@reltio/remotes
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:1664.86568a669821f41b9739.js | AI (source-diff): Standard webpack bundle output for this MFE package, not true obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): Trusted long-standing publisher; no provenance regression. | ai | |
| source-diff | obfuscated-file:101.ff29eb8fc102e02b2e2d.js | AI (source-diff): Webpack/Sentry-bundled chunk output, not true obfuscation. | ai | |
| source-diff | net-exec-file:4297.daac1d44702d8bae8a75.js | AI (source-diff): Bundled webpack chunk; no concrete exfil/dropper behavior shown. | ai | |
| source-diff | net-exec-file:1849.7929b2440da54ebe6824.js | AI (source-diff): Bundled webpack chunk; no concrete exfil/dropper behavior shown. | ai | |
| source-diff | net-exec-file:1849.832775f25b394ffaee3f.js | AI (source-diff): Webpack chunk with sourcemap; pattern-match on minified bundle, no concrete malicious behavior shown. | ai | |
| source-diff | obfuscated-file:101.9b4b26e2aca376b19e91.js | AI (source-diff): Webpack bundle chunk with Sentry banner; sampled code is standard minified React/MUI, not obfuscation. | ai | |
| source-diff | net-exec-file:4297.abf0dfe8e6785bf1ca78.js | AI (source-diff): Same webpack bundle pattern; base64-decode/new-Function hits are standard minifier/runtime helpers. | ai | |
| source-diff | obfuscated-file:101.46b2b22fa468988e1eae.js | AI (source-diff): Webpack bundle chunk with Sentry debug-id banner; minified, not obfuscated. | ai | |
| source-diff | net-exec-file:2458.bea82ac351cd35449d1f.js | AI (source-diff): Bundled third-party UI code (network+eval patterns), not a dropper. | ai | |
| source-diff | net-exec-file:1849.3754d9034377dc19ec52.js | AI (source-diff): Bundled third-party UI code (network+eval patterns), not a dropper. | ai | |
| source-diff | obfuscated-file:101.da213456cabf404a1f8c.js | AI (source-diff): Webpack bundle with Sentry banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:4297.7b42c07703e3b293cea3.js | AI (source-diff): Bundled vendor code, no fetched-binary execution or exfil observed. | ai | |
| source-diff | net-exec-file:4372.5ca45305a068d79040e0.js | AI (source-diff): Same webpack bundle pattern; no concrete malicious payload shown. | ai | |
| source-diff | obfuscated-file:1232.0d277a1c240197004897.js | AI (source-diff): Webpack bundle with Sentry banner and recognizable MUI source, not true obfuscation. | ai | |
| source-diff | net-exec-file:2458.3bf4c11755b7b674b13a.js | AI (source-diff): Bundled analytics/fetch code in minified chunk, no concrete exfil target. | ai | |
| source-diff | net-exec-file:1849.1fca8b2506381cda87f7.js | AI (source-diff): Bundled analytics/fetch code in minified chunk, no concrete exfil target. | ai | |
| source-diff | obfuscated-file:4372.fa82443727ff2928cc50.js | AI (source-diff): Webpack chunk with sentry banner; bundled output not true obfuscation. | ai | |
| source-diff | net-exec-file:4372.fa82443727ff2928cc50.js | AI (source-diff): Bundled webpack runtime, no concrete malicious network target identified. | ai | |
| source-diff | net-exec-file:4994.0f00de9a2cebc7b0505c.js | AI (source-diff): Bundled webpack runtime chunk, benign sourcemap/sentry pattern. | ai | |
| source-diff | obfuscated-file:1232.9ce18df0e1a9b81847a0.js | AI (source-diff): Webpack chunk bundle output, not obfuscation; sample is standard MUI icon code. | ai | |
| source-diff | obfuscated-file:101.2ac4fc21333da3c26e56.js | AI (source-diff): Standard webpack minified bundle chunk, not true obfuscation. | ai | |
| source-diff | net-exec-file:1849.6ce9ea331022f23a1e87.js | AI (source-diff): Minified bundle chunk pattern-matches net+exec heuristics; no dropper behavior found in sample. | ai | |
| source-diff | net-exec-file:2458.1591ac386b85c5c82616.js | AI (source-diff): Same bundled-chunk false positive as other net-exec hits in this release. | ai | |
| source-diff | obfuscated-file:4297.24459448f1c0897a4aa5.js | AI (source-diff): Webpack bundle chunk with Sentry debug-id banner; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:4297.24459448f1c0897a4aa5.js | AI (source-diff): Bundled chunk; network+eval patterns are library internals, no exfil destination found. | ai | |
| source-diff | net-exec-file:1849.231e7e180243e32914fc.js | AI (source-diff): Bundled chunk; same benign pattern as other webpack outputs. | ai | |
| source-diff | obfuscated-file:1664.33d71a2278a924344b03.js | AI (source-diff): Webpack bundle output, routine for this frontend package's release cadence. | ai | |
| source-diff | net-exec-file:2458.e13014ff825ed4a26742.js | AI (source-diff): Bundled webpack chunk, not a loader/dropper. | ai | |
| source-diff | net-exec-file:1849.3bb3b324fd90be452129.js | AI (source-diff): Bundled webpack chunk, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:101.2f6dab067cfee24a7393.js | AI (source-diff): Webpack bundle chunk with Sentry banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:4372.f2174d57d6fed06b5bad.js | AI (source-diff): Same bundled webpack chunk pattern, no concrete malicious network/exec behavior shown. | ai | |
| source-diff | net-exec-file:2458.b058a5d9d29ad0f37bc5.js | AI (source-diff): Bundled UI chunk; network+eval pattern from library code, not dropper behavior. | ai | |
| source-diff | net-exec-file:1849.5c75f7337b1d82d7c2c4.js | AI (source-diff): Bundled UI chunk; network+eval pattern from library code, not dropper behavior. | ai | |
| source-diff | obfuscated-file:101.7d73552e3389af398359.js | AI (source-diff): Webpack-bundled chunk with Sentry debug IDs, not true obfuscation. | ai | |
| source-diff | obfuscated-file:101.fa971fb416e2dffb7613.js | AI (source-diff): Minified webpack bundle chunk with Sentry debug-id banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:1849.17755857c70de3c32f81.js | AI (source-diff): Standard bundled JS with fetch+Function patterns, not a dropper. | ai | |
| source-diff | net-exec-file:2458.b57cb262bcc961f44f60.js | AI (source-diff): Standard bundled JS with fetch+Function patterns, not a dropper. | ai | |
| source-diff | net-exec-file:4372.c5f8f75645b88405753c.js | AI (source-diff): Bundled webpack chunk; network+eval pattern is bundler boilerplate, not a dropper. | ai | |
| source-diff | net-exec-file:4994.49f5ef2d38af1967ab6f.js | AI (source-diff): Bundled webpack chunk; same boilerplate pattern as other chunks. | ai | |
| source-diff | obfuscated-file:4372.c5f8f75645b88405753c.js | AI (source-diff): Webpack bundle chunk with sourcemap and sentry banner; build artifact, not obfuscation. | ai | |
| source-diff | net-exec-file:1849.326ea3c8a404f377aa3a.js | AI (source-diff): Bundled webpack chunk; no fetched-binary/exfil behavior evidenced. | ai | |
| source-diff | net-exec-file:2458.719a64c71617c9c69fa9.js | AI (source-diff): Bundled webpack chunk; no fetched-binary/exfil behavior evidenced. | ai | |
| source-diff | obfuscated-file:101.ddfc865e25d5b65d2cbe.js | AI (source-diff): Webpack-bundled build output with Sentry debug ids, not true obfuscation. | ai | |
| source-diff | obfuscated-file:1232.4f4c3d4f6750480f089f.js | AI (source-diff): Webpack-bundled MUI/React chunk with Sentry banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:4994.79dc125b877ccfbc7816.js | AI (source-diff): Minified bundle chunk, network+eval pattern match on build output not real exfil. | ai | |
| source-diff | net-exec-file:4372.45150b266316934953d2.js | AI (source-diff): Minified bundle chunk, network+eval pattern match on build output not real exfil. | ai | |
| source-diff | net-exec-file:4994.879d3c6f7e8190c71f13.js | AI (source-diff): Bundled SPA chunk, network+eval pattern from vendor libs not malware. | ai | |
| source-diff | obfuscated-file:1232.b286e73c8dde26649e73.js | AI (source-diff): Webpack bundle with Sentry banner, not true obfuscation. | ai | |
| source-diff | obfuscated-file:1232.c4950f01ebfdb4488e82.js | AI (source-diff): Webpack/Sentry bundle banner, minified MUI icon code — build output not obfuscation. | ai | |
| source-diff | net-exec-file:4994.2a4040138302ab45ca4d.js | AI (source-diff): Bundled webpack chunk boilerplate, not a real dropper pattern. | ai | |
| source-diff | net-exec-file:4372.f78e60b7ebf915b4277e.js | AI (source-diff): Bundled webpack chunk boilerplate, not a real dropper pattern. | ai | |
| source-diff | net-exec-file:4372.85df982dd5c50e6d1688.js | AI (source-diff): Webpack runtime pattern, no fetched/executed payload observed. | ai | |
| source-diff | net-exec-file:4994.e715371cba7fc57fa1bf.js | AI (source-diff): Webpack runtime pattern, no fetched/executed payload observed. | ai | |
| source-diff | obfuscated-file:1232.60474b2b6f6d28b1d0f0.js | AI (source-diff): Webpack/Sentry bundle chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:1664.43799233135d6232098c.js | AI (source-diff): Webpack bundle chunk with Sentry banner; minified, not obfuscated. | ai | |
| source-diff | net-exec-file:4372.565612b250740549aae4.js | AI (source-diff): Same bundled Sentry chunk pattern, benign build output. | ai | |
| source-diff | net-exec-file:4994.b4c9d8f5e8bbf7184a2a.js | AI (source-diff): Sentry SDK bundled chunk pattern, not a dropper; recurring across releases of this bundler-based package. | ai | |
| source-diff | net-exec-file:4372.876f20a97f9e70883adf.js | AI (source-diff): Bundled webpack output with Sentry/base64 boilerplate, not dropper behavior. | ai | |
| source-diff | obfuscated-file:1232.7ef599b97f55880a3b9c.js | AI (source-diff): Webpack chunk bundle with Sentry banner; sample shows plain vendored library code. | ai | |
| source-diff | net-exec-file:4994.af467dd93e401b1bcc67.js | AI (source-diff): Same bundler boilerplate pattern, not malicious code exec. | ai | |
| source-diff | net-exec-file:1849.96dfb7185a2ba6e48278.js | AI (source-diff): Same bundled webpack chunk pattern as other flagged files. | ai | |
| source-diff | net-exec-file:4297.6b10dc1079a0db01c709.js | AI (source-diff): Base64/Function usage is webpack runtime boilerplate, no exfil destination. | ai | |
| source-diff | obfuscated-file:4297.6b10dc1079a0db01c709.js | AI (source-diff): Webpack chunk with Sentry debug-id banner; minified bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:4372.b9004d4284420e18aa1c.js | AI (source-diff): Bundled chunk pattern, no fetched-binary or hostile exec observed. | ai | |
| source-diff | obfuscated-file:4372.b9004d4284420e18aa1c.js | AI (source-diff): Webpack-bundled vendor chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:1664.a1572634b56b41980bee.js | AI (source-diff): Webpack bundle output with sourcemap/license banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:4372.a10143e8ac64773a4b47.js | AI (source-diff): Bundled Sentry/webpack chunk; no concrete malicious network target identified. | ai | |
| source-diff | obfuscated-file:1232.86c6173d0968f4bae97d.js | AI (source-diff): Webpack/Sentry bundle banner; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:4994.1cfb1424bf463edb1478.js | AI (source-diff): Bundled Sentry/webpack chunk; no concrete malicious network target identified. | ai | |
| source-diff | net-exec-file:4372.1bcbcec469064eb71dc5.js | AI (source-diff): Bundled webpack chunk; no concrete malicious behavior found in sample. | ai | |
| source-diff | net-exec-file:4994.4a586f7377617535cf25.js | AI (source-diff): Bundled webpack chunk; no concrete malicious behavior found in sample. | ai | |
| source-diff | obfuscated-file:1232.1bb9b783dde33eb7b5bb.js | AI (source-diff): Webpack bundle with Sentry banner; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:4994.783f116e9a25dbe91d18.js | AI (source-diff): Bundled webpack chunk; base64/Function patterns are library internals, no exfil destination. | ai | |
| source-diff | obfuscated-file:1232.c411db69ee158db53dfa.js | AI (source-diff): Webpack bundle chunk with Sentry banner; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:4372.2588c13d5e3f08a392da.js | AI (source-diff): Bundled webpack chunk; base64/Function patterns are library internals, no exfil destination. | ai | |
| source-diff | net-exec-file:4372.ce3bbff0bd9fb65204e0.js | AI (source-diff): Webpack chunk loader network+eval pattern, no malicious destination shown. | ai | |
| source-diff | obfuscated-file:1232.9df9204717b35674e93f.js | AI (source-diff): Webpack/Sentry bundle output, not obfuscation. | ai | |
| source-diff | net-exec-file:4994.a94feb70e1d60f4845ab.js | AI (source-diff): Webpack chunk loader network+eval pattern, no malicious destination shown. | ai | |
| source-diff | net-exec-file:4994.460283ff95f33f8c35a2.js | AI (source-diff): Standard webpack chunk-loader network+exec pattern, not dropper behavior. | ai | |
| source-diff | net-exec-file:4372.bbaf0b7093c5e5cb2f73.js | AI (source-diff): Standard webpack chunk-loader network+exec pattern, not dropper behavior. | ai | |
| source-diff | obfuscated-file:1232.15846ecfb87aa7a24bf3.js | AI (source-diff): Webpack bundle output with Sentry debug-id banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:4297.dde9d95203c6f0f75b67.js | AI (source-diff): Bundled webpack chunk; same pattern as other chunks, no concrete malicious target identified. | ai | |
| source-diff | net-exec-file:1849.eeb560f9331024e8a5eb.js | AI (source-diff): Bundled webpack chunk; network+eval pattern matches bundler runtime, not dropper behavior. | ai | |
| source-diff | obfuscated-file:1232.4faece87a2bf82b30d24.js | AI (source-diff): Webpack bundle with Sentry banner; minified, not obfuscated. | ai | |
| source-diff | net-exec-file:2458.7d2628afb04354dc5784.js | AI (source-diff): Bundled frontend chunk; no concrete malicious network/exec behavior in sample. | ai | |
| source-diff | net-exec-file:1849.13eede4137e028f0ba73.js | AI (source-diff): Bundled frontend chunk; no concrete malicious network/exec behavior in sample. | ai | |
| source-diff | obfuscated-file:101.62032cfd501839d57588.js | AI (source-diff): Webpack-bundled minified output with Sentry debug IDs, not true obfuscation. | ai | |
| source-diff | obfuscated-file:101.2a89e998ffe3f4a52914.js | AI (source-diff): Webpack-bundled minified chunk with Sentry debug ID banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:4372.33ec72db182061df28b6.js | AI (source-diff): Bundled vendor code, no concrete exfil/malicious destination identified. | ai | |
| source-diff | obfuscated-file:1232.83f3b91465337fe5540b.js | AI (source-diff): Webpack bundle with Sentry banner, not true obfuscation; consistent with large legit build. | ai | |
| source-diff | obfuscated-file:1008.84f79ced527c0c1118ba.js | AI (source-diff): Webpack/Sentry bundle chunk, minified build output not true obfuscation. | ai | |
| source-diff | net-exec-file:2505.6835a3b7861a7e9a007d.js | AI (source-diff): Bundled webpack chunk; no fetched-binary/exfil behavior shown in sample. | ai | |
| source-diff | net-exec-file:2458.82bac974048cbb63f250.js | AI (source-diff): Bundled webpack chunk; no fetched-binary/exfil behavior shown in sample. | ai | |
| source-diff | obfuscated-file:1008.84d9231c94c53b4ae588.js | AI (source-diff): Webpack chunk with Sentry banner; sampled content is standard MUI icon/component code, not obfuscation. | ai | |
| source-diff | net-exec-file:2458.6214105fae7e5038a4ff.js | AI (source-diff): Bundled webpack output; no fetched-binary or exfil behavior observed, false-positive pattern for bundlers. | ai | |
| source-diff | net-exec-file:2505.1fb1bd522cfcb11f49d8.js | AI (source-diff): Bundled webpack output; no fetched-binary or exfil behavior observed, false-positive pattern for bundlers. | ai | |
| source-diff | net-exec-file:2505.4770a01550b477c3fd14.js | AI (source-diff): Same bundler-banner false positive pattern as other chunk files. | ai | |
| source-diff | net-exec-file:2458.d3b05832bf06ae31b9ee.js | AI (source-diff): Generic bundler banner triggers net+exec heuristic; no concrete malicious behavior shown. | ai | |
| source-diff | obfuscated-file:2458.d3b05832bf06ae31b9ee.js | AI (source-diff): Webpack bundle chunk with Sentry banner; large minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:4372.c3a386e737374d6d7108.js | AI (source-diff): Bundled webpack output; net+eval pattern is standard bundler runtime, not dropper behavior. | ai | |
| source-diff | obfuscated-file:4372.c3a386e737374d6d7108.js | AI (source-diff): Webpack bundle chunk with Sentry banner; long-line minification, not obfuscation. | ai | |
| source-diff | net-exec-file:4994.98842ebf1b6236d52174.js | AI (source-diff): Same bundled webpack chunk pattern as sibling files; no concrete malicious destination. | ai | |
| source-diff | net-exec-file:4372.bad3c1a52daaf9b69678.js | AI (source-diff): Bundled polyfill code, no evidence of fetched/executed remote payload. | ai | |
| source-diff | net-exec-file:4994.7e38df1395adcbe85e70.js | AI (source-diff): Bundled polyfill code, no evidence of fetched/executed remote payload. | ai | |
| source-diff | obfuscated-file:4372.bad3c1a52daaf9b69678.js | AI (source-diff): Webpack bundle chunk, long-line minification not true obfuscation. | ai | |
| source-diff | obfuscated-file:334.b1a23d4e32ecd3a35143.js | AI (source-diff): Webpack bundle chunk, minified not obfuscated; consistent with prior releases. | ai | |
| source-diff | net-exec-file:4994.7a939dfafa21cb6fcc30.js | AI (source-diff): Bundled library code (network+dynamic exec pattern typical of bundled fetch/polyfill code), not a dropper. | ai | |
| source-diff | net-exec-file:4297.cce9a9e1c25811dfe4d9.js | AI (source-diff): Bundled build chunk; network+eval pattern is standard webpack/react runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:101.f1a0511cac4bee6e8200.js | AI (source-diff): Webpack-bundled minified output with Sentry debug-id banner, not true obfuscation. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Longstanding internal package convention; not indicative of malice. | ai | |
| source-diff | net-exec-file:1849.e9a7a040fab7599b2480.js | AI (source-diff): Bundled build chunk; network+eval pattern is standard webpack/react runtime, not a dropper. | ai | |
| source-diff | net-exec-file:1849.b85af2bbfaa102dfa061.js | AI (source-diff): Minified webpack runtime, not a loader/dropper; matches bundling pattern. | ai | |
| source-diff | net-exec-file:2458.88a5b86fcc498a43bece.js | AI (source-diff): Minified webpack runtime, not a loader/dropper; matches bundling pattern. | ai | |
| source-diff | obfuscated-file:1232.e35eb2d47f8ae7afea20.js | AI (source-diff): Webpack bundle output with Sentry banner, not true obfuscation. | ai | |
| source-diff | net-exec-file:4994.84ee182f00b0b4a50cc3.js | AI (source-diff): Bundled webpack chunk with sourcemap; no concrete malicious behavior identified. | ai | |
| source-diff | net-exec-file:4372.99576340e484b9a5be40.js | AI (source-diff): Bundled webpack chunk with sourcemap; no concrete malicious behavior identified. | ai | |
| source-diff | net-exec-file:4372.c8644af53936b3899124.js | AI (source-diff): Bundled SPA chunk; no concrete exfil/dropper behavior identified. | ai | |
| source-diff | net-exec-file:4994.4d3d97d2d71c7186f979.js | AI (source-diff): Bundled SPA chunk; no concrete exfil/dropper behavior identified. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Org-internal team rotation (reltio-* handles), consistent with long publish history. | ai | |
| source-diff | obfuscated-file:1232.33f17eb15bf8dfa2a3bf.js | AI (source-diff): Webpack-bundled UI chunk with Sentry banner, not true obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Routine maintainer rotation within long-trusted 1600+ package history. | ai | |
| source-diff | net-exec-file:4994.a928c3402f4fae65c4e5.js | AI (source-diff): Minified bundle chunk; network+eval pattern matches bundler runtime code, not a dropper. | ai | |
| source-diff | obfuscated-file:1232.6c3f1d03f39c1a336faa.js | AI (source-diff): Webpack bundle chunk with Sentry banner, standard minified UI code, not malware. | ai | |
| source-diff | net-exec-file:4297.82bbaa5683c8d3a0d7c1.js | AI (source-diff): Webpack chunk with network calls and dynamic require — normal for this micro-frontend bundle package. | ai | |
| source-diff | net-exec-file:1849.ea15f7dfdae46c7a8759.js | AI (source-diff): Webpack chunk with network calls (fetch) and dynamic require — normal for this micro-frontend bundle package. | ai | |
| source-diff | obfuscated-file:101.6c1ccb184298b268eac5.js | AI (source-diff): Standard webpack minified bundle with Sentry debug IDs; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:1322.a4edf52d32dd6a5d5527.js | AI (source-diff): Standard webpack minified chunk; MUI icon components visible in sample. | ai | |
| source-diff | obfuscated-file:1312.cdd26db23c4846cc89fa.js | AI (source-diff): Standard webpack minified chunk; MUI icon components visible in sample. | ai | |
| source-diff | obfuscated-file:1232.c7ff0626eec6909d3b57.js | AI (source-diff): Standard webpack minified chunk; date-picker section type definitions visible. | ai | |
| source-diff | obfuscated-file:1138.96d7796a3e428760ad8b.js | AI (source-diff): Standard webpack minified chunk; React/SVG component code visible in sample. | ai | |
| source-diff | obfuscated-file:117.1a585a7f03d3c5817e68.js | AI (source-diff): Standard webpack minified chunk; MUI icon components visible in sample. | ai | |
| source-diff | obfuscated-file:101.6564150262f5ec9e7670.js | AI (source-diff): Standard webpack minified chunk with Sentry debug IDs; not malicious obfuscation. | ai | |
| source-diff | net-exec-file:4297.41eca8e08ac11fd315ce.js | AI (source-diff): Webpack bundle; network+eval pattern is expected in Module Federation runtime chunks. | ai | |
| source-diff | net-exec-file:1849.c339711575828c8ce6f1.js | AI (source-diff): Webpack bundle; network+eval pattern is expected in Module Federation runtime chunks. | ai | |
| source-diff | obfuscated-file:135.2501067060c5b6ca1f7e.js | AI (source-diff): Standard webpack minified chunk; MUI icon components visible in sample. | ai | |
| source-diff | obfuscated-file:133.3322c27aaae7cda17deb.js | AI (source-diff): Standard webpack minified chunk; React virtualized list component visible in sample. | ai | |
| source-diff | net-exec-file:1849.d7360c62198813c2c6e3.js | AI (source-diff): Webpack bundle; network+exec pattern is webpack module loader, not dropper malware. | ai | |
| source-diff | net-exec-file:4297.871e00d43257494d3e37.js | AI (source-diff): Webpack bundle; network+exec pattern is webpack module loader, not dropper malware. | ai | |
| source-diff | obfuscated-file:101.991f8fe890beaf7a0b43.js | AI (source-diff): Standard webpack chunk with Sentry debug ID; minified but not malicious. | ai | |
| source-diff | obfuscated-file:1138.09a1c31300267a88316f.js | AI (source-diff): Standard webpack minified bundle; same pattern as all other chunks in this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Incremental webpack build; 120 new chunk files is normal for this package's release cadence. | ai | |
| source-diff | net-exec-file:4297.b26e415d0945fd267123.js | AI (source-diff): Webpack async chunk loader pattern; not dropper malware. | ai | |
| source-diff | net-exec-file:1849.f12e5b78ba289a942564.js | AI (source-diff): Webpack async chunk loader pattern (fetch + eval); normal for code-split React apps. | ai | |
| source-diff | obfuscated-file:101.3324550f2c4e4507584b.js | AI (source-diff): Standard webpack minified bundle with Sentry debug IDs; consistent pattern across all 1600+ versions. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires in webpack-bundled JS; common in module federation / template engine bundles. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal corporate micro-frontend remote; no public repo/deps/description is expected for this package type. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Fires in webpack-bundled JS; standard pattern for this internal frontend bundle package. | ai |
Versions (showing 100 of 221)
v1.4.1057
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1055
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1054
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1053
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1052
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1051
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1050
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1049
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1048
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1047
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1046
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1045
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1044
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1043
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1042
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1041
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1039
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1038
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1037
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1036
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1035
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1034
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1033
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1032
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1031
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1030
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1029
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1028
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1027
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1026
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1024
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1023
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1022
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1021
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1020
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1019
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1018
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1017
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1016
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1015
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1014
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1013
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1012
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1011
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1010
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1009
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1008
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1007
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1006
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1005
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1002
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.1001
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.999
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.998
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.997
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.996
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.994
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.993
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.992
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.991
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.990
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.989
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.988
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.987
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.986
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.985
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.984
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.983
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.982
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.981
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.980
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.979
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.978
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.977
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.975
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.974
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.973
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.971
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.970
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.969
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.968
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.966
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.965
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.964
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.963
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.962
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.961
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.960
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.959
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.958
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.957
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.956
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.954
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.953
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.952
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.950
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.949
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.948
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.947
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.4.946
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.