@penclipai/server
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:base64-decode | AI (semgrep): Fires inside minified mermaid bundle; no hostile payload context. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/diagram-FQU43EPY-DvMwJlCi.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/diagram-G47NLZAW-DPY0Jz_y.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/diagram-NH7WQ7WH-BpopeEhp.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/diagram-OA4YK3LP-Qpu05z9X.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/diagram-WEI45ONY-DHnvw9XU.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/arc-HZhAwbOs.js | AI (source-diff): Vite-bundled mermaid/d3 chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/architectureDiagram-ZJ3FMSHR-BteMjuOn.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/blockDiagram-677ZJIJ3-Iq66uZjf.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/browser-ponyfill-BBsuyZJt.js | AI (source-diff): Vite-bundled fetch ponyfill; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/c4Diagram-LMCZKHZV-_nlglj7I.js | AI (source-diff): Vite-bundled mermaid C4 diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/cose-bilkent-JH36ORCC-CY-zAygY.js | AI (source-diff): Vite-bundled cytoscape layout chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/cynefin-VYW2F7L2-BQSQ1HKr.js | AI (source-diff): Vite-bundled mermaid/LSP chunk; minified build output. | ai | |
| source-diff | net-exec-file:ui-dist/assets/cynefin-VYW2F7L2-BQSQ1HKr.js | AI (source-diff): Same minified mermaid/LSP bundle; no hostile network destination. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/cynefinDiagram-TSTJHNR4-NJCuFrZL.js | AI (source-diff): Vite-bundled mermaid diagram chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/cytoscape.esm-D8joxN9f.js | AI (source-diff): Vite-bundled cytoscape ESM chunk; minified build output. | ai | |
| source-diff | obfuscated-file:ui-dist/assets/dagre-VKFMJZFB-DAUPIc8g.js | AI (source-diff): Vite-bundled dagre layout chunk; minified build output. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): pino-pretty is a declared runtime dep used as a pino transport; phantom-dep heuristic fires because it's not directly imported in source. | ai | |
| phantom-deps | phantom-dep:embedded-postgres | AI (phantom-deps): embedded-postgres is a declared runtime dep; phantom-dep heuristic fires but it's legitimately used via config/runtime initialization. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Legitimate org package; missing description is a style issue, not a malware indicator. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is common; no other risk signals warrant blocking on this alone. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped package @penclipai/server; name collision with 'semver' is coincidental, not impersonation. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 2026.704.0 | 37 / 14 | |
| 2026.607.0 | 36 / 14 | |
| 2026.522.0 | 36 / 14 | |
| 2026.521.0 | 36 / 14 | |
| 2026.505.0 | 34 / 14 | |
| 2026.426.0 | 33 / 14 | |
| 2026.419.0 | 33 / 14 | |
| 2026.413.0 | 33 / 14 | |
| 2026.411.0 | 33 / 14 | |
| 2026.410.0 | 33 / 14 | |
| 2026.406.0 | 34 / 14 | |
| 2026.404.0 | 34 / 14 |
v2026.704.0
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.