@pisell/pisellos
一个可扩展的前端模块化SDK框架,支持插件系统
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/modules/ScanOrderLogger/providers/feishu.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/solution/VenueBooking/index.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/solution/ScanOrder/index.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/ScanOrderLogger/index.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/SalesSummary/index.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/Quotation/index.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/OpenData/index.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/ScanOrderLogger/providers/grafana.js | AI (source-diff): Babel-compiled bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/SurchargeList/index.js | AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/solution/BookingTicket/utils/scan/applyGlobalScan.js | AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/solution/BookingTicket/utils/scan/cloudSearch.js | AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/Payment/eftpos.js | AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/solution/BookingTicket/utils/scan/handleScan.js | AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/BookingContext/index.js | AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/Customer/index.js | AI (source-diff): Babel-transpiled bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/server/modules/resource/index.js | AI (source-diff): Bundled build output, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/solution/Sales/index.js | AI (source-diff): Bundled build output, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/server/modules/schedule/index.js | AI (source-diff): Bundled build output, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/server/modules/products/index.js | AI (source-diff): Bundled build output, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/server/modules/quotation/index.js | AI (source-diff): Bundled build output, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/server/modules/menu/index.js | AI (source-diff): Bundled build output, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/server/modules/order/index.js | AI (source-diff): Bundled build output, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/modules/Holder/index.js | AI (source-diff): Babel-transpiled helper boilerplate, not true obfuscation; consistent with prior bundled dist files. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Frequent releases are normal cadence for this actively-maintained SDK (1272 versions). | ai | |
| source-diff | obfuscated-file:dist/utils/payment-number.js | AI (source-diff): father/Babel minified bundler output (regenerator-runtime preamble), not true obfuscation; benign payment-math helper. | ai | |
| source-diff | obfuscated-file:dist/server/index.js | AI (source-diff): Babel/regenerator bundler output, not true obfuscation; large SDK build artifact. | ai | |
| source-diff | obfuscated-file:dist/modules/Payment/cash.js | AI (source-diff): Babel-transpiled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/solution/Checkout/index.js | AI (source-diff): Babel-transpiled build output, not true obfuscation. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): StrategyEngine rules-expression evaluator; standard template/rules-engine use, no hostile target. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval inside SimpleWindow setTimeout/setInterval polyfill emulating browser string-handler spec; benign. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Legit monorepo SDK adding solution bundles; mass file additions are normal release pattern for this package. | ai | |
| phantom-deps | phantom-dep:@changesets/cli | AI (phantom-deps): Build/release tooling mistakenly listed as runtime dep; not a security issue for this package. | ai | |
| phantom-deps | phantom-dep:@types/lodash-es | AI (phantom-deps): TypeScript type package listed as runtime dep; not a security issue for this package. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() in a Proxy handler is standard reactive state management pattern (similar to Vue 3 reactivity), not obfuscation. Stable for this package. | ai |
Versions (showing 51 of 382)
| Version | Deps | Published |
|---|---|---|
| 3.0.93 | 5 / 11 | |
| 3.0.92 | 5 / 11 | |
| 3.0.91 | 5 / 11 | |
| 3.0.90 | 5 / 11 | |
| 3.0.89 | 5 / 11 | |
| 3.0.88 | 5 / 11 | |
| 3.0.87 | 5 / 11 | |
| 3.0.86 | 5 / 11 | |
| 3.0.85 | 5 / 11 | |
| 3.0.84 | 5 / 11 | |
| 3.0.83 | 5 / 11 | |
| 3.0.79 | 5 / 11 | |
| 3.0.73 | 5 / 11 | |
| 3.0.72 | 5 / 11 | |
| 3.0.71 | 5 / 11 | |
| 3.0.70 | 5 / 11 | |
| 3.0.69 | 5 / 11 | |
| 3.0.68 | 5 / 11 | |
| 3.0.67 | 5 / 11 | |
| 2.3.37 | 5 / 12 | |
| 2.3.36 | 5 / 12 | |
| 2.3.35 | 5 / 12 | |
| 2.3.34 | 5 / 12 | |
| 2.3.33 | 5 / 12 | |
| 2.3.32 | 5 / 12 | |
| 2.3.31 | 5 / 12 | |
| 2.3.30 | 5 / 12 | |
| 2.3.29 | 5 / 12 | |
| 2.3.28 | 5 / 12 | |
| 2.3.27 | 5 / 12 | |
| 2.3.26 | 5 / 12 | |
| 2.3.22 | 5 / 12 | |
| 2.3.21 | 5 / 12 | |
| 2.3.20 | 5 / 12 | |
| 2.3.19 | 5 / 12 | |
| 2.3.18 | 5 / 12 | |
| 2.3.17 | 5 / 12 | |
| 2.3.16 | 5 / 12 | |
| 2.3.15 | 5 / 12 | |
| 2.3.14 | 5 / 12 | |
| 2.3.13 | 5 / 12 | |
| 2.3.12 | 5 / 12 | |
| 2.3.11 | 5 / 12 | |
| 2.3.10 | 5 / 12 | |
| 2.3.9 | 5 / 12 | |
| 2.3.8 | 5 / 12 | |
| 2.3.7 | 5 / 12 | |
| 2.3.6 | 5 / 12 | |
| 2.2.271 | 5 / 12 | |
| 2.2.270 | 5 / 12 | |
| 2.2.266 | 5 / 12 |
v3.0.93
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.92
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.91
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.90
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-05-14, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.0.88
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-05-06, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v3.0.83
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.31
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.30
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.29
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-13, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.28
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-11, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.27
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.26
16 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-11, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.22
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-09, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.21
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.20
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-07, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.19
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-07, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.18
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-06, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.17
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-05, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.16
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-04, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.15
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.14
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.13
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.12
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.11
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.10
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.9
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-03, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.8
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 664 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-02, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.7
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 660 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-01, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.3.6
7 findings[Reject — re-review on republish] (prior reject: AI (source-diff): Publisher has 364 rejections; mass file additions are a persistent risk pattern for this package.) This version adds 660 new source files. A suddenly much larger package could indicate bundled/injected code.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-06-30, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.271
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (wang_han) on 2026-07-17, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.270
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (wang_han) on 2026-07-16, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.2.266
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (wang_han) on 2026-07-16, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.