@openobserve/browser-rum
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Metadata-only drift; no behavioral change vs prior approved version. | ai | |
| source-diff | obfuscated-file:bundle/chunks/profiler-da8b374510b8838a8938-openobserve-rum.js | AI (source-diff): Webpack-bundled minified chunk, not obfuscation; matches package's own SDK code. | ai | |
| source-diff | obfuscated-file:bundle/chunks/recorder-f4f0f1d89a0eadca1e0f-openobserve-rum.js | AI (source-diff): Webpack-bundled minified chunk, not obfuscation; matches package's own SDK code. | ai | |
| source-diff | obfuscated-file:bundle/chunks/datadogProfiler-6cb347afe0826c57b10c-openobserve-rum.js | AI (source-diff): Webpack-bundled profiler chunk, minified build output. | ai | |
| source-diff | obfuscated-file:bundle/chunks/datadogRecorder-a9c596a576daf366fb16-openobserve-rum.js | AI (source-diff): Webpack-bundled RUM recorder chunk, minified build output. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Same-org monorepo sibling package at matching version. | ai | |
| source-diff | obfuscated-file:bundle/chunks/recorder-8d1794a6ae1ceb03278c-openobserve-rum.js | AI (source-diff): Webpack-bundled chunk, build output not obfuscation. | ai | |
| dependencies | unvetted-dep:@openobserve/js-core | AI (dependencies): First-party sibling package from same org/monorepo. | ai | |
| source-diff | obfuscated-file:bundle/chunks/profiler-0d432ecf55d554e7d984-openobserve-rum.js | AI (source-diff): Webpack-bundled chunk, build output not obfuscation. | ai | |
| source-diff | obfuscated-file:esm/domain/deflate/deflateWorker.mjs | AI (source-diff): Minified bundled deflate worker (pako), not true obfuscation. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.4.1 | 3 / 3 | |
| 0.4.0 | 3 / 3 | |
| 0.3.4 | 2 / 2 | |
| 0.3.3 | 2 / 2 | |
| 0.3.2 | 2 / 2 | |
| 0.3.1 | 2 / 2 | |
| 0.3.0 | 2 / 2 |
v0.4.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: bhargav_oo.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.4
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: bhargav_oo.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.