@next-core/brick-container
Brick Container Server
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/preview/vendors.c77c822c.js | AI (source-diff): Vendor bundle for preview; network+exec pattern is standard library bundling. | ai | |
| source-diff | obfuscated-file:dist/all.cdbcb286.js | AI (source-diff): Standard webpack bundle output for this build-tool package; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/all.cdbcb286.js | AI (source-diff): Webpack bundle with HTTP interceptors and dynamic module loading — normal for a brick container runtime. | ai | |
| source-diff | obfuscated-file:dist/preview/core.30b8e824.js | AI (source-diff): Standard webpack bundle for preview runtime; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/preview/core.30b8e824.js | AI (source-diff): Preview runtime fetches bootstrap config and renders bricks — expected behavior. | ai | |
| source-diff | obfuscated-file:dist/main.713586ae.js | AI (source-diff): Webpack entry bundle; minified output is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/preview/main.de0b7136.js | AI (source-diff): Preview entry bundle; standard webpack minification. | ai | |
| source-diff | obfuscated-file:dist/polyfill.7bd3acdf.js | AI (source-diff): core-js polyfill bundle; minified by design. | ai | |
| source-diff | net-exec-file:dist/polyfill.7bd3acdf.js | AI (source-diff): Polyfill bundle; dynamic code patterns are core-js feature detection, not malware. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal monorepo component; sparse README and no keywords are expected for this package type. | ai | |
| source-diff | obfuscated-file:dist/dll.8954cc01.js | AI (source-diff): Standard webpack DLL bundle; canonical chunk-loading boilerplate, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/dll.8954cc01.js | AI (source-diff): Webpack dynamic script injection for lazy chunk loading; expected pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/icons--app.93f15145.js | AI (source-diff): Minified webpack icon bundle; SVG path data causes long lines, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/preview.ba16cd1fb77a727d0aac.js | AI (source-diff): Standard webpack preview bundle; boilerplate runtime code. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Used only in dev-server SSL cert generation (serve.js); not a runtime/install-time risk. | ai | |
| source-diff | obfuscated-file:dist/main.863487174fce157f823c.js | AI (source-diff): Standard webpack main bundle; boilerplate runtime code. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Fires in dev-server config loader (dev.config.js); stable pattern for local dev tooling across versions. | ai | |
| phantom-deps | phantom-dep:mockdate | AI (phantom-deps): mockdate is a runtime dep listed in dependencies; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 3.25.1 | 13 / 19 | |
| 3.25.0 | 13 / 19 | |
| 3.24.17 | 13 / 19 | |
| 2.99.1 | 12 / 31 | |
| 2.99.0 | 12 / 31 | |
| 2.98.23 | 12 / 31 | |
| 2.98.22 | 12 / 31 |
v3.25.1
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.25.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.24.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.99.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.99.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.98.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.98.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.