@riverbankcms/sdk
Riverbank CMS SDK for headless content consumption
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@riverbankcms/site-commands | AI (phantom-deps): Same-org workspace dep, referenced indirectly. | ai | |
| phantom-deps | phantom-dep:@riverbankcms/content-model | AI (phantom-deps): Same-org workspace dep, referenced indirectly. | ai | |
| dependencies | unvetted-dep:@riverbankcms/site-commands | AI (dependencies): First-party workspace package from same org. | ai | |
| dependencies | unvetted-dep:@riverbankcms/content-model | AI (dependencies): First-party workspace package from same org. | ai | |
| source-diff | net-exec-file:dist/previewAuthStore-CfquDtTh.mjs | AI (source-diff): Preview auth store client code, standard SDK feature. | ai | |
| source-diff | net-exec-file:dist/previewAuthStore-ByPPZqmp.mjs | AI (source-diff): Bundled preview auth store using package's own cache-tag constants, benign. | ai | |
| source-diff | net-exec-file:dist/cli/index.mjs | AI (source-diff): Bundled CLI (commander/simple-git/prompts) matches documented bin entrypoint, not a dropper. | ai | |
| source-diff | net-exec-file:dist/client/media-CZJKL7fi.mjs | AI (source-diff): Bundled media path-safety helper code, no exfil behavior. | ai | |
| phantom-deps | phantom-dep:jiti | AI (phantom-deps): Used by CLI tooling, declared correctly for bin usage. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): CLI dependency used in bundled cli/index.mjs. | ai | |
| phantom-deps | phantom-dep:prompts | AI (phantom-deps): CLI dependency used in bundled cli/index.mjs. | ai | |
| phantom-deps | phantom-dep:fast-deep-equal | AI (phantom-deps): Utility dep used within bundled build, false positive on import detection. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Diff vs stale v0.2.0 sibling across ~100 intervening npm releases, not a sudden injection. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Same stale-baseline diff artifact; growth aligns with many skipped versions. | ai | |
| source-diff | net-exec-file:dist/server/chunk-2NBNOY3C.mjs | AI (source-diff): Same loader logic, ESM chunk of legitimate bundled code. | ai | |
| source-diff | net-exec-file:dist/server/chunk-KH3EXBJM.js | AI (source-diff): Bundled prebuild-loader chunk (fs/path manifest cache), no dropper behavior in sample. | ai | |
| dependencies | unvetted-dep:@riverbankcms/api | AI (dependencies): Workspace-internal sibling package from same org; not an external unvetted dependency. | ai | |
| dependencies | unvetted-dep:@riverbankcms/blocks | AI (dependencies): Workspace-internal sibling package from same org; not an external unvetted dependency. | ai | |
| dependencies | unvetted-dep:@riverbankcms/site-renderer | AI (dependencies): Workspace-internal sibling package from same org; not an external unvetted dependency. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 0.104.1 | 8 / 21 | |
| 0.104.0 | 8 / 21 | |
| 0.102.0 | 8 / 21 | |
| 0.68.0 | 10 / 23 | |
| 0.60.16 | 9 / 23 | |
| 0.55.0 | 8 / 23 | |
| 0.7.5 | 6 / 14 | |
| 0.7.0 | 6 / 13 | |
| 0.6.1 | 6 / 12 | |
| 0.6.0 | 6 / 12 | |
| 0.5.3 | 6 / 12 | |
| 0.5.2 | 6 / 12 | |
| 0.5.1 | 6 / 12 | |
| 0.5.0 | 5 / 11 | |
| 0.4.3 | 4 / 10 | |
| 0.4.2 | 4 / 10 | |
| 0.4.1 | 4 / 10 | |
| 0.4.0 | 4 / 10 | |
| 0.3.0 | 3 / 10 | |
| 0.2.0 | 6 / 7 | |
| 0.1.0 | 6 / 7 |
v0.104.1
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.104.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.102.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.60.16
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: riverbankcms.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.5
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.