← Home

@powerhousedao/vetra

23
Versions
AGPL-3.0-only
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

acaldas.powerhousememo.devryanwolhuterprometheus-phcallme-tfroidliberuum

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/editor-fvDig5Bd.js AI (source-diff): Bundled/minified React output from tsdown build; code is readable and from the Powerhouse monorepo. ai
provenance publisher-changed AI (provenance): Legitimate org transition; memo.dev has strong track record (75 approved, 0 rejected) and SLSA provenance. ai
maintainer-change maintainer-added AI (maintainer-change): Same-org maintainer addition consistent with team growth at powerhouse. ai
source-diff obfuscated-file:dist/editor-D70FYIwV.js AI (source-diff): Standard tsdown/rollup bundle with readable source; long lines from minification, no encoded payloads. ai
dependencies unvetted-dep:@powerhousedao/design-system AI (dependencies): Same-org monorepo dependency pinned to exact version; consistent with coordinated releases across the @powerhousedao ecosystem. ai
dependencies unvetted-dep:@powerhousedao/builder-tools AI (dependencies): Same-org monorepo dependency pinned to exact version; consistent with coordinated releases across the @powerhousedao ecosystem. ai
npm-metadata no-description AI (npm-metadata): Monorepo package with no standalone description; consistent across all @powerhousedao packages in this release. ai
phantom-deps phantom-dep:uuid AI (phantom-deps): uuid is a common utility likely used in config or indirectly; same-org monorepo pattern makes this a stable false positive. ai
phantom-deps phantom-dep:@powerhousedao/connect AI (phantom-deps): Same org scope; monorepo dependency declared for peer/config use, not a phantom dep concern. ai
phantom-deps phantom-dep:@powerhousedao/common AI (phantom-deps): Same org scope; monorepo dependency declared for peer/config use, not a phantom dep concern. ai

Versions (showing 23 of 23)

Version Deps Published
6.1.0 10 / 17
6.0.0 9 / 17
5.3.6 13 / 30
5.3.5 13 / 30
5.3.4 13 / 30
5.3.3 13 / 30
5.3.2 13 / 30
5.3.1 13 / 30
5.3.0 13 / 30
5.1.0 13 / 30
5.0.12 13 / 30
5.0.11 13 / 30
5.0.10 13 / 30
5.0.9 13 / 30
5.0.8 13 / 30
5.0.7 13 / 30
5.0.6 13 / 30
5.0.5 13 / 30
5.0.4 13 / 30
5.0.3 13 / 30
5.0.2 13 / 30
5.0.1 13 / 30
5.0.0 13 / 30

v6.1.0

2 findings
HIGH New obfuscated file: dist/editor-fvDig5Bd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v6.0.0

3 findings
HIGH Publisher changed: acaldas.powerhouse → memo.dev (on 2026-05-21) provenance

This version was published by a different npm account than previous versions on 2026-05-21. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/editor-D70FYIwV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.3.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.