← Home

@powerhousedao/powerhouse-vetra-packages

4
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

acaldas.powerhousememo.devryanwolhuterprometheus-phph-thegoldenmulecallme-tfroidliberuum

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/browser/connect-fm478Tkm.js AI (source-diff): Bundled rolldown/vite output, not true obfuscation. ai
source-diff net-exec-file:dist/browser/connect-fm478Tkm.js AI (source-diff): Standard require/import shims in bundled output, no fetched exec. ai
source-diff obfuscated-file:dist/browser/graphql-editor-BViOPvVT.js AI (source-diff): Bundled GraphQL/CodeMirror editor code. ai
source-diff obfuscated-file:dist/node/connect-Dn8dIaUM.mjs AI (source-diff): Bundled build output mirroring browser variant. ai
source-diff net-exec-file:dist/node/connect-Dn8dIaUM.mjs AI (source-diff): Bundled require/import shims, not real exec. ai
source-diff obfuscated-file:dist/node/graphql-editor-Q8X5fIKt.mjs AI (source-diff): Bundled GraphQL editor code, minified not obfuscated. ai
source-diff net-exec-file:dist/node/dist-fA4EItr0.mjs AI (source-diff): Standard rolldown runtime preamble. ai
source-diff obfuscated-file:dist/browser/connect-DtxdWwmH.js AI (source-diff): Bundled minified output from rolldown build, not true obfuscation. ai
bogus-package bogus-package AI (bogus-package): Monorepo package with sparse metadata but legitimate large codebase and provenance. ai
source-diff obfuscated-file:dist/node/graphql-editor-CerP5vG3.mjs AI (source-diff): Bundled graphql-language-service code, not obfuscated malware. ai
source-diff net-exec-file:dist/browser/connect-DtxdWwmH.js AI (source-diff): Bundler runtime require/import shim, not dropper/loader code. ai
source-diff net-exec-file:dist/browser/dist-CXoKspdx.js AI (source-diff): Rolldown runtime helpers, no actual network+exec malware behavior. ai
source-diff obfuscated-file:dist/browser/graphql-editor-B6Qmp_5P.js AI (source-diff): Bundled graphql editor UI code, minified not obfuscated. ai
source-diff obfuscated-file:dist/node/connect-DID9HJAK.mjs AI (source-diff): Bundled build output mirroring browser variant. ai
source-diff net-exec-file:dist/node/connect-DID9HJAK.mjs AI (source-diff): Bundler shim code, not malicious network exec. ai

Versions (showing 4 of 4)

Version Deps Published
6.2.1 0 / 39
6.2.0 0 / 39
6.1.0 0 / 39
6.0.0 0 / 38

v6.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.2.0

9 findings
HIGH New obfuscated file: dist/browser/connect-DtxdWwmH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/browser/connect-DtxdWwmH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/browser/dist-CXoKspdx.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/browser/graphql-editor-B6Qmp_5P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/connect-DID9HJAK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/node/connect-DID9HJAK.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/node/dist-fA4EItr0.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/node/graphql-editor-CerP5vG3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.