frontend asset, not true obfuscation; consistent with package's build tooling. ai
source-diff net-exec-file:dist/assets/index-BCljFOyw.js AI (source-diff): Standard Vite modulepreload polyfill fetch, not dropper behavior. ai
source-diff obfuscated-file:dist/assets/index-BCljFOyw.js AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation. ai
source-diff net-exec-file:dist/assets/index-BJmWRAsv.js AI (source-diff): fetch() calls are standard vite modulepreload polyfill, no malicious behavior. ai
source-diff obfuscated-file:dist/assets/index-BJmWRAsv.js AI (source-diff): Vite/Rollup bundled output for the editor frontend, not obfuscation. ai
source-diff obfuscated-file:dist/assets/index-By6TnR5x.js AI (source-diff): Vite/Rollup bundled frontend asset, not true obfuscation — long minified lines expected. ai
source-diff net-exec-file:dist/assets/index-By6TnR5x.js AI (source-diff): fetch() is vite's modulepreload polyfill in bundled SPA output, not a dropper. ai
source-diff obfuscated-file:dist/assets/index-6nt9fjbB.js AI (source-diff): Vite/Rollup bundled dist asset, not obfuscation; consistent with build:static script. ai
source-diff source-size-dropped AI (source-diff): Bundle size fluctuation from Vite build output, no stub/redirect behavior evident. ai
publish-pattern new-deps-added AI (publish-pattern): fflate is a well-known compression lib, benign build-time swap for @stackblitz/sdk. ai
source-diff obfuscated-file:dist/assets/index-D7-O5u45.js AI (source-diff): Vite/rolldown bundled static asset, not obfuscation; standard for this editor package's dist build. ai
dependencies unvetted-dep:@nestia/migrate AI (dependencies): Sibling package in the same nestia monorepo; stable false positive for this package. ai

Versions (showing 21 of 21)

Version Deps Published
12.0.0 8 / 20
11.3.4 8 / 23
11.3.3 8 / 23
11.3.2 8 / 23
11.3.1 8 / 23
11.3.0 8 / 23
11.2.1 8 / 23
11.2.0 8 / 23
11.1.0 8 / 23
11.0.2 8 / 23
11.0.1 8 / 23
11.0.0 8 / 23
10.0.2 10 / 23
10.0.1 10 / 23
10.0.0 10 / 23
9.1.1 10 / 23
9.1.0 10 / 23
9.0.3 10 / 23
9.0.2 10 / 23
9.0.1 10 / 23
9.0.0 10 / 23

v12.0.0

2 findings
HIGH New obfuscated file: dist/assets/index-D7-O5u45.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v11.0.1

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/assets/index-DORxj52S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-DORxj52S.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: samchon → GitHub Actions (on 2026-03-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v11.0.0

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

HIGH New obfuscated file: dist/assets/index-DUWBgT-P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-DUWBgT-P.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: samchon → GitHub Actions (on 2026-03-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-03-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v10.0.2

4 findings
HIGH New obfuscated file: dist/assets/index-mRHc7mME.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-mRHc7mME.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: samchon → GitHub Actions (on 2026-01-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-01-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v10.0.1

4 findings
HIGH New obfuscated file: dist/assets/index-B4dcJE1c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-B4dcJE1c.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: samchon → GitHub Actions (on 2026-01-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2026-01-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v10.0.0

4 findings
HIGH New obfuscated file: dist/assets/index-BkCuFHhN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-BkCuFHhN.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: samchon → GitHub Actions (on 2025-12-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (samchon) on 2025-12-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v9.1.1

3 findings
HIGH New obfuscated file: dist/assets/index-6I93ebLy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-6I93ebLy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.1.0

3 findings
HIGH New obfuscated file: dist/assets/index-D0p46kEY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-D0p46kEY.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.3

3 findings
HIGH New obfuscated file: dist/assets/index-CazOgca4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-CazOgca4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.2

3 findings
HIGH New obfuscated file: dist/assets/index-BfCvApiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-BfCvApiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.1

3 findings
HIGH New obfuscated file: dist/assets/index-IJ9szrWO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/assets/index-IJ9szrWO.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.