@satisfactory-dev/docs.json.ts
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:typescript-eslint | AI (phantom-deps): typescript-eslint is listed as a runtime dep and used in ESLint config files; not a true phantom dep for this package. | ai | |
| source-diff | obfuscated-file:generated-types/lib/0.3.7.7.js | AI (source-diff): AJV-compiled JSON schema validator with inlined schema objects; long lines are codegen artifacts, not obfuscation. | ai | |
| source-diff | obfuscated-file:generated-types/lib/1.0.1.4.js | AI (source-diff): Same AJV codegen pattern; long lines from inlined JSON schema definitions, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:generated-types/1.2.0.0/Base.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.3.7.7/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.4.2.11/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.5.2.1/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.6.1.5/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.7.1.1/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.8.3.3/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/1.0.1.4/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/1.1.2.2/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.3.7.7/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.4.2.11/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.5.2.1/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.6.1.5/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.7.1.1/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/0.8.3.3/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/1.0.1.4/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/1.1.2.2/types.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/1.2.0.0/classes.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| source-diff | obfuscated-file:generated-types/1.0.1.4/Base.d.ts | AI (source-diff): Long lines are verbose TypeScript re-export aliases, not obfuscation; stable pattern for this generated-types package. | ai | |
| source-diff | obfuscated-file:generated-types/1.1.2.2/Base.d.ts | AI (source-diff): Same generated TypeScript alias pattern; false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 54 versions; lack of provenance is consistent across all prior releases. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 1.5.1 | 0 / 6 | |
| 1.5.0 | 0 / 6 | |
| 1.4.3 | 0 / 6 | |
| 1.4.2 | 0 / 6 | |
| 1.4.1 | 0 / 6 | |
| 1.4.0 | 0 / 6 | |
| 1.3.3 | 0 / 6 | |
| 1.3.2 | 0 / 6 | |
| 1.3.1 | 0 / 6 | |
| 1.3.0 | 0 / 6 | |
| 1.2.3 | 0 / 6 | |
| 1.2.2 | 0 / 6 | |
| 1.2.1 | 0 / 6 | |
| 1.2.0 | 0 / 5 | |
| 1.1.1 | 0 / 5 | |
| 1.1.0 | 0 / 5 | |
| 1.0.12 | 3 / 8 | |
| 1.0.11 | 3 / 8 | |
| 1.0.10 | 3 / 8 | |
| 1.0.9 | 3 / 8 | |
| 1.0.8 | 3 / 8 | |
| 1.0.7 | 3 / 8 | |
| 0.17.0 | 7 / 8 |
v1.5.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
23 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
23 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.