@sisense/sdk-ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/apply-styled-options-to-query-Dl8vVNxo.cjs | AI (source-diff): Minified bundler output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-CyWQaInf.cjs | AI (source-diff): Bundled widget chunk. | ai | |
| source-diff | net-exec-file:dist/utils-L-HO2pCd.js | AI (source-diff): Bundled utils chunk, dual-use capability only. | ai | |
| source-diff | obfuscated-file:dist/utils-L-HO2pCd.js | AI (source-diff): Bundled utils chunk. | ai | |
| source-diff | net-exec-file:dist/utils-Cpeyj9TN.cjs | AI (source-diff): Bundled utils chunk, dual-use capability only. | ai | |
| source-diff | obfuscated-file:dist/utils-Cpeyj9TN.cjs | AI (source-diff): Bundled utils chunk. | ai | |
| source-diff | net-exec-file:dist/quota-notification-gYE6PTWA.cjs | AI (source-diff): Bundled chunk; no exfil target found. | ai | |
| source-diff | obfuscated-file:dist/quota-notification-gYE6PTWA.cjs | AI (source-diff): Bundled cjs output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/quota-notification-DqabeDbO.js | AI (source-diff): Bundled chunk; capability, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/quota-notification-DqabeDbO.js | AI (source-diff): Vite bundle chunk, standard minification. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-Dl8vVNxo.cjs | AI (source-diff): Bundled chunk; no malicious destination in sample. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-BK1NnV4P.js | AI (source-diff): Bundled Vite chunk; fetch+dynamic code is normal app logic, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-DHOhho50.js | AI (source-diff): Bundled build chunk, no malicious net+exec behavior. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-8MsC7-0N.js | AI (source-diff): Bundled build chunk, no malicious net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-8MsC7-0N.js | AI (source-diff): Bundled/minified vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/execute-query-k_ytd_Rf.cjs | AI (source-diff): Bundled build chunk, no malicious net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/execute-query-k_ytd_Rf.cjs | AI (source-diff): Bundled/minified vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/execute-query-D1JOjJ8n.js | AI (source-diff): Bundled build chunk, no malicious net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/dimensions-CtINdhqK.cjs | AI (source-diff): Bundled/minified vite output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-DlP4xqST.cjs | AI (source-diff): Bundled/minified vite output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-DHOhho50.js | AI (source-diff): Bundled/minified vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-0J_WPLDy.cjs | AI (source-diff): Bundled build chunk containing standard fetch/i18n code, no malicious net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-0J_WPLDy.cjs | AI (source-diff): Bundled/minified vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-DlP4xqST.cjs | AI (source-diff): Bundled build chunk, no malicious net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-DBwcb3ao.cjs | AI (source-diff): Bundled/minified vite output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-BhFFlOqU.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-BGLYpqmt.cjs | AI (source-diff): Bundled build output, not malicious. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-BGLYpqmt.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-BhFFlOqU.js | AI (source-diff): Bundled build output, not malicious. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-CkQznSEt.cjs | AI (source-diff): Bundled output false-positive. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-CkQznSEt.cjs | AI (source-diff): Bundled output, not obfuscation. | ai | |
| phantom-deps | phantom-dep:guid-typescript | AI (phantom-deps): Declared but indirectly used; consistent with other accepted phantom deps. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-CxoO7TzT.js | AI (source-diff): Bundled output false-positive. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-CxoO7TzT.js | AI (source-diff): Bundled output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/dimensions-X4_igtmO.cjs | AI (source-diff): Minified vite/rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/execute-query-DJDE0zRU.cjs | AI (source-diff): Same bundled query logic in cjs form. | ai | |
| source-diff | net-exec-file:dist/execute-query-BEeqqDl6.js | AI (source-diff): Bundled query-execution code calling package's own API, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-NyouhE_A.cjs | AI (source-diff): Minified bundle output for UI strings/logic. | ai | |
| source-diff | obfuscated-file:dist/execute-query-DJDE0zRU.cjs | AI (source-diff): Minified bundle (i18next etc.), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-Cps0frVZ.cjs | AI (source-diff): Bundled build artifact. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): First-party @sisense/sdk-* packages pinned to same version. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-Db1VFZvT.js | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-Cps0frVZ.cjs | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-Db1VFZvT.js | AI (source-diff): Bundled build artifact. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-DLwnWblo.js | AI (source-diff): fetch+dynamic code in bundled query-execution chunk, matches stated function. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-BaOTPn5w.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-DOn2HdBv.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-DOn2HdBv.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-CCeRLdGB.js | AI (source-diff): Bundled build output, no unrelated destination. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-CCeRLdGB.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/execute-query-CFK2R_1S.js | AI (source-diff): Same as above, ESM variant. | ai | |
| source-diff | net-exec-file:dist/execute-query-CB4XfUng.cjs | AI (source-diff): Query execution module fetching data is the package's stated purpose. | ai | |
| source-diff | obfuscated-file:dist/execute-query-CB4XfUng.cjs | AI (source-diff): Bundled build output, core SDK query logic. | ai | |
| source-diff | obfuscated-file:dist/dimensions-BUWtZxix.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-d7eaC45K.cjs | AI (source-diff): Same bundled chunk, no unrelated destination. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-d7eaC45K.cjs | AI (source-diff): Bundled CJS output mirroring ESM chunk. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-DLwnWblo.js | AI (source-diff): Bundled Vite/Rollup output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-YqBj1IAH.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/execute-query-tRu-NooT.cjs | AI (source-diff): Query-execution module; network calls are the stated function. | ai | |
| source-diff | obfuscated-file:dist/execute-query-tRu-NooT.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/execute-query-CUf3Nz7H.js | AI (source-diff): Query-execution module; network calls are the stated function. | ai | |
| source-diff | obfuscated-file:dist/dimensions-_D0C3KY2.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-C3PTAfzX.cjs | AI (source-diff): Bundled fetch/query client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-C3PTAfzX.cjs | AI (source-diff): CJS build output of same bundle. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-BEjUaaLD.js | AI (source-diff): Bundled fetch/query client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-BEjUaaLD.js | AI (source-diff): Vite/esbuild bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-34N34d-K.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-DsBF8OC2.cjs | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-34N34d-K.cjs | AI (source-diff): Bundled fetch/query client code. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-YqBj1IAH.js | AI (source-diff): Bundled fetch/query client code. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-Bh4KYWy_.cjs | AI (source-diff): Bundled output. | ai | |
| source-diff | net-exec-file:dist/execute-query-l7jejslh.js | AI (source-diff): Bundled SDK query client code. | ai | |
| source-diff | net-exec-file:dist/execute-query-CdhSHTTA.cjs | AI (source-diff): Bundled SDK query client code. | ai | |
| source-diff | obfuscated-file:dist/execute-query-CdhSHTTA.cjs | AI (source-diff): Bundled output. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-B_cR1yhw.cjs | AI (source-diff): Vite/esbuild bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-B_cR1yhw.cjs | AI (source-diff): Bundled library code, network calls are legitimate SDK API usage. | ai | |
| source-diff | obfuscated-file:dist/derive-chart-family-DkuTQGOE.js | AI (source-diff): Vite/esbuild bundled output. | ai | |
| source-diff | net-exec-file:dist/derive-chart-family-DkuTQGOE.js | AI (source-diff): Bundled library code, not dropper malware. | ai | |
| source-diff | obfuscated-file:dist/dimensions-DI9h9IJH.cjs | AI (source-diff): Bundled output. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-BzzTf8UH.cjs | AI (source-diff): Bundled output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-D5yiZCTg.js | AI (source-diff): Bundled output. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-D5yiZCTg.js | AI (source-diff): Bundled output. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-Bh4KYWy_.cjs | AI (source-diff): Bundled output. | ai | |
| source-diff | net-exec-file:dist/execute-query-CHYTupEo.js | AI (source-diff): Bundled query-execution module; network calls are the package's stated function. | ai | |
| source-diff | obfuscated-file:dist/dimensions-2t18RSZC.cjs | AI (source-diff): Bundled/minified vite output, not obfuscation; matches package's build pattern. | ai | |
| source-diff | obfuscated-file:dist/execute-query-DmAyVFF5.cjs | AI (source-diff): Minified bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/execute-query-DmAyVFF5.cjs | AI (source-diff): Bundled query-execution module; expected network+exec pattern for this SDK. | ai | |
| source-diff | obfuscated-file:dist/index-Dx6wvLd3.cjs | AI (source-diff): Minified bundle (i18next/error strings), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-BrP6xVFh.cjs | AI (source-diff): Same bundled chunk as .js counterpart, benign library code. | ai | |
| source-diff | obfuscated-file:dist/apply-styled-options-to-query-BrP6xVFh.cjs | AI (source-diff): Minified bundler output, not true obfuscation signature. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-BddNnNsW.js | AI (source-diff): Bundled vite chunk (i18next/date-fns), no fetched-binary or exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/index-DhUTJSni.cjs | AI (source-diff): Minified date-fns bundle, standard build output. | ai | |
| source-diff | obfuscated-file:dist/index-DTvxJdqZ.cjs | AI (source-diff): Minified bundle of package's own i18n/error strings, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-BXDqo_yg.js | AI (source-diff): Minified bundle output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-DBqRT0et.js | AI (source-diff): Bundled UI hook module. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-DBqRT0et.js | AI (source-diff): Minified bundle output. | ai | |
| source-diff | net-exec-file:dist/use-common-filters-CXJN3RSs.cjs | AI (source-diff): Bundled UI hook module. | ai | |
| source-diff | obfuscated-file:dist/use-common-filters-CXJN3RSs.cjs | AI (source-diff): Minified bundle output. | ai | |
| source-diff | net-exec-file:dist/execute-query-BIkhszY1.cjs | AI (source-diff): Bundled query-execution module, expected network+exec pattern for this SDK. | ai | |
| source-diff | obfuscated-file:dist/execute-query-BIkhszY1.cjs | AI (source-diff): Minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/dimensions-DVGn8ORR.cjs | AI (source-diff): Minified Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/execute-query-B21bnb05.js | AI (source-diff): Bundled query-execution module; network calls are the package's own API client, not exfil. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-DgCWcMJ1.cjs | AI (source-diff): Minified bundle output. | ai | |
| source-diff | net-exec-file:dist/utils-DH69_bUK.cjs | AI (source-diff): Bundled utils, expected pattern. | ai | |
| source-diff | obfuscated-file:dist/utils-DH69_bUK.cjs | AI (source-diff): Minified bundle output. | ai | |
| source-diff | net-exec-file:dist/utils-BXDqo_yg.js | AI (source-diff): Bundled utils, expected pattern. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-23D9br-S.cjs | AI (source-diff): Network calls and dynamic code are part of the SDK's legitimate query/fetch logic, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-BagjzMqm.js | AI (source-diff): ESM counterpart bundle; same legitimate SDK patterns. | ai | |
| source-diff | obfuscated-file:dist/dimensions-D8r34WRI.cjs | AI (source-diff): Minified dimensions bundle; content shows DimensionalElement SDK code. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-C72Io-3c.cjs | AI (source-diff): Minified widget-composer bundle; standard build artifact. | ai | |
| source-diff | net-exec-file:dist/utils-CsV-iYtb.js | AI (source-diff): Legitimate SDK patterns in ESM utils bundle. | ai | |
| source-diff | obfuscated-file:dist/utils-CsV-iYtb.js | AI (source-diff): ESM utils bundle; standard Vite output. | ai | |
| source-diff | net-exec-file:dist/utils-BwGnDoB0.cjs | AI (source-diff): Legitimate SDK patterns in utils bundle. | ai | |
| source-diff | obfuscated-file:dist/utils-BwGnDoB0.cjs | AI (source-diff): Minified utils bundle; standard build artifact. | ai | |
| source-diff | net-exec-file:dist/use-hover-CaSOzp0i.cjs | AI (source-diff): Legitimate SDK patterns in CJS bundle. | ai | |
| source-diff | obfuscated-file:dist/use-hover-CaSOzp0i.cjs | AI (source-diff): CJS counterpart of the same Vite bundle; standard minification. | ai | |
| source-diff | net-exec-file:dist/use-hover-B6VmMb06.js | AI (source-diff): Legitimate SDK network/execution patterns in bundled output. | ai | |
| source-diff | obfuscated-file:dist/use-hover-B6VmMb06.js | AI (source-diff): Minified Vite bundle chunk; content is recognizable React/Highcharts SDK code. | ai | |
| source-diff | obfuscated-file:dist/apply-styled-options-to-query-23D9br-S.cjs | AI (source-diff): Standard Vite/Rollup minified bundle output for this SDK; not malicious obfuscation. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-CaP4IMrQ.js | AI (source-diff): Standard Vite-bundled UI library output; network calls are fetch/HTTP client code, not dropper behavior. | ai | |
| phantom-deps | phantom-dep:hash-it | AI (phantom-deps): Newly added runtime dep; phantom-dep heuristic fires because it's bundled rather than directly imported at top level. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large UI library with many bundled chunks; 62 new files consistent with Vite code-splitting refactor. | ai | |
| source-diff | obfuscated-file:dist/index-C9G8giSk.cjs | AI (source-diff): Minified Vite/Rollup bundle; content is Sisense SDK error strings and standard React code. | ai | |
| source-diff | obfuscated-file:dist/apply-styled-options-to-query-D5D8pRl2.cjs | AI (source-diff): Minified Vite/Rollup output; long lines are expected for bundled UI library code. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-D5D8pRl2.cjs | AI (source-diff): CJS counterpart of the same Vite bundle; same rationale as the ESM file. | ai | |
| source-diff | obfuscated-file:dist/widget-composer-CZ0_bPXK.cjs | AI (source-diff): Minified CJS chunk; consistent with SDK build output. | ai | |
| source-diff | obfuscated-file:dist/utils-Db3U6oHa.js | AI (source-diff): Minified ESM utils chunk from Vite build pipeline. | ai | |
| source-diff | net-exec-file:dist/utils-DM5vp1gw.cjs | AI (source-diff): Bundled fetch + async generator pattern; consistent with SDK utilities. | ai | |
| source-diff | obfuscated-file:dist/utils-DM5vp1gw.cjs | AI (source-diff): Minified CJS utils chunk from Vite build pipeline. | ai | |
| source-diff | net-exec-file:dist/use-hover-D_mBUhp9.cjs | AI (source-diff): Bundled fetch + async generator; no malicious indicators. | ai | |
| source-diff | obfuscated-file:dist/use-hover-D_mBUhp9.cjs | AI (source-diff): Minified CJS chunk; content is React/i18n/Sisense SDK code. | ai | |
| source-diff | net-exec-file:dist/use-hover-CkmV6eu9.js | AI (source-diff): Bundled fetch + async generator pattern; no exfiltration or shell execution. | ai | |
| source-diff | obfuscated-file:dist/use-hover-CkmV6eu9.js | AI (source-diff): Minified ESM chunk; content is React hook and chart component code. | ai | |
| source-diff | obfuscated-file:dist/dimensions-huCJK0y6.cjs | AI (source-diff): Minified CJS chunk from Vite build; content is Sisense dimensional model code. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-k10gkPCG.cjs | AI (source-diff): Same as ESM counterpart; bundled fetch + async generator, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/apply-styled-options-to-query-BzMAmDnD.js | AI (source-diff): Network calls are Sisense API fetches; dynamic execution is async generator pattern from bundler output. | ai | |
| source-diff | obfuscated-file:dist/apply-styled-options-to-query-k10gkPCG.cjs | AI (source-diff): Standard Vite minified CJS build chunk; consistent with SDK build pipeline. | ai | |
| source-diff | net-exec-file:dist/utils-Db3U6oHa.js | AI (source-diff): Bundled fetch + async generator; no malicious indicators. | ai | |
| phantom-deps | phantom-dep:highcharts-react-official | AI (phantom-deps): UI SDK pattern; re-exported for consumer convenience. | ai | |
| phantom-deps | phantom-dep:react-error-boundary | AI (phantom-deps): UI SDK pattern; re-exported for consumer convenience. | ai | |
| phantom-deps | phantom-dep:react-number-format | AI (phantom-deps): UI SDK pattern; re-exported for consumer convenience. | ai | |
| phantom-deps | phantom-dep:@mui/icons-material | AI (phantom-deps): UI SDK pattern; MUI icons imported indirectly through component exports. | ai | |
| phantom-deps | phantom-dep:highcharts-rounded-corners | AI (phantom-deps): UI SDK pattern; re-exported for consumer convenience. | ai | |
| phantom-deps | phantom-dep:immer | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Large monorepo bundle; phantom-dep heuristic fires on bundled/re-exported deps, stable false positive. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:fixed-data-table-2 | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/utilities | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@dnd-kit/modifiers | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:markdown-to-jsx | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@emotion/cache | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:react-i18next | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:whatwg-fetch | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:ts-deepmerge | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:proj4leaflet | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:date-fns-tz | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:@mui/system | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:classnames | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash-es | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:deepmerge | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Same monorepo bundle pattern; stable false positive. | ai |
Versions (showing 20 of 20)
| Version | Deps | Published |
|---|---|---|
| 2.31.0 | 47 / 52 | |
| 2.30.0 | 48 / 54 | |
| 2.29.0 | 48 / 54 | |
| 2.28.0 | 47 / 54 | |
| 2.27.0 | 47 / 54 | |
| 2.26.0 | 47 / 54 | |
| 2.25.0 | 47 / 54 | |
| 2.24.0 | 46 / 54 | |
| 2.23.0 | 46 / 54 | |
| 2.22.0 | 46 / 53 | |
| 2.21.0 | 45 / 53 | |
| 2.20.0 | 44 / 52 | |
| 2.19.0 | 44 / 51 | |
| 2.18.1 | 44 / 51 | |
| 2.18.0 | 44 / 51 | |
| 2.17.0 | 44 / 51 | |
| 2.16.1 | 43 / 51 | |
| 2.16.0 | 43 / 51 | |
| 2.15.0 | 43 / 52 | |
| 2.14.0 | 43 / 52 |
v2.31.0
6 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.0
14 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.21.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.19.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.1
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.1
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.