@powerhousedao/powerhouse-vetra-packages
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/browser/connect-fm478Tkm.js | AI (source-diff): Bundled rolldown/vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/connect-fm478Tkm.js | AI (source-diff): Standard require/import shims in bundled output, no fetched exec. | ai | |
| source-diff | obfuscated-file:dist/browser/graphql-editor-BViOPvVT.js | AI (source-diff): Bundled GraphQL/CodeMirror editor code. | ai | |
| source-diff | obfuscated-file:dist/node/connect-Dn8dIaUM.mjs | AI (source-diff): Bundled build output mirroring browser variant. | ai | |
| source-diff | net-exec-file:dist/node/connect-Dn8dIaUM.mjs | AI (source-diff): Bundled require/import shims, not real exec. | ai | |
| source-diff | obfuscated-file:dist/node/graphql-editor-Q8X5fIKt.mjs | AI (source-diff): Bundled GraphQL editor code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/node/dist-fA4EItr0.mjs | AI (source-diff): Standard rolldown runtime preamble. | ai | |
| source-diff | obfuscated-file:dist/browser/connect-DtxdWwmH.js | AI (source-diff): Bundled minified output from rolldown build, not true obfuscation. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo package with sparse metadata but legitimate large codebase and provenance. | ai | |
| source-diff | obfuscated-file:dist/node/graphql-editor-CerP5vG3.mjs | AI (source-diff): Bundled graphql-language-service code, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/browser/connect-DtxdWwmH.js | AI (source-diff): Bundler runtime require/import shim, not dropper/loader code. | ai | |
| source-diff | net-exec-file:dist/browser/dist-CXoKspdx.js | AI (source-diff): Rolldown runtime helpers, no actual network+exec malware behavior. | ai | |
| source-diff | obfuscated-file:dist/browser/graphql-editor-B6Qmp_5P.js | AI (source-diff): Bundled graphql editor UI code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/node/connect-DID9HJAK.mjs | AI (source-diff): Bundled build output mirroring browser variant. | ai | |
| source-diff | net-exec-file:dist/node/connect-DID9HJAK.mjs | AI (source-diff): Bundler shim code, not malicious network exec. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 6.2.1 | 0 / 39 | |
| 6.2.0 | 0 / 39 | |
| 6.1.0 | 0 / 39 | |
| 6.0.0 | 0 / 38 |
v6.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.0
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.