@raystack/frontier
A js library for frontier
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@raystack/apsara-v1 | AI (dependencies): Same-org sibling package (Raystack's own apsara UI lib), aliased as pre-release. | ai | |
| source-diff | obfuscated-file:api-client/dist/index.d.ts | AI (source-diff): Generated API client type definitions; long lines are from codegen, not obfuscation. | ai | |
| source-diff | obfuscated-file:react/dist/client.js | AI (source-diff): Standard tsup/esbuild bundle output; long lines are minified but not obfuscated. Stable pattern for this package. | ai | |
| source-diff | net-exec-file:react/dist/client.mjs | AI (source-diff): Same as CJS counterpart; ESM bundle with identical benign patterns. | ai | |
| source-diff | net-exec-file:react/dist/client.js | AI (source-diff): Network calls are React/axios SDK usage; dynamic code execution is tsup __commonJS wrapper. No dropper pattern present. | ai | |
| source-diff | obfuscated-file:react/dist/client.mjs | AI (source-diff): ESM counterpart of the same tsup bundle; same reasoning applies. | ai | |
| phantom-deps | phantom-dep:@raystack/proton | AI (phantom-deps): Same-org scoped dep; transitive usage in library is expected. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Established library; config-referenced transitive dep is normal. | ai | |
| phantom-deps | phantom-dep:@connectrpc/connect-web | AI (phantom-deps): Established library; config-referenced transitive dep is normal. | ai | |
| phantom-deps | phantom-dep:@connectrpc/connect-query | AI (phantom-deps): Established library; config-referenced transitive dep is normal. | ai | |
| source-diff | obfuscated-file:admin/dist/index.js | AI (source-diff): Standard esbuild/tsup bundle output; long lines are minified but not obfuscated. Stable pattern for this package. | ai | |
| source-diff | net-exec-file:admin/dist/index.mjs | AI (source-diff): Same rationale as CJS counterpart; standard bundled UI code. | ai | |
| source-diff | obfuscated-file:admin/dist/index.mjs | AI (source-diff): Same tsup ESM bundle; long lines are minified output, not obfuscation. | ai | |
| source-diff | net-exec-file:admin/dist/index.js | AI (source-diff): Network calls and dynamic requires are part of the React UI bundle, not dropper behavior. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): 231 versions in registry; publisher has 4 approved packages; dormancy likely reflects org release cadence, not takeover. | ai | |
| dependencies | unvetted-dep:@raystack/proton | AI (dependencies): Internal org protobuf package pinned to a specific commit hash; consistent with @raystack ecosystem pattern. | ai | |
| provenance | no-provenance | AI (provenance): Established @raystack org package; provenance not used across their release history. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @connectrpc/connect is a canonical Buf/ConnectRPC library, consistent with existing connect-query/connect-web deps already in the package. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): axios is a declared runtime dependency in package.json; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 51 of 183)
| Version | Deps | Published |
|---|---|---|
| 0.104.1 | 20 / 29 | |
| 0.103.2 | 20 / 29 | |
| 0.103.1 | 20 / 29 | |
| 0.102.0 | 20 / 29 | |
| 0.101.0 | 20 / 29 | |
| 0.99.0 | 20 / 29 | |
| 0.96.0 | 20 / 29 | |
| 0.95.1 | 19 / 32 | |
| 0.95.0 | 19 / 32 | |
| 0.93.1 | 19 / 32 | |
| 0.92.1 | 19 / 32 | |
| 0.89.1 | 19 / 26 | |
| 0.81.0 | 19 / 27 | |
| 0.79.0 | 18 / 26 | |
| 0.78.2 | 18 / 26 | |
| 0.78.1 | 18 / 26 | |
| 0.78.0 | 18 / 26 | |
| 0.71.0 | 17 / 26 | |
| 0.70.1 | 13 / 26 | |
| 0.70.0 | 13 / 26 | |
| 0.69.0 | 13 / 26 | |
| 0.68.0 | 13 / 26 | |
| 0.67.0 | 13 / 26 | |
| 0.66.0 | 13 / 26 | |
| 0.65.0 | 13 / 26 | |
| 0.64.0 | 13 / 26 | |
| 0.63.0 | 15 / 26 | |
| 0.62.0 | 15 / 26 | |
| 0.61.0 | 15 / 26 | |
| 0.60.0 | 15 / 26 | |
| 0.59.0 | 15 / 26 | |
| 0.58.3 | 15 / 26 | |
| 0.58.2 | 15 / 26 | |
| 0.58.1 | 15 / 26 | |
| 0.58.0 | 15 / 26 | |
| 0.57.0 | 15 / 26 | |
| 0.56.0 | 15 / 26 | |
| 0.55.0 | 15 / 26 | |
| 0.54.0 | 15 / 26 | |
| 0.53.0 | 15 / 26 | |
| 0.52.0 | 15 / 26 | |
| 0.51.0 | 15 / 26 | |
| 0.50.0 | 15 / 26 | |
| 0.49.0 | 15 / 26 | |
| 0.48.1 | 15 / 26 | |
| 0.48.0 | 15 / 26 | |
| 0.47.0 | 15 / 26 | |
| 0.46.0 | 15 / 26 | |
| 0.45.0 | 15 / 26 | |
| 0.44.2 | 15 / 26 | |
| 0.44.1 | 15 / 26 |
v0.101.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.61.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.59.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.58.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.57.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.56.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.55.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.54.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.53.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.52.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.51.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.50.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.49.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.48.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.