← Home

@react-native-community/netinfo

React Native Network Info API for iOS & Android

100
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mattoakesbrentvatnemikehardy

Keywords

react-nativereact nativenetinfonetworkingnetwork info

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:lib/module/internal/nativeModule.web.js AI (source-diff): File is standard Babel-compiled ESM output from @react-native-community/bob build tool. Long lines are minified bundle output, not obfuscation. Content is benign network-info logic. ai
source-diff obfuscated-file:lib/commonjs/internal/nativeModule.web.js AI (source-diff): File is standard Babel-compiled CommonJS output from @react-native-community/bob build tool. Long lines are minified bundle output, not obfuscation. Content is benign network-info logic. ai
source-diff obfuscated-file:lib/commonjs/internal/state.js AI (source-diff): File is standard Babel/bob-compiled CommonJS output from TypeScript source; long lines are a Babel artifact, not obfuscation. Stable for this package's build pipeline. ai
source-diff obfuscated-file:lib/module/__tests__/isConnected.js AI (source-diff): Babel-transpiled ES module build artifact from bob build. Content is legitimate Jest test code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/module/index.js AI (source-diff): Babel-transpiled ES module build artifact from bob build. Content is legitimate network info event listener code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/commonjs/__tests__/eventListenerCallbacks.js AI (source-diff): Babel-transpiled build artifact generated by @react-native-community/bob. Long lines are minified test code, not obfuscation. Stable pattern for this package. ai
source-diff obfuscated-file:lib/commonjs/index.js AI (source-diff): Babel-transpiled CommonJS build artifact from bob build. Content is legitimate network info event listener code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/commonjs/__tests__/isConnected.js AI (source-diff): Babel-transpiled build artifact generated by @react-native-community/bob. Long lines are minified test code, not obfuscation. Stable pattern for this package. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance by years; published by established react-native-community-bot with clean track record. ai
source-diff obfuscated-file:lib/module/__tests__/eventListenerCallbacks.js AI (source-diff): Babel-transpiled ES module build artifact from bob build. Content is legitimate Jest test code. Stable pattern for this package. ai
provenance publisher-changed AI (provenance): Transition from react-native-community-bot to GitHub Actions reflects CI/CD migration, not account compromise. SLSA attestation confirms integrity. Stable for this package. ai
maintainer-change maintainer-added AI (maintainer-change): brentvatne and mikehardy are well-known React Native community contributors. Addition is a legitimate governance change, not a takeover. ai
maintainer-change maintainer-removed AI (maintainer-change): react-native-community-bot was an automated account; its removal alongside addition of real maintainers is a legitimate transition. ai
source-diff large-new-source-files AI (source-diff): Diff is against v4.7.0; this is v12.0.1 — a major version jump. Large number of new files is expected for such a significant version increment. ai
semgrep semgrep:toplevel-fetch AI (semgrep): fetch() in internetReachability.js is core functionality — the library checks internet reachability by making HTTP requests. This is expected and documented behavior, not exfiltration. ai

Versions (showing 100 of 148)

Version Deps Published
12.0.1 0 / 44
12.0.0 0 / 44
11.5.2 0 / 44
11.5.1 0 / 44
11.5.0 0 / 44
11.4.1 0 / 44
11.4.0 0 / 44
11.3.3 0 / 44
11.3.2 0 / 44
11.3.1 0 / 44
11.3.0 0 / 44
11.2.1 0 / 44
11.2.0 0 / 44
11.1.1 0 / 44
11.1.0 0 / 44
11.0.1 0 / 44
11.0.0 0 / 44
10.0.0 0 / 44
9.5.0 0 / 44
9.4.2 0 / 44
9.4.1 0 / 44
9.4.0 0 / 44
9.3.11 0 / 44
9.3.10 0 / 44
9.3.9 0 / 44
9.3.8 0 / 44
9.3.7 0 / 44
9.3.6 0 / 44
9.3.5 0 / 44
9.3.4 0 / 44
9.3.3 0 / 44
9.3.2 0 / 44
9.3.1 0 / 44
9.3.0 0 / 44
9.2.0 0 / 44
9.1.0 0 / 44
9.0.0 0 / 44
8.3.1 0 / 44
8.3.0 0 / 44
8.2.0 0 / 44
8.1.0 0 / 44
8.0.0 0 / 44
7.1.12 0 / 44
7.1.11 0 / 44
7.1.10 0 / 44
7.1.9 0 / 44
7.1.8 0 / 44
7.1.7 0 / 44
7.1.6 0 / 44
7.1.5 0 / 44
7.1.4 0 / 44
7.1.3 0 / 44
7.1.2 0 / 44
7.1.1 0 / 44
7.1.0 0 / 44
7.0.0 0 / 44
6.2.1 0 / 44
6.2.0 0 / 44
6.1.1 0 / 44
6.1.0 0 / 44
6.0.6 0 / 44
6.0.5 0 / 43
6.0.4 0 / 43
6.0.3 0 / 43
6.0.2 0 / 39
6.0.1 0 / 39
6.0.0 0 / 40
5.9.10 0 / 40
5.9.9 0 / 40
5.9.8 0 / 40
5.9.7 0 / 40
5.9.6 0 / 40
5.9.5 0 / 40
5.9.4 0 / 40
5.9.3 0 / 40
5.9.2 0 / 40
5.9.1 0 / 40
5.9.0 0 / 40
5.8.1 0 / 40
5.8.0 0 / 40
5.7.1 0 / 38
5.7.0 0 / 38
5.6.2 0 / 38
5.6.1 0 / 38
5.6.0 0 / 38
5.5.1 0 / 37
5.5.0 0 / 37
5.4.0 0 / 27
5.3.4 0 / 27
5.3.3 0 / 27
5.3.2 0 / 27
5.3.1 0 / 27
5.3.0 0 / 27
5.2.0 0 / 27
5.1.0 0 / 27
5.0.2 0 / 27
5.0.1 0 / 27
5.0.0 0 / 27
4.7.0 0 / 27
4.6.2 0 / 27
Showing 100 of 148 Next page →

v10.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.4.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v7.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-17) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-17. This could indicate a legitimate maintainer transition or an account compromise.

v7.0.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-16) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-16. This could indicate a legitimate maintainer transition or an account compromise.

v6.2.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-15. This could indicate a legitimate maintainer transition or an account compromise.

v6.2.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-13) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-13. This could indicate a legitimate maintainer transition or an account compromise.

v6.1.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-13) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-13. This could indicate a legitimate maintainer transition or an account compromise.

v6.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-07. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.6

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-04) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-04. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-11-03) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-11-03. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-10-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-10-22. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.3

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-10-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-10-22. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.2

4 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-09-03) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-09-03. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.1

4 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: react-native-community-bot → mattoakes (on 2021-08-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2021-08-24. This could indicate a legitimate maintainer transition or an account compromise.

v6.0.0

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.10

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.9

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.8

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.7

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.6

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.5

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.4

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.3

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.2

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.1

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.0

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.8.1

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.8.0

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.7.1

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.7.0

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.2

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.1

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.6.0

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.5.1

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.5.0

3 findings
HIGH New obfuscated file: lib/commonjs/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/module/internal/nativeModule.web.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.2

2 findings
HIGH New obfuscated file: lib/commonjs/internal/state.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.1

2 findings
HIGH New obfuscated file: lib/commonjs/internal/state.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.0

2 findings
HIGH New obfuscated file: lib/commonjs/internal/state.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.2.0

2 findings
HIGH New obfuscated file: lib/commonjs/internal/state.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.6.2

2 findings
HIGH New obfuscated file: lib/commonjs/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.