@super-protocol/addons-tee
The TEE trusted loader addons
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/proto/AmdSevSnp.js | AI (source-diff): protoc-generated file, not true obfuscation. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process used for libc detection, not hostile exec. | ai | |
| source-diff | obfuscated-file:dist/tee-native-module/dcap-quote-verify.service.js | AI (source-diff): Standard tsc/webpack compiled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/tee-native-module/sev-snp-mrenclave.js | AI (source-diff): Standard compiled TS output. | ai | |
| source-diff | obfuscated-file:dist/tee-native-module/sev-snp.js | AI (source-diff): Standard compiled TS output. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): TEE attestation package legitimately bundles SGX/SEV/TDX native binaries. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): execSync used only for musl/ldd detection, not arbitrary exec. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): NVIDIA native binding postinstall is documented and consistent across this package's history. | ai | |
| phantom-deps | phantom-dep:msgpack5 | AI (phantom-deps): Declared dep used in config/type references; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:p-queue | AI (phantom-deps): Declared dep used in config/type references; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:asn1-tree | AI (phantom-deps): Declared dep used in config/type references; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:node-forge | AI (phantom-deps): Declared dep used in config/type references; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@sinclair/typebox | AI (phantom-deps): Declared dep used in config/type references; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@super-protocol/eslint-config-typescript | AI (phantom-deps): Same-org scoped package; stable false positive. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 4.1.0 | 6 / 7 | |
| 2.0.0 | 6 / 10 | |
| 1.1.1 | 5 / 9 | |
| 1.1.0 | 5 / 9 | |
| 1.0.0 | 6 / 10 | |
| 0.9.9 | 5 / 10 |
v4.1.0
5 findingsPackage contains compiled binaries that could be backdoors: • bindings/go-tdx-attest-wrapper/go-tdx-attest-wrapper • bindings/utils/virtee/snpguest • bindings/intel-native/build/Release/libsgx_dcap_quoteverify.so.1 • bindings/intel-native/build/Release/libtdx_attest.so.1 • bindings/amd-sev-snp-napi-rs/amd-sev-snp-napi-rs.linux-x64-gnu.node • bindings/intel-native/build/Release/intel_native.node
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.1
7 findingsPackage contains compiled binaries that could be backdoors: • bindings/utils/virtee/snpguest • bindings/sgx-native/build/Release/libsgx_dcap_quoteverify.so.1 • bindings/sgx-native/build/Release/libtdx_attest.so.1 • bindings/sgx-native/build/Release/libmbedcrypto_gramine.so.15 • bindings/sgx-native/build/Release/libmbedx509_gramine.so.6 • bindings/amd-sev-snp-napi-rs/amd-sev-snp-napi-rs.linux-x64-gnu.node • bindings/sgx-native/build/Release/sgx_native.node • bindings/utils/virtee/libsev.so
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
7 findingsPackage contains compiled binaries that could be backdoors: • bindings/utils/virtee/snpguest • bindings/sgx-native/build/Release/libsgx_dcap_quoteverify.so.1 • bindings/sgx-native/build/Release/libtdx_attest.so.1 • bindings/sgx-native/build/Release/libmbedcrypto_gramine.so.15 • bindings/sgx-native/build/Release/libmbedx509_gramine.so.6 • bindings/amd-sev-snp-napi-rs/amd-sev-snp-napi-rs.linux-x64-gnu.node • bindings/sgx-native/build/Release/sgx_native.node • bindings/utils/virtee/libsev.so
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.9
2 findingsPackage contains compiled binaries that could be backdoors: • bindings/utils/virtee/snpguest • bindings/sgx-native/build/Release/libsgx_dcap_quoteverify.so.1 • bindings/sgx-native/build/Release/libtdx_attest.so.1 • bindings/sgx-native/build/Release/libmbedcrypto_gramine.so.15 • bindings/sgx-native/build/Release/libmbedx509_gramine.so.6 • bindings/amd-sev-snp-napi-rs/amd-sev-snp-napi-rs.linux-x64-gnu.node • bindings/sgx-native/build/Release/sgx_native.node • bindings/utils/virtee/libsev.so
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.