← Home

@pisell/private-materials

pisell前端使用的私有物料

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

wang_hanzsj1037797769zhiwei.wangyaoxiaojialarry_ranhejunxiangfeng.xueah-scjinglin.tan

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff bulk-obfuscated-files:build AI (source-diff): Routine minified webpack build-output dump under build/. ai
source-diff obfuscated-file:lib/components/venueBooking/temp.js AI (source-diff): esbuild/tsdown bundler banner, not true obfuscation; new UI component build output. ai
source-diff obfuscated-file:es/plus/piPayment/sdk/flows/spi/tyro.js AI (source-diff): Babel-transpiled build output, not obfuscation. ai
source-diff obfuscated-file:es/plus/saleDetail/components/Client/ClientSelector.js AI (source-diff): Same babel-compiled artifact pattern. ai
source-diff obfuscated-file:es/plus/piPayment/sdk/providers/spi/tyro/client.js AI (source-diff): Babel/webpack build output, not true obfuscation. ai
source-diff obfuscated-file:es/plus/piPayment/sdk/providers/spi/tyro/flow.js AI (source-diff): Babel/webpack build output, not true obfuscation. ai
source-diff obfuscated-file:es/plus/piPayment/sdk/core/client.js AI (source-diff): Babel/webpack build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/booking/utils/holderAssignmentConfirmModal.js AI (source-diff): Babel-transpiled build output in es/ dist, not true obfuscation. ai
source-diff obfuscated-file:es/components/checkout/components/PaymentResultToast/PaymentResultToastProvider.js AI (source-diff): Babel-transpiled build output in es/ dist, not true obfuscation. ai
source-diff bulk-obfuscated-files:lib AI (source-diff): esbuild-bundled CJS output, standard build artifact. ai
source-diff bulk-obfuscated-files:es AI (source-diff): Bundled build output (babel/regenerator helpers), not true obfuscation. ai
source-diff obfuscated-file:es/components/sharedSecondaryBigSale/SharedSecondaryBigSaleReceiver.js AI (source-diff): Same transpiled-output pattern, not obfuscation. ai
source-diff obfuscated-file:es/plus/saleDetail/actions/index.js AI (source-diff): Babel-transpiled long-line ES output, not real obfuscation. ai
source-diff obfuscated-file:es/plus/pisellReservation/floorMap/floorPlanApi.js AI (source-diff): Babel/regenerator transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:es/plus/pisellReservation/serve/formResourcePage.js AI (source-diff): Babel/regenerator transpiled build output, not true obfuscation. ai
source-diff obfuscated-file-transition:es/components/appointmentBooking/components/Form/index.js AI (source-diff): Babel/father build inlines helper boilerplate past 3000-char threshold; transpiled output not obfuscation. Recurs every release. ai
source-diff obfuscated-file-transition:es/components/appointmentBooking/utils.js AI (source-diff): Babel/father build inlines regeneratorRuntime/helpers past line threshold; transpiled output not obfuscation. Recurs every release. ai
source-diff obfuscated-file:es/plus/saleDetail/components/Voucher/components/DiscountCardHolderModal.js AI (source-diff): Babel-bundled component code, not true obfuscation; no malicious behavior found. ai
source-diff obfuscated-file:es/plus/saleDetail/components/Voucher/DiscountCardHolderContext.js AI (source-diff): Babel-bundled component code, not true obfuscation; no malicious behavior found. ai
source-diff obfuscated-file:es/plus/piPayment/sdk/routes/walletpass/adapter.js AI (source-diff): Babel-transpiled bundle output, not obfuscation. ai
source-diff obfuscated-file:es/plus/piPayment/sdk/routes/eftpos/adapter.js AI (source-diff): Babel-transpiled bundle output, not obfuscation. ai
source-diff obfuscated-file:es/plus/orderList/components/BatchActionBar.js AI (source-diff): Babel-transpiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:es/plus/saleDetail/hooks/useAdjustTimeModal.js AI (source-diff): Babel helper output, standard transpiled bundle artifact. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/modules/deviceConnections/components/ConnectExistingDeviceModal.js AI (source-diff): Babel-transpiled component code, not true obfuscation; matches package's build pipeline. ai
source-diff obfuscated-file:es/plus/salesSdk/bookingEditService/BookingEditHolderField.js AI (source-diff): Babel-transpiled bundle output, not true obfuscation. ai
source-diff obfuscated-file:build/lowcode/render/default/async/view.js AI (source-diff): Bundled webpack chunk, same build artifact as sibling file. ai
source-diff obfuscated-file:build/lowcode/async/view.js AI (source-diff): Bundled webpack chunk containing AWS SDK code, not obfuscation. ai
publish-pattern suspicious-version-number AI (publish-pattern): Long-running internal versioning scheme, not spoofing. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/components/DeviceDetailDrawer/hooks/useDeviceConnections.js AI (source-diff): Babel-compiled long-line output, not true obfuscation; no malicious payload. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/components/DeviceDetailDrawer/components/DeviceConnectionsPanel.js AI (source-diff): Babel-compiled long-line output, not true obfuscation; no malicious payload. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/components/DeviceDetailDrawer/components/ConnectExistingDeviceModal.js AI (source-diff): Babel-compiled long-line output, not true obfuscation; no malicious payload. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/hooks/useDeviceList.js AI (source-diff): Babel-compiled long-line output, not true obfuscation; no malicious payload. ai
source-diff obfuscated-file:build/lowcode/14.js AI (source-diff): Webpack-bundled chunk, not true obfuscation; matches build/lowcode output pattern. ai
phantom-deps phantom-dep:use-sync-external-store AI (phantom-deps): Unused declared dep typical of this large shared-materials package. ai
source-diff obfuscated-file:build/lowcode/render/default/12.js AI (source-diff): Webpack-bundled chunk, not true obfuscation; matches build/lowcode output pattern. ai
source-diff obfuscated-file:es/plus/saleDetail/hooks/useSaleDetailActions.js AI (source-diff): Babel-compiled build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/pay/toC/PaymentMethods/components/MiniProgramWaitingPaymentModal/serve.js AI (source-diff): Babel-transpiled es/ build output, not true obfuscation. ai
source-diff obfuscated-file:es/hooks/useCartProductStockCheck.js AI (source-diff): Babel-transpiled es/ build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/venueBooking/components/Voucher/index.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/scanOrder/components/Menu/index.js AI (source-diff): Babel-transpiled build output (regeneratorRuntime helpers), not true obfuscation. ai
source-diff obfuscated-file:es/components/scanOrder/components/Voucher/index.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/venueBooking/components/Addons/index.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/venueBooking/components/Cart/index.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/venueBooking/components/Checkout/index.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:es/components/venueBooking/components/Content/index.js AI (source-diff): Sample shows readable JSX component source, not obfuscated. ai
source-diff obfuscated-file:es/components/venueBooking/components/VenueSelection/index.js AI (source-diff): Babel-transpiled build output, not true obfuscation. ai
source-diff obfuscated-file:build/lowcode/3.js AI (source-diff): Webpack bundle chunk, minified build output not obfuscation. ai
source-diff obfuscated-file:es/components/checkout/PaymentPlugin.js AI (source-diff): Babel-compiled helper code, standard build output. ai
source-diff obfuscated-file:build/lowcode/render/default/1.js AI (source-diff): Webpack bundle chunk, minified build output not obfuscation. ai
phantom-deps phantom-dep:decimal.js AI (phantom-deps): Same pattern across this org's component packages. ai
phantom-deps phantom-dep:@pisell/icon AI (phantom-deps): Same org scope, config-referenced dependency. ai
phantom-deps phantom-dep:@pisell/utils AI (phantom-deps): Same org scope, config-referenced dependency. ai
phantom-deps phantom-dep:@ant-design/icons AI (phantom-deps): Same pattern across this org's component packages. ai
phantom-deps phantom-dep:@react-spring/web AI (phantom-deps): Same pattern across this org's component packages. ai
phantom-deps phantom-dep:@use-gesture/react AI (phantom-deps): Same pattern across this org's component packages. ai
phantom-deps phantom-dep:antd AI (phantom-deps): Lowcode materials package; deps used via config/schema not direct import. ai
phantom-deps phantom-dep:dayjs AI (phantom-deps): Same pattern across this org's component packages. ai
phantom-deps phantom-dep:ahooks AI (phantom-deps): Same pattern across this org's component packages. ai
phantom-deps phantom-dep:classnames AI (phantom-deps): Same pattern across this org's component packages. ai
source-diff large-new-source-files AI (source-diff): Component library legitimately adds many compiled files per release. ai
source-diff obfuscated-file:es/plus/saasDevice/appPeripheral/hooks/usePeripheralSetupFlow.js AI (source-diff): Babel-transpiled build output, not obfuscation; standard for this lib's es/ dist. ai
source-diff obfuscated-file:es/plus/saasDevice/appPeripheral/services/peripheralDiscoveryService.js AI (source-diff): Babel-transpiled build output, not obfuscation; standard for this lib's es/ dist. ai
bogus-package bogus-package AI (bogus-package): Internal component library naming/README style, established publisher. ai
source-diff obfuscated-file:es/components/booking/components/reloadResourceModal/index.js AI (source-diff): Standard Babel/regenerator compiled output; not malicious obfuscation. Consistent with this package's build pipeline. ai
source-diff obfuscated-file:es/components/booking/info2/cartClientCard/index.js AI (source-diff): Standard Babel/regenerator compiled output; not malicious obfuscation. Consistent with this package's build pipeline. ai
source-diff obfuscated-file:es/components/pay/toC/PaymentMethods/components/MiniProgramWaitingPaymentModal/index.js AI (source-diff): Standard Babel transpiled output with regenerator-runtime; not obfuscation. ai
source-diff obfuscated-file:es/components/scanOrder/components/Content/index.js AI (source-diff): Standard Babel transpiled output with regenerator-runtime; not obfuscation. ai
source-diff obfuscated-file:es/components/scanOrder/components/Check/index.js AI (source-diff): Standard Babel transpiled output with regenerator-runtime; not obfuscation. ai
source-diff obfuscated-file:es/components/scanOrder/components/Cart/index.js AI (source-diff): Standard Babel transpiled output with regenerator-runtime; not obfuscation. ai
source-diff obfuscated-file:lib/plus/salesSdk/adjustTime/components/AdjustTimeActionList.js AI (source-diff): Standard esbuild/Babel CJS bundle output; not malicious obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:es/components/ticketBooking/dialog.js AI (source-diff): Standard Babel transpile output; long lines from inlined helpers, not obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/appPeripheral/components/ConnectExistingDeviceModal.js AI (source-diff): Standard Babel transpile output (regeneratorRuntime, _typeof helpers); not obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/appPeripheral/components/EditDeviceModal.js AI (source-diff): Standard Babel transpile output; not obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/appDevicePlanning/api/index.js AI (source-diff): Standard Babel transpile output; not obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/appDevicePlanning/index.js AI (source-diff): Standard Babel transpile output; not obfuscation. ai
source-diff obfuscated-file:es/components/booking/utils/confirmHolderModal.js AI (source-diff): Standard Babel/regenerator compiled output; long-line minification is expected for this component library. ai
source-diff obfuscated-file:es/components/pay/toB/store/hooks.js AI (source-diff): Same Babel compiled pattern; not obfuscation, just minified build output. ai
source-diff obfuscated-file:es/components/venueBooking/context.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/venueBooking/hooks.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/scanOrder/hooks.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/venueBooking/components/VenueSelection/components/DateNavigator.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/scanOrder/context.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/eftpos/PairModal/index.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/booking/info2/pet/index.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/booking/info2/header/index.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/booking/info2/clientVariant/vertical/index.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/components/booking/info2/client/index.js AI (source-diff): Standard Babel-transpiled React output; regenerator-runtime boilerplate, not obfuscation. ai
source-diff obfuscated-file:es/plus/pisellReservation/components/blockTimeModal/demo.js AI (source-diff): Standard Babel transpile output with regenerator-runtime; not obfuscation. ai
source-diff obfuscated-file:es/plus/salesSdk/hosts/BookingEditHostRenderer.js AI (source-diff): Standard Babel/regenerator transpiled output; not obfuscated malware. ai
source-diff obfuscated-file:es/plus/salesSdk/utils/assignHolderToCartLine.js AI (source-diff): Standard Babel/regenerator transpiled output; not obfuscated malware. ai
source-diff obfuscated-file:es/plus/salesSdk/utils/addProductWithFlowDebounced.js AI (source-diff): Standard Babel/regenerator transpiled output; not obfuscated malware. ai
source-diff obfuscated-file:es/components/pay/toC/PaymentMethods/components/MiniProgramWaitingPaymentModal/3dsPayment.js AI (source-diff): Standard Babel/regenerator-runtime transpiled output; consistent with this package's compiled React component library pattern. ai
source-diff obfuscated-file:es/plus/pisellReservation/data/bookingCalendarMoveIntegration.js AI (source-diff): Standard Babel/regenerator-runtime transpiled output; consistent with this package's compiled React component library pattern. ai
source-diff obfuscated-file:es/plus/saleDetail/components/CartItems/index.js AI (source-diff): Babel-transpiled output, not obfuscation; stable pattern for this component library. ai
source-diff obfuscated-file:es/plus/salesSdk/demo/components/DemoTabDetail.js AI (source-diff): Babel-transpiled output with standard helpers; not obfuscation. ai
source-diff obfuscated-file:es/plus/saleDetail/components/SaleOverview/index.js AI (source-diff): Babel-transpiled output with standard helpers; not obfuscation. ai
source-diff obfuscated-file:es/plus/saleDetail/components/ButtonActions/index.js AI (source-diff): Babel-transpiled output with standard helpers; not obfuscation. ai
source-diff obfuscated-file:es/plus/salesSdk/demo/components/DemoStepRunner.js AI (source-diff): Babel-transpiled output with standard helpers; not obfuscation. ai
source-diff obfuscated-file:es/plus/salesSdk/demo/components/buildSteps.js AI (source-diff): Babel-transpiled output with standard helpers, not obfuscation. ai
source-diff obfuscated-file:es/plus/salesSdk/demo/components/CartPanel.js AI (source-diff): Babel-transpiled output with regenerator-runtime helpers, not obfuscation. ai
source-diff obfuscated-file:es/plus/salesSdk/utils/buildDefaultLoadProductsParams.js AI (source-diff): Babel-transpiled output with regenerator-runtime helpers, not obfuscation. ai
source-diff obfuscated-file:es/plus/salesSdk/bookingEditService/BookingEditServiceDrawer.js AI (source-diff): Babel-transpiled output with regenerator-runtime helpers, not obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/components/AddDeviceModal/index.js AI (source-diff): Standard Babel-compiled React component output; not intentional obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/deviceProfile/serve.js AI (source-diff): Standard Babel-compiled output consistent with rest of package build pipeline. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/serve.js AI (source-diff): Standard Babel-compiled output consistent with rest of package build pipeline. ai
source-diff obfuscated-file:lib/plus/saasDevice/devicePlanning/components/DeviceDetailDrawer/index.js AI (source-diff): Standard esbuild CJS bundle output with clear source comments; not intentional obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/deviceProfile/index.js AI (source-diff): Standard Babel-compiled React component output; not intentional obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/deviceProfile/components/ProfileSetting/index.js AI (source-diff): Standard Babel-compiled React component output; not intentional obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/deviceProfile/components/CreateProfileModal/index.js AI (source-diff): Standard Babel-compiled React component output; not intentional obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/index.js AI (source-diff): Standard Babel-compiled React component output; not intentional obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/components/WorkAreaModal/index.js AI (source-diff): Standard Babel-compiled React component output; not intentional obfuscation. ai
source-diff obfuscated-file:es/plus/saasDevice/devicePlanning/components/EditDeviceModal/index.js AI (source-diff): Standard Babel-compiled React component output; not intentional obfuscation. ai
source-diff obfuscated-file:es/components/pay/toC/PaymentMethods/StripePay/Stripe/StripeSDK/DynamicSDK.js AI (source-diff): Standard Babel-transpiled output for Stripe SDK loader; minified helpers are expected build artifacts, not obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): react-zoom-pan-pinch is a legitimate, widely-used React library; no risk signal. ai
phantom-deps phantom-dep:react-zoom-pan-pinch AI (phantom-deps): Declared as runtime dep; phantom-dep heuristic fires on config-only references, stable FP for this package. ai
provenance missing-githead AI (provenance): High-volume package with frequent releases; missing gitHead reflects CI change, not malicious intent. ai
phantom-deps phantom-dep:@dnd-kit/core AI (phantom-deps): Declared dependency used via re-exports; stable pattern for this component library. ai
phantom-deps phantom-dep:@pisell/date-picker AI (phantom-deps): Monorepo internal dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@dnd-kit/utilities AI (phantom-deps): Declared dependency used via re-exports; stable pattern for this component library. ai
phantom-deps phantom-dep:@dnd-kit/sortable AI (phantom-deps): Declared dependency used via re-exports; stable pattern for this component library. ai
semgrep semgrep:new-function-constructor AI (semgrep): Used in a rule/expression evaluator with comment noting it replaces eval; not exfiltration. ai
phantom-deps phantom-dep:rc-virtual-list AI (phantom-deps): Declared runtime dep in a component library; likely re-exported or used indirectly. ai
phantom-deps phantom-dep:styled-components AI (phantom-deps): Declared runtime dep in a component library; likely re-exported or used indirectly. ai
phantom-deps phantom-dep:@dnd-kit/modifiers AI (phantom-deps): Declared runtime dep in a component library; likely re-exported or used indirectly. ai
phantom-deps phantom-dep:react-resizable AI (phantom-deps): Declared runtime dep in a component library; likely re-exported or used indirectly. ai
phantom-deps phantom-dep:react-infinite-scroll-component AI (phantom-deps): Declared runtime dep in a component library; likely re-exported or used indirectly. ai

Versions (showing 51 of 670)

View all versions
Version Deps Published
6.12.75 20 / 28
6.12.71 20 / 28
6.12.70 20 / 28
6.12.69 20 / 28
6.12.68 20 / 28
6.12.65 20 / 28
6.12.64 20 / 28
6.12.63 20 / 28
6.12.60 20 / 28
6.12.58 20 / 28
6.12.57 20 / 28
6.12.55 20 / 28
6.12.54 20 / 28
6.12.53 20 / 28
6.12.52 20 / 28
6.12.50 20 / 28
6.12.49 20 / 28
6.12.48 20 / 28
6.12.46 20 / 28
6.12.43 20 / 28
6.12.42 20 / 28
6.12.40 20 / 28
6.12.39 20 / 28
6.12.38 20 / 28
6.12.37 20 / 28
6.12.35 20 / 28
6.12.34 20 / 28
6.12.31 20 / 28
6.12.29 20 / 28
6.12.28 20 / 28
6.12.27 20 / 28
6.12.25 20 / 28
6.12.21 20 / 28
6.12.20 20 / 28
6.12.18 20 / 28
6.12.17 20 / 28
6.12.16 20 / 28
6.12.14 20 / 28
6.12.13 20 / 28
6.12.12 20 / 28
6.12.11 20 / 28
6.12.10 20 / 28
6.12.9 20 / 28
6.12.8 20 / 28
6.12.7 20 / 28
6.12.6 20 / 28
6.12.5 20 / 28
6.12.4 20 / 28
6.12.2 20 / 28
6.12.1 20 / 28
6.11.413 22 / 28

v6.12.75

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

INFO Publisher changed: jinglin.tan → zhiwei.wang (on 2026-07-21, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-21, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.71

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xiangfeng.xue → jinglin.tan (on 2026-07-18, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (xiangfeng.xue) on 2026-07-18, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.70

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zhiwei.wang → xiangfeng.xue (on 2026-07-18, known maintainer) provenance

This version was published by a different npm account (xiangfeng.xue) than the most recent previously approved version (zhiwei.wang) on 2026-07-18, but xiangfeng.xue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.69

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

v6.12.68

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

INFO Publisher changed: wang_han → zhiwei.wang (on 2026-07-17, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (wang_han) on 2026-07-17, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.65

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.64

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: wang_han → ah-sc (on 2026-07-16, known maintainer) provenance

This version was published by a different npm account (ah-sc) than the most recent previously approved version (wang_han) on 2026-07-16, but ah-sc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.63

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → xiangfeng.xue (on 2026-07-15, known maintainer) provenance

This version was published by a different npm account (xiangfeng.xue) than the most recent previously approved version (jinglin.tan) on 2026-07-15, but xiangfeng.xue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.60

5 findings
HIGH New obfuscated file: es/plus/piPayment/sdk/core/client.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/piPayment/sdk/providers/spi/tyro/client.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/piPayment/sdk/providers/spi/tyro/flow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saleDetail/actions/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.58

5 findings
HIGH New obfuscated file: es/plus/saleDetail/actions/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/sharedSecondaryBigSale/SharedSecondaryBigSaleReceiver.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/piPayment/sdk/flows/spi/tyro.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → zhiwei.wang (on 2026-07-15, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-15, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.57

3 findings
HIGH New obfuscated file: es/plus/saleDetail/actions/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/sharedSecondaryBigSale/SharedSecondaryBigSaleReceiver.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.55

4 findings
HIGH New obfuscated file: es/plus/saleDetail/actions/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/sharedSecondaryBigSale/SharedSecondaryBigSaleReceiver.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → zhiwei.wang (on 2026-07-14, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-14, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.53

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: zhiwei.wang → jinglin.tan (on 2026-07-13, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zhiwei.wang) on 2026-07-13, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.52

4 findings
HIGH New obfuscated file: es/plus/saleDetail/actions/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/components/sharedSecondaryBigSale/SharedSecondaryBigSaleReceiver.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: jinglin.tan → zhiwei.wang (on 2026-07-14, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-14, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.50

4 findings
HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/DiscountCardHolderContext.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/components/DiscountCardHolderModal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

v6.12.49

4 findings
HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/DiscountCardHolderContext.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/components/DiscountCardHolderModal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

v6.12.48

4 findings
HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/DiscountCardHolderContext.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/components/DiscountCardHolderModal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

v6.12.46

4 findings
HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/DiscountCardHolderContext.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saleDetail/components/Voucher/components/DiscountCardHolderModal.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

v6.12.43

5 findings
HIGH New obfuscated file: es/plus/piPayment/sdk/routes/eftpos/adapter.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/piPayment/sdk/routes/walletpass/adapter.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

INFO Publisher changed: ah-sc → zhiwei.wang (on 2026-07-11, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (ah-sc) on 2026-07-11, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.42

5 findings
HIGH New obfuscated file: es/plus/piPayment/sdk/routes/eftpos/adapter.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/piPayment/sdk/routes/walletpass/adapter.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: xiangfeng.xue.

INFO Publisher changed: zhiwei.wang → xiangfeng.xue (on 2026-07-10, known maintainer) provenance

This version was published by a different npm account (xiangfeng.xue) than the most recent previously approved version (zhiwei.wang) on 2026-07-10, but xiangfeng.xue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.40

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: xiangfeng.xue → zhiwei.wang (on 2026-07-10, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (xiangfeng.xue) on 2026-07-10, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.38

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

v6.12.37

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

INFO Publisher changed: jinglin.tan → zhiwei.wang (on 2026-07-09, known maintainer) provenance

This version was published by a different npm account (zhiwei.wang) than the most recent previously approved version (jinglin.tan) on 2026-07-09, but zhiwei.wang is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.35

4 findings
HIGH New obfuscated file: es/plus/salesSdk/bookingEditService/BookingEditHolderField.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.

INFO Publisher changed: xiangfeng.xue → jinglin.tan (on 2026-07-08, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (xiangfeng.xue) on 2026-07-08, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.34

3 findings
HIGH New obfuscated file: es/plus/salesSdk/bookingEditService/BookingEditHolderField.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zhiwei.wang.

v6.12.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.29

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zsj1037797769.

INFO Publisher changed: jinglin.tan → zsj1037797769 (on 2026-07-07, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (jinglin.tan) on 2026-07-07, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.28

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zsj1037797769.

INFO Publisher changed: xiangfeng.xue → zsj1037797769 (on 2026-07-07, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (xiangfeng.xue) on 2026-07-07, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.27

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: xiangfeng.xue.

INFO Publisher changed: zsj1037797769 → xiangfeng.xue (on 2026-07-06, known maintainer) provenance

This version was published by a different npm account (xiangfeng.xue) than the most recent previously approved version (zsj1037797769) on 2026-07-06, but xiangfeng.xue is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.25

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zsj1037797769.

v6.12.21

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.

v6.12.20

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.

v6.12.18

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.

v6.12.17

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.

v6.12.16

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.

INFO Publisher changed: zsj1037797769 → jinglin.tan (on 2026-07-01, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (zsj1037797769) on 2026-07-01, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.14

2 findings
HIGH New obfuscated file: es/plus/salesSdk/bookingEditService/BookingEditHolderField.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.13

2 findings
HIGH New obfuscated file: es/plus/salesSdk/bookingEditService/BookingEditHolderField.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.12

5 findings
HIGH New obfuscated file: es/plus/salesSdk/bookingEditService/BookingEditHolderField.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/services/peripheralDiscoveryService.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/hooks/usePeripheralSetupFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ah-sc → zsj1037797769 (on 2026-06-30, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (ah-sc) on 2026-06-30, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.11

3 findings
HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/services/peripheralDiscoveryService.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/hooks/usePeripheralSetupFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.12.10

4 findings
HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/services/peripheralDiscoveryService.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/hooks/usePeripheralSetupFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ah-sc → jinglin.tan (on 2026-06-29, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (ah-sc) on 2026-06-29, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.9

4 findings
HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/services/peripheralDiscoveryService.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/hooks/usePeripheralSetupFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ah-sc → zsj1037797769 (on 2026-06-29, known maintainer) provenance

This version was published by a different npm account (zsj1037797769) than the most recent previously approved version (ah-sc) on 2026-06-29, but zsj1037797769 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.12.8

4 findings
HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/services/peripheralDiscoveryService.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: es/plus/saasDevice/appPeripheral/hooks/usePeripheralSetupFlow.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: ah-sc → jinglin.tan (on 2026-06-27, known maintainer) provenance

This version was published by a different npm account (jinglin.tan) than the most recent previously approved version (ah-sc) on 2026-06-27, but jinglin.tan is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v6.11.413

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: jinglin.tan.