@owox/web
Web interface for OWOX Data Marts - an open-source solution for Data Analysts
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/assets/index-DZ3jEYdf.js | AI (source-diff): Vite-bundled minified output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/assets/RelationshipCanvas-CI3MvKBM.js | AI (source-diff): Standard bundler modulepreload fetch polyfill, no malicious network exec. | ai | |
| source-diff | obfuscated-file:dist/assets/RelationshipCanvas-CI3MvKBM.js | AI (source-diff): Vite-bundled minified output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DcFjVifs.js | AI (source-diff): Vite-bundled build output, not obfuscation; contains standard React license banner. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @tanstack/react-query is a well-known, widely used React data library. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DRY20jAX.js | AI (source-diff): Vite/esbuild minified bundle, not obfuscation; consistent with package's build script. | ai | |
| source-diff | obfuscated-file:dist/assets/index-D0ToJutM.js | AI (source-diff): Vite/Rollup bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CMyHjkgu.js | AI (source-diff): Minified Vite/React bundle output, not obfuscation; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Bctu6f9K.js | AI (source-diff): Vite/Rollup bundled build output, not true obfuscation - matches React/vite license headers. | ai | |
| source-diff | obfuscated-file:dist/assets/RelationshipCanvas-BztHh6P0.js | AI (source-diff): Bundled React/lucide-react chunk, minified build output. | ai | |
| phantom-deps | phantom-dep:styled-components | AI (phantom-deps): Monorepo config-referenced dep, expected false positive for this build. | ai | |
| phantom-deps | phantom-dep:rete | AI (phantom-deps): Monorepo config-referenced dep, expected false positive for this build. | ai | |
| source-diff | net-exec-file:dist/assets/RelationshipCanvas-BztHh6P0.js | AI (source-diff): Fetch call is the standard Vite modulepreload helper, not exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-dfv6qWu-.js | AI (source-diff): Vite bundler output, minified not obfuscated; contains standard modulepreload polyfill. | ai | |
| source-diff | obfuscated-file:dist/assets/ModelCanvas-R-5Z2Wo9.js | AI (source-diff): Vite-bundled minified output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/RelationshipCanvas-Bf4UjOHF.js | AI (source-diff): Vite-bundled minified output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Bn6xf3W7.js | AI (source-diff): Vite bundler banner confirmed; large minified app bundle. | ai | |
| source-diff | obfuscated-file:dist/assets/viewport-ztZvIm-X.js | AI (source-diff): Vite-bundled minified output with license headers, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@xyflow/react | AI (phantom-deps): New UI library used in bundled canvas components, not scannable pre-build. | ai | |
| phantom-deps | phantom-dep:@dagrejs/dagre | AI (phantom-deps): Graph layout lib used by flow canvas, bundled output not scannable. | ai | |
| source-diff | obfuscated-file:dist/assets/RelationshipCanvas-DHD_684J.js | AI (source-diff): Vite-bundled canvas feature chunk; samples show lucide-react and rete library code. | ai | |
| source-diff | net-exec-file:dist/assets/RelationshipCanvas-DHD_684J.js | AI (source-diff): Network+exec pattern is from bundled rete/React code, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/assets/index-D5aLo6qw.js | AI (source-diff): Standard Vite production bundle; samples show React/license headers, not obfuscation. | ai | |
| dependencies | unvetted-dep:@owox/ui | AI (dependencies): Local monorepo path dependency to same-org sibling package; not a third-party supply chain risk. | ai | |
| phantom-deps | phantom-dep:react-hot-toast | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/utilities | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/sortable | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/core | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@owox/ui | AI (phantom-deps): Monorepo sibling package; local path dep, not a supply-chain risk. | ai | |
| phantom-deps | phantom-dep:tailwindcss | AI (phantom-deps): CSS build tool referenced in config; expected for this package. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Bundled app; used transitively or in config, not a phantom risk. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Same as react; bundled app pattern. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Bundled React app; deps referenced in config/build files, not direct imports — stable FP for this package. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@hookform/resolvers | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@monaco-editor/react | AI (phantom-deps): Bundled app; stable FP. | ai | |
| phantom-deps | phantom-dep:@tailwindcss/vite | AI (phantom-deps): Build tool referenced in vite config; stable FP. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Bundled app; stable FP. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.30.1 | 17 / 15 | |
| 0.30.0 | 17 / 15 | |
| 0.29.0 | 21 / 15 | |
| 0.25.0 | 21 / 15 | |
| 0.24.0 | 21 / 15 | |
| 0.23.0 | 15 / 15 | |
| 0.22.0 | 15 / 15 | |
| 0.21.1 | 15 / 14 | |
| 0.20.0 | 15 / 14 | |
| 0.19.0 | 14 / 13 | |
| 0.18.0 | 14 / 13 | |
| 0.17.0 | 14 / 13 | |
| 0.15.0 | 14 / 12 | |
| 0.12.0 | 14 / 11 | |
| 0.11.0 | 14 / 11 | |
| 0.6.0 | 14 / 11 |
v0.30.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.19.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.18.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.