@qwen-code/sdk
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | source-size-tripled | AI (source-diff): Growth from bundling CLI + vendored ripgrep binaries, documented in package.json files/scripts. | ai | |
| npm-metadata | url-dep:@qwen-code/acp-bridge | AI (npm-metadata): Monorepo devDependency via file: path, standard for sibling packages. | ai | |
| source-diff | obfuscated-file:dist/daemon/index.cjs | AI (source-diff): Minified esbuild bundle output, not true obfuscation; matches package's CLI/daemon build. | ai | |
| source-diff | obfuscated-file:dist/daemon/transports.cjs | AI (source-diff): Minified esbuild bundle output for SSE transport code, benign. | ai | |
| source-diff | net-exec-file:dist/cli/chunks/chunk-2UUAIFQO.js | AI (source-diff): Bundled third-party lib (ajv) code, not a dropper/loader. | ai | |
| phantom-deps | phantom-dep:tiktoken | AI (phantom-deps): Used indirectly via config/tokenizer setup, not a real issue. | ai | |
| source-diff | obfuscated-file:dist/cli/cli.js | AI (source-diff): esbuild bundle boilerplate, not true obfuscation; matches official qwen-code CLI. | ai | |
| source-diff | net-exec-file:dist/cli/cli.js | AI (source-diff): Bundled CLI network+exec is expected functionality for a code-assistant CLI tool. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Binaries are ripgrep (well-known OSS) and tree-sitter WASM; consistent with code-assistant CLI purpose. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 0.1.8 | 2 / 10 | |
| 0.1.7 | 2 / 9 | |
| 0.1.5 | 2 / 9 | |
| 0.1.4 | 2 / 9 | |
| 0.1.3 | 3 / 9 | |
| 0.1.2 | 3 / 9 | |
| 0.1.1 | 3 / 9 | |
| 0.1.0 | 1 / 10 |
v0.1.8
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (yiliang114) than the most recent previously approved version (tanzhenxin) on 2026-07-14, but yiliang114 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 20MB bundled CLI with network+exec patterns added by new publisher; high-risk pattern for this package.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tanzhenxin) than the most recent previously approved version (ranpox) on 2026-02-18, but tanzhenxin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.4
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 20MB bundled CLI with network+exec patterns added by new publisher; high-risk pattern for this package.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tanzhenxin) than the most recent previously approved version (ranpox) on 2026-01-27, but tanzhenxin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 20MB bundled CLI with network+exec patterns added by new publisher; high-risk pattern for this package.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tanzhenxin) than the most recent previously approved version (ranpox) on 2026-01-13, but tanzhenxin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 20MB bundled CLI with network+exec patterns added by new publisher; high-risk pattern for this package.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tanzhenxin) than the most recent previously approved version (ranpox) on 2026-01-12, but tanzhenxin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.1.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Reject — re-review on republish] (prior reject: AI (source-diff): 20MB bundled CLI with network+exec patterns added by new publisher; high-risk pattern for this package.) Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tanzhenxin) than the most recent previously approved version (ranpox) on 2025-12-29, but tanzhenxin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.