← Home

@riverbankcms/sdk

Riverbank CMS SDK for headless content consumption

21
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

riverbankcms

Keywords

headless-cmsriverbankcmscmscontentsdk

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@riverbankcms/site-commands AI (phantom-deps): Same-org workspace dep, referenced indirectly. ai
phantom-deps phantom-dep:@riverbankcms/content-model AI (phantom-deps): Same-org workspace dep, referenced indirectly. ai
dependencies unvetted-dep:@riverbankcms/site-commands AI (dependencies): First-party workspace package from same org. ai
dependencies unvetted-dep:@riverbankcms/content-model AI (dependencies): First-party workspace package from same org. ai
source-diff net-exec-file:dist/previewAuthStore-CfquDtTh.mjs AI (source-diff): Preview auth store client code, standard SDK feature. ai
source-diff net-exec-file:dist/previewAuthStore-ByPPZqmp.mjs AI (source-diff): Bundled preview auth store using package's own cache-tag constants, benign. ai
source-diff net-exec-file:dist/cli/index.mjs AI (source-diff): Bundled CLI (commander/simple-git/prompts) matches documented bin entrypoint, not a dropper. ai
source-diff net-exec-file:dist/client/media-CZJKL7fi.mjs AI (source-diff): Bundled media path-safety helper code, no exfil behavior. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): Used by CLI tooling, declared correctly for bin usage. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): CLI dependency used in bundled cli/index.mjs. ai
phantom-deps phantom-dep:prompts AI (phantom-deps): CLI dependency used in bundled cli/index.mjs. ai
phantom-deps phantom-dep:fast-deep-equal AI (phantom-deps): Utility dep used within bundled build, false positive on import detection. ai
source-diff large-new-source-files AI (source-diff): Diff vs stale v0.2.0 sibling across ~100 intervening npm releases, not a sudden injection. ai
source-diff source-size-tripled AI (source-diff): Same stale-baseline diff artifact; growth aligns with many skipped versions. ai
source-diff net-exec-file:dist/server/chunk-2NBNOY3C.mjs AI (source-diff): Same loader logic, ESM chunk of legitimate bundled code. ai
source-diff net-exec-file:dist/server/chunk-KH3EXBJM.js AI (source-diff): Bundled prebuild-loader chunk (fs/path manifest cache), no dropper behavior in sample. ai
dependencies unvetted-dep:@riverbankcms/api AI (dependencies): Workspace-internal sibling package from same org; not an external unvetted dependency. ai
dependencies unvetted-dep:@riverbankcms/blocks AI (dependencies): Workspace-internal sibling package from same org; not an external unvetted dependency. ai
dependencies unvetted-dep:@riverbankcms/site-renderer AI (dependencies): Workspace-internal sibling package from same org; not an external unvetted dependency. ai

Versions (showing 21 of 21)

Version Deps Published
0.104.1 8 / 21
0.104.0 8 / 21
0.102.0 8 / 21
0.68.0 10 / 23
0.60.16 9 / 23
0.55.0 8 / 23
0.7.5 6 / 14
0.7.0 6 / 13
0.6.1 6 / 12
0.6.0 6 / 12
0.5.3 6 / 12
0.5.2 6 / 12
0.5.1 6 / 12
0.5.0 5 / 11
0.4.3 4 / 10
0.4.2 4 / 10
0.4.1 4 / 10
0.4.0 4 / 10
0.3.0 3 / 10
0.2.0 6 / 7
0.1.0 6 / 7

v0.104.1

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.

HIGH New file with network + code execution: dist/cli/index.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/client/media-CZJKL7fi.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/previewAuthStore-CfquDtTh.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.104.0

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.

HIGH New file with network + code execution: dist/cli/index.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/client/media-CZJKL7fi.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/previewAuthStore-CfquDtTh.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.102.0

5 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.

HIGH New file with network + code execution: dist/cli/index.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/client/media-CZJKL7fi.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/previewAuthStore-ByPPZqmp.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.60.16

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.

HIGH New file with network + code execution: dist/cli/index.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.5

3 findings
HIGH New file with network + code execution: dist/server/chunk-KH3EXBJM.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/server/chunk-2NBNOY3C.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.