← Home

@opencor/opencor

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

agarny

Keywords

vuecomponentopencorcellmlsed-mlomexcombine

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/quill-CNUBlgYr.js AI (source-diff): Standard bundled lib code, no concrete malicious network behavior found. ai
source-diff obfuscated-file:dist/quill-CNUBlgYr.js AI (source-diff): Bundled quill/lodash chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-Bdn_8jQ3.js AI (source-diff): Vite/rollup bundled vue app output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-Dz6m_943.js AI (source-diff): Bundled Vite/Vue build output, not true obfuscation. ai
source-diff net-exec-file:dist/quill-Ey33_3OK.js AI (source-diff): CDN ESM imports are build-time module resolution, not runtime dropper behavior. ai
source-diff obfuscated-file:dist/quill-Ey33_3OK.js AI (source-diff): Bundled quill library code, minified not obfuscated. ai
source-diff obfuscated-file:dist/quill-DR7SCAb4.js AI (source-diff): Bundled quill/lodash vendor code, minified not obfuscated. ai
source-diff net-exec-file:dist/quill-DR7SCAb4.js AI (source-diff): Bundler dynamic import machinery, not a loader/dropper; no hostile destination. ai
source-diff obfuscated-file:dist/index-CVtvUNos.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation; consistent with build tooling. ai
source-diff obfuscated-file:dist/quill-BxQjL-ej.js AI (source-diff): Bundled quill dependency chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-DbIZLeOa.js AI (source-diff): Vite/rollup bundled output, not true obfuscation. ai
source-diff net-exec-file:dist/quill-BxQjL-ej.js AI (source-diff): Generic bundled utility code, no concrete malicious network+exec behavior. ai
source-diff obfuscated-file:dist/quill-c3wy0V4g.js AI (source-diff): Minified vendor chunk (lodash/quill), not obfuscated malware. ai
source-diff net-exec-file:dist/quill-c3wy0V4g.js AI (source-diff): Bundled vendor code; network+exec pattern is standard lodash/quill internals, not a loader. ai
source-diff obfuscated-file:dist/index-CXumcUSA.js AI (source-diff): Minified Vite bundle output, not true obfuscation; no malicious behavior found. ai
phantom-deps phantom-dep:tailwindcss-primeui AI (phantom-deps): Tailwind plugin used via config, not JS import. ai
phantom-deps phantom-dep:@tailwindcss/postcss AI (phantom-deps): PostCSS plugin referenced in build config, not JS import. ai
phantom-deps phantom-dep:tailwindcss AI (phantom-deps): CSS/build-tool dep consumed via config, not JS import; false positive for this stack. ai
phantom-deps phantom-dep:@tailwindcss/vite AI (phantom-deps): Vite plugin referenced in vite config, not scannable by import heuristic. ai
source-diff obfuscated-file:dist/index-SWtGxqQi.js AI (source-diff): Vite/Rollup bundled minified output, not true obfuscation. ai
source-diff net-exec-file:dist/index-SWtGxqQi.js AI (source-diff): CDN ESM imports for mathjs/plotly libs used by the app, not a dropper. ai
source-diff obfuscated-file:dist/quill-DJwMCWbC.js AI (source-diff): Bundled quill editor dependency output. ai
source-diff net-exec-file:dist/quill-DJwMCWbC.js AI (source-diff): Bundled build output, not dropper behavior. ai
source-diff obfuscated-file:dist/index-jYjiqU58.js AI (source-diff): Vite/Rollup bundle output, not true obfuscation. ai
source-diff net-exec-file:dist/index-jYjiqU58.js AI (source-diff): Bundled app code importing CDN ESM libs, no malicious exec target. ai
source-diff obfuscated-file:dist/quill-DV5CwDZS.js AI (source-diff): Bundled quill dependency, minified not obfuscated. ai
source-diff net-exec-file:dist/quill-DV5CwDZS.js AI (source-diff): Bundled dependency chunk, no malicious behavior. ai
phantom-deps phantom-dep:jszip AI (phantom-deps): Used inside bundled dist, not detectable via source scan. ai
phantom-deps phantom-dep:vue-tippy AI (phantom-deps): Used inside bundled dist, not detectable via source scan. ai
source-diff obfuscated-file:dist/quill-D-p1Ilcy.js AI (source-diff): Bundled quill vendor chunk, standard minification. ai
source-diff net-exec-file:dist/quill-D-p1Ilcy.js AI (source-diff): Lodash-style Function()/global detection pattern in bundled code, no exfil target. ai
source-diff obfuscated-file:dist/index-DzfDkBnj.js AI (source-diff): Vite bundle output, not true obfuscation; large minified vendor chunk. ai
source-diff net-exec-file:dist/quill-Do3h7dmn.js AI (source-diff): Bundler chunk import graph, no fetched/executed remote payload. ai
source-diff obfuscated-file:dist/index-C9HHfqsk.js AI (source-diff): Vite-bundled Vue app chunk, not true obfuscation. ai
source-diff obfuscated-file:dist/quill-Do3h7dmn.js AI (source-diff): Bundled quill lib chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-BlVVVssG.js AI (source-diff): Vite/rollup bundled vue app code, not true obfuscation. ai
source-diff net-exec-file:dist/quill-B2-mjajw.js AI (source-diff): Bundled output importing CDN ESM libs (plotly/mathjs), not a dropper. ai
source-diff obfuscated-file:dist/quill-B2-mjajw.js AI (source-diff): Bundled quill editor + lodash-style utils, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-BO4fwPpK.js AI (source-diff): Vite/esbuild bundled output, not true obfuscation; no malicious behavior found. ai
source-diff net-exec-file:dist/quill-Ch1Pv3Qv.js AI (source-diff): CDN ESM imports of plotly/mathjs in bundled build, not a dropper pattern. ai
source-diff obfuscated-file:dist/quill-Ch1Pv3Qv.js AI (source-diff): Bundled quill dependency chunk; minified not obfuscated. ai
phantom-deps phantom-dep:@opencor/libopencor-types AI (phantom-deps): Same-org type-only dep, expected not to be directly imported in source scan. ai
dependencies unvetted-dep:@opencor/libopencor-types AI (dependencies): Same-org sibling package, version-pinned to libopencorVersion field. ai
publish-pattern new-deps-added AI (publish-pattern): Same-org first-party dependency, not an external supply-chain risk. ai
phantom-deps phantom-dep:js-cookie AI (phantom-deps): js-cookie referenced in config files; stable false positive for this package. ai
phantom-deps phantom-dep:firebase AI (phantom-deps): Declared runtime dep; referenced in config files as expected for this package. ai
phantom-deps phantom-dep:octokit AI (phantom-deps): Declared runtime dep; referenced in config files as expected for this package. ai
phantom-deps phantom-dep:quill AI (phantom-deps): Used via config/plugin registration, not direct import; stable pattern for this Vue component library. ai
phantom-deps phantom-dep:ua-parser-js AI (phantom-deps): Utility dep referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:jsonschema AI (phantom-deps): Referenced in config context; stable false positive for this package. ai
phantom-deps phantom-dep:crypto-js AI (phantom-deps): Utility dep used indirectly; stable false positive for this package. ai
phantom-deps phantom-dep:xxhash-wasm AI (phantom-deps): Platform-specific binary dep; not directly imported in JS — stable FP. ai
phantom-deps phantom-dep:@primevue/auto-import-resolver AI (phantom-deps): Build-time resolver referenced in vite config; stable FP for this package. ai
phantom-deps phantom-dep:@primeuix/themes AI (phantom-deps): Theme package referenced in config; stable FP for this package. ai
phantom-deps phantom-dep:@napi-rs/keyring AI (phantom-deps): Native binding referenced in config; stable FP for this package. ai
phantom-deps phantom-dep:primevue AI (phantom-deps): Vue component library; primevue referenced in config/build, not direct imports — stable FP. ai
phantom-deps phantom-dep:primeicons AI (phantom-deps): Icon font dep used via CSS/config, not direct JS import — stable FP. ai
phantom-deps phantom-dep:@vueuse/core AI (phantom-deps): Referenced in config files; stable FP for this package. ai

Versions (showing 51 of 71)

View all versions
Version Deps Published
0.20260727.1 9 / 20
0.20260724.1 9 / 20
0.20260619.0 8 / 19
0.20260616.0 8 / 19
0.20260612.4 8 / 19
0.20260612.3 8 / 19
0.20260612.2 8 / 19
0.20260612.1 8 / 19
0.20260612.0 8 / 19
0.20260611.0 8 / 19
0.20260604.1 8 / 19
0.20260604.0 8 / 19
0.20260417.1 8 / 19
0.20260417.0 8 / 19
0.20260416.3 8 / 19
0.20260416.2 8 / 19
0.20260416.1 8 / 19
0.20260416.0 8 / 19
0.20260410.0 8 / 19
0.20260319.0 8 / 19
0.20260318.1 8 / 19
0.20260318.0 8 / 18
0.20260317.1 8 / 18
0.20260314.0 8 / 17
0.20260311.0 8 / 16
0.20260304.2 8 / 16
0.20260304.1 8 / 16
0.20260304.0 8 / 16
0.20260303.1 8 / 16
0.20260227.1 9 / 16
0.20260227.0 9 / 16
0.20260215.0 9 / 16
0.20260209.3 13 / 17
0.20260207.1 13 / 17
0.20251223.1 10 / 15
0.20251222.0 10 / 15
0.20251215.0 10 / 15
0.20251210.0 10 / 15
0.20251206.2 10 / 13
0.20251206.1 10 / 13
0.20251206.0 10 / 13
0.20251205.2 10 / 13
0.20251205.0 12 / 13
0.20251204.4 12 / 13
0.20251204.3 12 / 13
0.20251204.2 12 / 13
0.20251112.0 9 / 12
0.20251111.0 9 / 12
0.20251110.0 9 / 12
0.20251027.0 10 / 13
0.20251024.0 10 / 13

v0.20260727.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20260724.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20260227.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20260227.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20260215.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20260209.3

5 findings
HIGH New obfuscated file: dist/index-jYjiqU58.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-jYjiqU58.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/quill-DV5CwDZS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-DV5CwDZS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20260207.1

5 findings
HIGH New obfuscated file: dist/index-SWtGxqQi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-SWtGxqQi.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/quill-DJwMCWbC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-DJwMCWbC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251223.1

4 findings
HIGH New obfuscated file: dist/index-DzfDkBnj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-D-p1Ilcy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-D-p1Ilcy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251222.0

4 findings
HIGH New obfuscated file: dist/index-BlVVVssG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-B2-mjajw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-B2-mjajw.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251215.0

4 findings
HIGH New obfuscated file: dist/index-CVtvUNos.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-DR7SCAb4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-DR7SCAb4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251210.0

4 findings
HIGH New obfuscated file: dist/index-Bdn_8jQ3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-CNUBlgYr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-CNUBlgYr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251206.2

4 findings
HIGH New obfuscated file: dist/index-DbIZLeOa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-BxQjL-ej.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-BxQjL-ej.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251206.1

4 findings
HIGH New obfuscated file: dist/index-C9HHfqsk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-Do3h7dmn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-Do3h7dmn.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251206.0

4 findings
HIGH New obfuscated file: dist/index-Dz6m_943.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-Ey33_3OK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-Ey33_3OK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251205.0

4 findings
HIGH New obfuscated file: dist/index-CXumcUSA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-c3wy0V4g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-c3wy0V4g.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251204.2

4 findings
HIGH New obfuscated file: dist/index-BO4fwPpK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/quill-Ch1Pv3Qv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/quill-Ch1Pv3Qv.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251112.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251111.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251110.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251027.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20251024.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.