@peerbit/server
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/ui/assets/index-La-G0Wni.js | AI (source-diff): Vite-bundled frontend asset copied via postbuild script, not true obfuscation. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established monorepo package; missing description is cosmetic. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-Dst3R_bZ.js | AI (source-diff): Vite-bundled frontend asset copied via postbuild script, not injected obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-0tCU_HqE.js | AI (source-diff): Vite-bundled frontend UI asset from documented postbuild step, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-Uwc-1pv0.js | AI (source-diff): Vite-bundled frontend asset copied via documented postbuild script, not real obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-DVtj_GOf.js | AI (source-diff): Vite-bundled frontend UI asset, not obfuscation; matches project's documented build-ui step. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-CjZwCewh.js | AI (source-diff): Vite-bundled frontend UI asset, not obfuscated code. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Localhost nginx proxy_pass constant, not an exfil endpoint. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-e3g42MbC.js | AI (source-diff): Bundled axios/vendor chunk from frontend build, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@libp2p/tcp | AI (phantom-deps): Referenced in config files for runtime use; stable false positive for this server package. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped monorepo package @peerbit/server; Levenshtein match to 'semver' is a false positive. | ai | |
| phantom-deps | phantom-dep:@libp2p/websockets | AI (phantom-deps): Referenced in config files for runtime use; stable false positive for this server package. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Server CLI spawning child processes; spreading process.env is standard and intentional here. | ai | |
| dependencies | unvetted-dep:peerbit | AI (dependencies): First-party peerbit monorepo dependency; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@peerbit/time | AI (dependencies): First-party @peerbit/* monorepo dependency. | ai | |
| dependencies | unvetted-dep:@dao-xyz/borsh | AI (dependencies): Same org (dao-xyz) serialization library; stable false positive. | ai | |
| dependencies | unvetted-dep:@peerbit/blocks | AI (dependencies): First-party @peerbit/* monorepo dependency. | ai | |
| dependencies | unvetted-dep:@peerbit/crypto | AI (dependencies): First-party @peerbit/* monorepo dependency. | ai | |
| dependencies | unvetted-dep:@peerbit/pubsub | AI (dependencies): First-party @peerbit/* monorepo dependency. | ai | |
| dependencies | unvetted-dep:@peerbit/program | AI (dependencies): First-party @peerbit/* monorepo dependency. | ai |
Versions (showing 51 of 67)
| Version | Deps | Published |
|---|---|---|
| 7.0.2 | 26 / 9 | |
| 7.0.1 | 26 / 9 | |
| 7.0.0 | 26 / 9 | |
| 6.0.42 | 25 / 10 | |
| 6.0.41 | 25 / 10 | |
| 6.0.40 | 25 / 10 | |
| 6.0.39 | 25 / 10 | |
| 6.0.38 | 25 / 10 | |
| 6.0.37 | 25 / 10 | |
| 6.0.36 | 25 / 10 | |
| 6.0.35 | 25 / 10 | |
| 6.0.34 | 25 / 10 | |
| 6.0.33 | 25 / 10 | |
| 6.0.32 | 25 / 10 | |
| 6.0.31 | 25 / 10 | |
| 6.0.30 | 25 / 10 | |
| 6.0.29 | 25 / 10 | |
| 6.0.28 | 25 / 10 | |
| 6.0.27 | 25 / 10 | |
| 6.0.26 | 25 / 10 | |
| 6.0.25 | 25 / 10 | |
| 6.0.24 | 25 / 10 | |
| 6.0.23 | 25 / 10 | |
| 6.0.22 | 25 / 10 | |
| 6.0.21 | 25 / 10 | |
| 6.0.20 | 25 / 10 | |
| 6.0.19 | 25 / 10 | |
| 6.0.18 | 25 / 10 | |
| 6.0.17 | 25 / 10 | |
| 6.0.16 | 25 / 10 | |
| 6.0.15 | 25 / 10 | |
| 6.0.14 | 25 / 10 | |
| 6.0.13 | 25 / 10 | |
| 6.0.12 | 25 / 10 | |
| 6.0.11 | 25 / 10 | |
| 6.0.10 | 25 / 10 | |
| 6.0.9 | 25 / 10 | |
| 6.0.8 | 25 / 10 | |
| 6.0.7 | 25 / 10 | |
| 6.0.6 | 25 / 10 | |
| 6.0.5 | 25 / 10 | |
| 6.0.4 | 25 / 10 | |
| 6.0.3 | 25 / 10 | |
| 6.0.2 | 25 / 10 | |
| 6.0.0 | 25 / 10 | |
| 5.10.14 | 25 / 10 | |
| 5.10.13 | 25 / 10 | |
| 5.10.12 | 25 / 10 | |
| 5.10.11 | 25 / 10 | |
| 5.10.10 | 25 / 10 | |
| 5.10.9 | 25 / 10 |
v7.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.