@opencor/opencor
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/quill-CNUBlgYr.js | AI (source-diff): Standard bundled lib code, no concrete malicious network behavior found. | ai | |
| source-diff | obfuscated-file:dist/quill-CNUBlgYr.js | AI (source-diff): Bundled quill/lodash chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-Bdn_8jQ3.js | AI (source-diff): Vite/rollup bundled vue app output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-Dz6m_943.js | AI (source-diff): Bundled Vite/Vue build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/quill-Ey33_3OK.js | AI (source-diff): CDN ESM imports are build-time module resolution, not runtime dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/quill-Ey33_3OK.js | AI (source-diff): Bundled quill library code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/quill-DR7SCAb4.js | AI (source-diff): Bundled quill/lodash vendor code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/quill-DR7SCAb4.js | AI (source-diff): Bundler dynamic import machinery, not a loader/dropper; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/index-CVtvUNos.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation; consistent with build tooling. | ai | |
| source-diff | obfuscated-file:dist/quill-BxQjL-ej.js | AI (source-diff): Bundled quill dependency chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-DbIZLeOa.js | AI (source-diff): Vite/rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/quill-BxQjL-ej.js | AI (source-diff): Generic bundled utility code, no concrete malicious network+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/quill-c3wy0V4g.js | AI (source-diff): Minified vendor chunk (lodash/quill), not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/quill-c3wy0V4g.js | AI (source-diff): Bundled vendor code; network+exec pattern is standard lodash/quill internals, not a loader. | ai | |
| source-diff | obfuscated-file:dist/index-CXumcUSA.js | AI (source-diff): Minified Vite bundle output, not true obfuscation; no malicious behavior found. | ai | |
| phantom-deps | phantom-dep:tailwindcss-primeui | AI (phantom-deps): Tailwind plugin used via config, not JS import. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/postcss | AI (phantom-deps): PostCSS plugin referenced in build config, not JS import. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): CSS/build-tool dep consumed via config, not JS import; false positive for this stack. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/vite | AI (phantom-deps): Vite plugin referenced in vite config, not scannable by import heuristic. | ai | |
| source-diff | obfuscated-file:dist/index-SWtGxqQi.js | AI (source-diff): Vite/Rollup bundled minified output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-SWtGxqQi.js | AI (source-diff): CDN ESM imports for mathjs/plotly libs used by the app, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/quill-DJwMCWbC.js | AI (source-diff): Bundled quill editor dependency output. | ai | |
| source-diff | net-exec-file:dist/quill-DJwMCWbC.js | AI (source-diff): Bundled build output, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/index-jYjiqU58.js | AI (source-diff): Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-jYjiqU58.js | AI (source-diff): Bundled app code importing CDN ESM libs, no malicious exec target. | ai | |
| source-diff | obfuscated-file:dist/quill-DV5CwDZS.js | AI (source-diff): Bundled quill dependency, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/quill-DV5CwDZS.js | AI (source-diff): Bundled dependency chunk, no malicious behavior. | ai | |
| phantom-deps | phantom-dep:jszip | AI (phantom-deps): Used inside bundled dist, not detectable via source scan. | ai | |
| phantom-deps | phantom-dep:vue-tippy | AI (phantom-deps): Used inside bundled dist, not detectable via source scan. | ai | |
| source-diff | obfuscated-file:dist/quill-D-p1Ilcy.js | AI (source-diff): Bundled quill vendor chunk, standard minification. | ai | |
| source-diff | net-exec-file:dist/quill-D-p1Ilcy.js | AI (source-diff): Lodash-style Function()/global detection pattern in bundled code, no exfil target. | ai | |
| source-diff | obfuscated-file:dist/index-DzfDkBnj.js | AI (source-diff): Vite bundle output, not true obfuscation; large minified vendor chunk. | ai | |
| source-diff | net-exec-file:dist/quill-Do3h7dmn.js | AI (source-diff): Bundler chunk import graph, no fetched/executed remote payload. | ai | |
| source-diff | obfuscated-file:dist/index-C9HHfqsk.js | AI (source-diff): Vite-bundled Vue app chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/quill-Do3h7dmn.js | AI (source-diff): Bundled quill lib chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-BlVVVssG.js | AI (source-diff): Vite/rollup bundled vue app code, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/quill-B2-mjajw.js | AI (source-diff): Bundled output importing CDN ESM libs (plotly/mathjs), not a dropper. | ai | |
| source-diff | obfuscated-file:dist/quill-B2-mjajw.js | AI (source-diff): Bundled quill editor + lodash-style utils, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-BO4fwPpK.js | AI (source-diff): Vite/esbuild bundled output, not true obfuscation; no malicious behavior found. | ai | |
| source-diff | net-exec-file:dist/quill-Ch1Pv3Qv.js | AI (source-diff): CDN ESM imports of plotly/mathjs in bundled build, not a dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/quill-Ch1Pv3Qv.js | AI (source-diff): Bundled quill dependency chunk; minified not obfuscated. | ai | |
| phantom-deps | phantom-dep:@opencor/libopencor-types | AI (phantom-deps): Same-org type-only dep, expected not to be directly imported in source scan. | ai | |
| dependencies | unvetted-dep:@opencor/libopencor-types | AI (dependencies): Same-org sibling package, version-pinned to libopencorVersion field. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Same-org first-party dependency, not an external supply-chain risk. | ai | |
| phantom-deps | phantom-dep:js-cookie | AI (phantom-deps): js-cookie referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:firebase | AI (phantom-deps): Declared runtime dep; referenced in config files as expected for this package. | ai | |
| phantom-deps | phantom-dep:octokit | AI (phantom-deps): Declared runtime dep; referenced in config files as expected for this package. | ai | |
| phantom-deps | phantom-dep:quill | AI (phantom-deps): Used via config/plugin registration, not direct import; stable pattern for this Vue component library. | ai | |
| phantom-deps | phantom-dep:ua-parser-js | AI (phantom-deps): Utility dep referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:jsonschema | AI (phantom-deps): Referenced in config context; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:crypto-js | AI (phantom-deps): Utility dep used indirectly; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:xxhash-wasm | AI (phantom-deps): Platform-specific binary dep; not directly imported in JS — stable FP. | ai | |
| phantom-deps | phantom-dep:@primevue/auto-import-resolver | AI (phantom-deps): Build-time resolver referenced in vite config; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@primeuix/themes | AI (phantom-deps): Theme package referenced in config; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@napi-rs/keyring | AI (phantom-deps): Native binding referenced in config; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:primevue | AI (phantom-deps): Vue component library; primevue referenced in config/build, not direct imports — stable FP. | ai | |
| phantom-deps | phantom-dep:primeicons | AI (phantom-deps): Icon font dep used via CSS/config, not direct JS import — stable FP. | ai | |
| phantom-deps | phantom-dep:@vueuse/core | AI (phantom-deps): Referenced in config files; stable FP for this package. | ai |
Versions (showing 51 of 71)
v0.20260727.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20260724.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20260227.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20260227.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20260215.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20260209.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20260207.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251223.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251222.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251215.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251210.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251206.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251206.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251206.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251205.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251204.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251112.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251111.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251110.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251027.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20251024.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.