@sentio/runtime
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:lib/chunk-Z6R7IWRT.js | AI (source-diff): Bundled vendor deps, same tsup build output pattern. | ai | |
| source-diff | net-exec-file:lib/chunk-X5CIKWKP.js | AI (source-diff): Bundled vendored deps inside tsup chunk; same false-positive pattern as sibling chunk. | ai | |
| source-diff | net-exec-file:lib/chunk-CFG44J2I.js | AI (source-diff): Bundled vendored deps (protobufjs/graceful-fs) inside tsup chunk, not injected exfil/loader code. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): Bundled vendor code (fs-extra/grpc chunks), not package-authored eval. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): False positive on minified string literals in bundled deps. | ai | |
| semgrep | semgrep:shady-links-tlds | AI (semgrep): Matches on bundled template-literal artifacts, not real URLs. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established, widely-used runtime; metadata gaps are cosmetic, not spam. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Bundled code pattern, no malicious behavior evidenced. | ai | |
| source-diff | net-exec-file:lib/chunk-ASPTWJQG.js | AI (source-diff): tsup-bundled deps (grpc/protobufjs/otel/fs-extra); not obfuscation, no exfil destination | ai | |
| source-diff | net-exec-file:lib/chunk-M7AXVHAR.js | AI (source-diff): tsup-bundled protobufjs/deps; base64 encode is protobuf, no hostile target | ai | |
| source-diff | net-exec-file:lib/chunk-VRBW2KLF.js | AI (source-diff): Bundled build chunk (tsup output), not obfuscated malware; sample shows standard module polyfills. | ai | |
| source-diff | net-exec-file:lib/chunk-WQZPRG3V.js | AI (source-diff): Bundled build chunk (tsup output), not obfuscated malware; sample shows standard fs/graceful-fs shims. | ai | |
| source-diff | obfuscated-file:dist/service-v3-CUCRzxpl.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:dist/plugin-BKPj92hO.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:lib/chunk-U6BJVJ62.js | AI (source-diff): Bundled base64/protobuf helper code, not malicious loader. | ai | |
| source-diff | net-exec-file:lib/chunk-EQHBEFKX.js | AI (source-diff): Bundled third-party libs (graceful-fs etc.) via tsup, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/service-v3-C-P_jSmD.js | AI (source-diff): Bundled build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/service-v3-3iFcydRx.js | AI (source-diff): Bundled output chunk. | ai | |
| source-diff | obfuscated-file:dist/plugin-BZBEYadJ.js | AI (source-diff): Bundled tsdown output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:src/gen/service/common/protos/common_pb.ts | AI (source-diff): Generated protobuf descriptor file with base64 payload, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/processor-runner.js | AI (source-diff): child_process.fork of same file for worker processes, documented runtime behavior. | ai | |
| source-diff | obfuscated-file:src/gen/processor/protos/processor_pb.ts | AI (source-diff): Generated protobuf descriptor file, same as above. | ai | |
| source-diff | obfuscated-file:dist/esm-Ajeyb2yg.js | AI (source-diff): Bundled minified output from new tsdown build, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/plugin-zKrh74uo.js | AI (source-diff): Bundled minified output from new tsdown build, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/processor-runner.js | AI (source-diff): Bundled minified CLI entrypoint, matches documented bin target. | ai | |
| source-diff | obfuscated-file:dist/service-v3-BXdclcET.js | AI (source-diff): Bundled minified output from new tsdown build. | ai | |
| source-diff | net-exec-file:lib/chunk-LK4RU6UR.js | AI (source-diff): Bundled tsup output; samples show graceful-fs and fs-extra wrappers, not dropper/loader malware. | ai | |
| source-diff | net-exec-file:lib/chunk-3DTPHRJ2.js | AI (source-diff): Bundled tsup output; samples show standard library code (protobuf, base64, event emitter), not malware. | ai | |
| source-diff | net-exec-file:lib/chunk-TBN64DSW.js | AI (source-diff): Bundled library code (protobuf/base64/event-emitter); no actual dropper payload present in samples. | ai | |
| source-diff | net-exec-file:lib/chunk-WUUWUOFG.js | AI (source-diff): Bundled library code (graceful-fs, fs-extra wrappers); no actual dropper payload present in samples. | ai | |
| provenance | publisher-changed | AI (provenance): Legitimate migration to GitHub Actions CI/CD publishing; SLSA provenance attestation confirms integrity. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): CI/CD pipeline publishing multiple packages in sequence; consistent with automated release workflow. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): process.env spread into child fork options is standard Node.js subprocess pattern for this processor runner. | ai | |
| phantom-deps | phantom-dep:piscina | AI (phantom-deps): piscina is declared as a runtime dependency in package.json; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 4.3.4 | 1 / 3 | |
| 4.3.3 | 1 / 3 | |
| 4.3.2 | 1 / 3 | |
| 4.3.1 | 1 / 3 | |
| 4.3.0 | 1 / 3 | |
| 4.2.2 | 1 / 3 | |
| 4.2.1 | 1 / 3 | |
| 4.2.0 | 1 / 3 | |
| 4.1.0 | 1 / 3 | |
| 4.0.0 | 1 / 2 | |
| 3.8.1 | 1 / 2 | |
| 3.8.0 | 1 / 2 | |
| 3.7.0 | 1 / 2 | |
| 3.6.2 | 1 / 2 | |
| 3.6.1 | 1 / 2 | |
| 3.6.0 | 1 / 2 | |
| 3.5.0 | 1 / 2 | |
| 3.4.2 | 1 / 2 | |
| 3.4.1 | 1 / 2 | |
| 3.4.0 | 1 / 2 | |
| 3.3.0 | 1 / 2 | |
| 3.2.0 | 1 / 2 | |
| 3.1.0 | 1 / 2 | |
| 3.0.1 | 1 / 2 | |
| 3.0.0 | 1 / 2 | |
| 2.63.1 | 1 / 2 | |
| 2.63.0 | 1 / 2 | |
| 2.62.7 | 1 / 2 | |
| 2.62.6 | 1 / 2 |
v4.3.4
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.3
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.2
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.2
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.1.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.4.2
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-03-17. This could indicate a legitimate maintainer transition or an account compromise.
v3.4.1
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version was published by a different npm account than previous versions on 2026-03-17. This could indicate a legitimate maintainer transition or an account compromise.
v3.4.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.2.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.1.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.62.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.62.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.