← Home

@pkistudio/asn1instancebuilder

14
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

pkistudio

Keywords

asn1derpkix509pkistudio

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/app-shell/assets/main-C6imgx_h.js AI (source-diff): Vite-bundled app shell output; minification is expected for this package's build:app step. ai
source-diff obfuscated-file:dist/app-shell/assets/main-BvCYqbuh.js AI (source-diff): Vite build output; minified hashed bundles are expected for this package's app-shell build step. ai
source-diff obfuscated-file:dist/app-shell/assets/viewer-BRHDy45Z.js AI (source-diff): Standard Vite minified bundle output; content is OID registry data consistent with ASN.1/PKI tooling. ai
source-diff obfuscated-file:dist/app-shell/assets/main-CGl_rViF.js AI (source-diff): Standard Vite minified bundle output; build:app script in package.json targets this exact output directory. ai
source-diff obfuscated-file:dist/app-shell/assets/main-BX1VGvMS.js AI (source-diff): Vite build output with hashed filenames; content is readable ASN.1/PKI library code, not malicious obfuscation. ai
source-diff obfuscated-file:dist/app-shell/assets/main-Bd4i9vmC.js AI (source-diff): Vite-bundled app-shell output; hashed filename and readable PKI logic confirm legitimate minification. ai
source-diff obfuscated-file:dist/app-shell/assets/main-Cci3gyCM.js AI (source-diff): Vite-minified app-shell bundle with hashed filename; content is readable PKI/ASN.1 logic, not malicious obfuscation. ai
source-diff obfuscated-file:dist/app-shell/assets/main-3FaXukHj.js AI (source-diff): Standard Vite minified bundle output; content is readable ASN.1/PKI logic, not malicious obfuscation. ai
source-diff obfuscated-file:dist/app-shell/assets/main-BGZlNPER.js AI (source-diff): Vite-minified app-shell bundle; content is readable ASN.1/DER utility code, not malicious obfuscation. ai
publish-pattern rapid-publish AI (publish-pattern): Automated CI/CD pipeline with SLSA provenance; rapid successive publishes are expected in this workflow. ai
source-diff obfuscated-file:dist/app-shell/assets/main-DtQxPYKD.js AI (source-diff): Standard Vite minified build output; content is readable ASN.1/PKI logic, not malicious obfuscation. ai
source-diff obfuscated-file:dist/app-shell/assets/viewer-0XYZEovH.js AI (source-diff): Standard Vite minified bundle; content is OID table data for PKI viewer, not obfuscation. ai
source-diff obfuscated-file:dist/app-shell/assets/main-DUgoSoAV.js AI (source-diff): Standard Vite minified bundle; content is domain-appropriate ASN.1/DER logic, not obfuscation. ai
source-diff obfuscated-file:dist/app-shell/assets/main-D1NyQkgU.js AI (source-diff): Standard Vite minified bundle with readable PKI/ASN.1 logic; hashed filename is normal Vite output. ai
source-diff obfuscated-file:dist/app-shell/assets/viewer-ChUP4p43.js AI (source-diff): Standard Vite minified bundle containing OID registry data; consistent with ASN.1 viewer app shell. ai

Versions (showing 14 of 14)

Version Deps Published
0.1.13 1 / 4
0.1.12 1 / 4
0.1.11 1 / 4
0.1.10 1 / 4
0.1.9 1 / 4
0.1.8 1 / 4
0.1.7 1 / 4
0.1.6 1 / 4
0.1.5 1 / 4
0.1.4 1 / 4
0.1.3 1 / 4
0.1.2 1 / 4
0.1.1 1 / 4
0.1.0 1 / 4

v0.1.13

2 findings
HIGH New obfuscated file: dist/app-shell/assets/main-BGZlNPER.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.12

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-BX1VGvMS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-ChUP4p43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.11

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-D1NyQkgU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-ChUP4p43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.10

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-Bd4i9vmC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-ChUP4p43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.9

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-Cci3gyCM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-ChUP4p43.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.8

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-DtQxPYKD.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-0XYZEovH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.7

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-3FaXukHj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-0XYZEovH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.6

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-DUgoSoAV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-0XYZEovH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.5

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-BvCYqbuh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-0XYZEovH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.4

3 findings
HIGH New obfuscated file: dist/app-shell/assets/main-CGl_rViF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/app-shell/assets/viewer-BRHDy45Z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.3

2 findings
HIGH New obfuscated file: dist/app-shell/assets/main-C6imgx_h.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.