@pkistudio/asn1instancebuilder
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/app-shell/assets/main-C6imgx_h.js | AI (source-diff): Vite-bundled app shell output; minification is expected for this package's build:app step. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-BvCYqbuh.js | AI (source-diff): Vite build output; minified hashed bundles are expected for this package's app-shell build step. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/viewer-BRHDy45Z.js | AI (source-diff): Standard Vite minified bundle output; content is OID registry data consistent with ASN.1/PKI tooling. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-CGl_rViF.js | AI (source-diff): Standard Vite minified bundle output; build:app script in package.json targets this exact output directory. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-BX1VGvMS.js | AI (source-diff): Vite build output with hashed filenames; content is readable ASN.1/PKI library code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-Bd4i9vmC.js | AI (source-diff): Vite-bundled app-shell output; hashed filename and readable PKI logic confirm legitimate minification. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-Cci3gyCM.js | AI (source-diff): Vite-minified app-shell bundle with hashed filename; content is readable PKI/ASN.1 logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-3FaXukHj.js | AI (source-diff): Standard Vite minified bundle output; content is readable ASN.1/PKI logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-BGZlNPER.js | AI (source-diff): Vite-minified app-shell bundle; content is readable ASN.1/DER utility code, not malicious obfuscation. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Automated CI/CD pipeline with SLSA provenance; rapid successive publishes are expected in this workflow. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-DtQxPYKD.js | AI (source-diff): Standard Vite minified build output; content is readable ASN.1/PKI logic, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/viewer-0XYZEovH.js | AI (source-diff): Standard Vite minified bundle; content is OID table data for PKI viewer, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-DUgoSoAV.js | AI (source-diff): Standard Vite minified bundle; content is domain-appropriate ASN.1/DER logic, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/main-D1NyQkgU.js | AI (source-diff): Standard Vite minified bundle with readable PKI/ASN.1 logic; hashed filename is normal Vite output. | ai | |
| source-diff | obfuscated-file:dist/app-shell/assets/viewer-ChUP4p43.js | AI (source-diff): Standard Vite minified bundle containing OID registry data; consistent with ASN.1 viewer app shell. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 0.1.13 | 1 / 4 | |
| 0.1.12 | 1 / 4 | |
| 0.1.11 | 1 / 4 | |
| 0.1.10 | 1 / 4 | |
| 0.1.9 | 1 / 4 | |
| 0.1.8 | 1 / 4 | |
| 0.1.7 | 1 / 4 | |
| 0.1.6 | 1 / 4 | |
| 0.1.5 | 1 / 4 | |
| 0.1.4 | 1 / 4 | |
| 0.1.3 | 1 / 4 | |
| 0.1.2 | 1 / 4 | |
| 0.1.1 | 1 / 4 | |
| 0.1.0 | 1 / 4 |
v0.1.13
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.12
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.11
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.9
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.6
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.