@scalar/api-reference
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-YU9KKgvZ.js | AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-WJ4Gcv8N.js | AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-B-Nhpn0q.js | AI (source-diff): Vite-bundled minified dist chunk with build banner; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BqFs9NIb.js | AI (source-diff): Bundled vendor chunk; net+exec patterns are library code, no hostile target. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-7kt1IXrE.js | AI (source-diff): Vendor bundle for a browser API-reference component; net/exec are library primitives, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BkjPSVNK.js | AI (source-diff): Vite/Rollup minified browser bundle with Scalar banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-CI1RYR0j.js | AI (source-diff): Minified bundled browser chunk; benign build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-CnSl7YW1.js | AI (source-diff): Minified bundled Vue component chunk; benign build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-BLBi4S4R.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-D7J_MHKY.js | AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-DHN5fsxL.js | AI (source-diff): Bundled vendor chunk; net+exec is browser-runtime library code, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Fb0snAee.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BPQqqkn-.js | AI (source-diff): Bundled vendor chunk; net+exec are library primitives, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-CysYmeeN.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-wI0tG53V.js | AI (source-diff): Vite-bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-C3QiXv0S.js | AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-B4LeCbAi.js | AI (source-diff): Minified Vite bundle; normal ESM imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-D4DCmV5y.js | AI (source-diff): Minified Vite bundle with Scalar banner; long lines are build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BNhbieDE.js | AI (source-diff): Vendor browser bundle; net+exec patterns inherent to bundled deps, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-C5aaO8tA.js | AI (source-diff): Minified Vue component bundle; build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-Dp5Q6nDX.js | AI (source-diff): Bundled vendor chunk of a browser API-reference UI; network+eval is normal Vue runtime, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CPqxdcxM.js | AI (source-diff): Minified vite bundle output, not obfuscation; per-file path won't recur but pattern is benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/src-DJwsRvMU.js | AI (source-diff): Bundled Vite build output, readable ESM imports; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-DfHAfVG5.js | AI (source-diff): Bundled minified Vue component chunk. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-uEJhFXkB.js | AI (source-diff): Bundled minified dist chunk, build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-VSnkfbyL.js | AI (source-diff): Bundled minified dist chunk with Scalar banner, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-C5HmjoOQ.js | AI (source-diff): Minified Vite vendor bundle; long lines are build output, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BhUn0w1j.js | AI (source-diff): Vite-bundled dist chunk with Scalar banner; minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BeJNu9KM.js | AI (source-diff): Bundled vendor chunk; net+exec patterns are inherent to browser bundle, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-BUzf4Z_k.js | AI (source-diff): Vite-bundled dist chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-CZI71Aau.js | AI (source-diff): Vite-bundled dist chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-B2flFlrc.js | AI (source-diff): Bundled dist chunk; minified build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DX-rWLia.js | AI (source-diff): Vite-bundled dist chunk, long lines are minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-DuE2oAzR.js | AI (source-diff): Bundled dist chunk; minified build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-DPVN2O_H.js | AI (source-diff): Bundled vendor chunk; net+exec patterns are Vue runtime build output, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Cg0WEkPQ.js | AI (source-diff): Minified Vite bundle chunk; build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-DfF1NNVy.js | AI (source-diff): Bundled Vue vendor chunk; net+exec is standard browser runtime, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-Bd03__M5.js | AI (source-diff): Minified Vite bundle chunk with Scalar banner; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-DXAlZ4Y8.js | AI (source-diff): Minified Vite bundle chunk; build output. | ai | |
| source-diff | obfuscated-file:dist/src-DqcYVBWI.js | AI (source-diff): Vite/rollup bundle output with readable ESM imports, not obfuscation; stable for this build tool. | ai | |
| source-diff | obfuscated-file:dist/components/GettingStarted.vue.script.js | AI (source-diff): Vite/Vue bundled component output, not obfuscation; readable imports and first-party fetch target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-c6CQmaLr.js | AI (source-diff): Vite-bundled minified chunk with Scalar banner, not obfuscation. | ai | |
| dependencies | unvetted-dep:@scalar/client-app | AI (dependencies): First-party sibling package in the same monorepo. | ai | |
| phantom-deps | phantom-dep:unhead | AI (phantom-deps): Used in config, not a real risk. | ai | |
| phantom-deps | phantom-dep:unified | AI (phantom-deps): Used via config files, not direct import; benign. | ai | |
| phantom-deps | phantom-dep:postcss-nested | AI (phantom-deps): Used via PostCSS config, not direct import; stable false positive. | ai | |
| dependencies | unvetted-dep:@scalar/api-client-modal | AI (dependencies): First-party @scalar sibling package within same monorepo. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-BvqLUPs5.js | AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-BlFFskFr.js | AI (source-diff): Bundled vendor chunk; net+exec are inherent to browser bundle, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CNs5mxby.js | AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-D_L-rtQC.js | AI (source-diff): Vite-bundled dist chunk with official banner; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-DQLVQL1H.js | AI (source-diff): Minified bundle chunk, official banner; build output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-CMNc6l_z.js | AI (source-diff): Standard vendor bundle for browser build; dual-use in minified output, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-Cb7P6-e4.js | AI (source-diff): Minified Vue component bundle chunk; build output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DeQ6jlD2.js | AI (source-diff): Vite/Rollup minified bundle chunk with official Scalar banner; build output not obfuscation. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-wW8jg8wN.js | AI (source-diff): Vendor bundle from Vite build; network+exec patterns are from bundled dependencies (Vue, etc.). | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-BZzcBkVp.js | AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-CesFQ_Ax.js | AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-C14zmVNI.js | AI (source-diff): Standard Vite-minified browser bundle chunk; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:flatted | AI (phantom-deps): Declared dep used transitively or in config; stable pattern for this package. | ai | |
| provenance | publisher-changed | AI (provenance): scalar_geoff is an established Scalar org publisher with 446 approved packages. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-Dv0uBVU9.js | AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-Cx_C-51y.js | AI (source-diff): Vendor bundle from Vite build; network+exec patterns are from bundled dependencies. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-ZmlutrTU.js | AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-DHI6k89v.js | AI (source-diff): Vite-minified browser bundle chunk; standard for this package's dist output. | ai | |
| source-diff | encoded-string-file:dist/browser/standalone.js | AI (source-diff): Bundled standalone build with CodeMirror bidi char-class tables; stable minified output pattern. | ai | |
| source-diff | net-exec-file:dist/browser/chunks/vendor-nugWm4eq.js | AI (source-diff): Bundled vendor chunk for browser dist; network+exec pattern is normal for UI framework bundles. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/ScalarTextInput.vue-XkIzhvc0.js | AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/modal-Bp9V4D2s.js | AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-BXB1nZKJ.js | AI (source-diff): Standard Vite-minified browser chunk with Scalar banner; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@scalar/openapi-upgrader | AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. | ai | |
| phantom-deps | phantom-dep:@scalar/object-utils | AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. | ai | |
| phantom-deps | phantom-dep:@scalar/json-magic | AI (phantom-deps): Same-org scoped dependency; declared and re-exported, stable pattern. | ai | |
| phantom-deps | phantom-dep:@floating-ui/vue | AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:type-fest | AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:js-base64 | AI (phantom-deps): Declared dependency; referenced in config, stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/browser-67K6wmG9.js | AI (source-diff): Vite-bundled browser standalone chunk with standard minification; stable pattern for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New standalone ESM build target adds expected browser bundle chunks. | ai | |
| source-diff | obfuscated-file:dist/browser/chunks/AgentScalarChatInterface-DIIVMX31.js | AI (source-diff): Vite-bundled browser standalone chunk with standard minification; stable pattern for this package. | ai | |
| dependencies | unvetted-dep:@scalar/themes | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/workspace-store | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/use-toasts | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/components | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/api-client | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/agent-chat | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/use-hooks | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/oas-utils | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/sidebar | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai | |
| dependencies | unvetted-dep:@scalar/icons | AI (dependencies): Same scalar monorepo; legitimate sibling dep. | ai |
Versions (showing 51 of 395)
| Version | Deps | Published |
|---|---|---|
| 1.63.0 | 25 / 18 | |
| 1.62.9 | 25 / 18 | |
| 1.62.8 | 25 / 18 | |
| 1.62.7 | 25 / 18 | |
| 1.62.6 | 25 / 18 | |
| 1.62.5 | 25 / 18 | |
| 1.62.4 | 25 / 18 | |
| 1.62.3 | 25 / 18 | |
| 1.62.2 | 25 / 18 | |
| 1.62.1 | 25 / 18 | |
| 1.62.0 | 25 / 18 | |
| 1.61.0 | 24 / 18 | |
| 1.60.0 | 24 / 18 | |
| 1.59.3 | 24 / 18 | |
| 1.59.2 | 24 / 18 | |
| 1.59.1 | 24 / 18 | |
| 1.59.0 | 24 / 18 | |
| 1.58.0 | 24 / 18 | |
| 1.57.5 | 24 / 18 | |
| 1.57.4 | 24 / 18 | |
| 1.57.3 | 24 / 18 | |
| 1.57.2 | 24 / 18 | |
| 1.57.1 | 24 / 18 | |
| 1.57.0 | 24 / 18 | |
| 1.55.3 | 22 / 18 | |
| 1.55.2 | 22 / 18 | |
| 1.55.1 | 22 / 17 | |
| 1.55.0 | 23 / 17 | |
| 1.54.0 | 23 / 17 | |
| 1.53.1 | 23 / 17 | |
| 1.53.0 | 23 / 17 | |
| 1.52.6 | 23 / 17 | |
| 1.52.5 | 23 / 17 | |
| 1.52.4 | 23 / 17 | |
| 1.52.3 | 23 / 17 | |
| 1.52.2 | 23 / 16 | |
| 1.52.1 | 23 / 16 | |
| 1.52.0 | 23 / 16 | |
| 1.51.0 | 23 / 16 | |
| 1.50.0 | 23 / 16 | |
| 1.49.8 | 24 / 16 | |
| 1.49.7 | 24 / 18 | |
| 1.49.6 | 24 / 18 | |
| 1.49.5 | 24 / 18 | |
| 1.49.4 | 24 / 18 | |
| 1.49.3 | 24 / 18 | |
| 1.49.2 | 24 / 18 | |
| 1.49.1 | 24 / 18 | |
| 1.49.0 | 24 / 19 | |
| 1.48.8 | 24 / 19 | |
| 1.48.7 | 24 / 19 |
v1.63.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.9
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.8
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.7
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.6
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.5
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.4
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.62.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.5
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.4
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.