@superblocksteam/cli
Official Superblocks CLI
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@oclif/plugin-plugins | AI (phantom-deps): oclif plugin loaded via oclif config, not direct import. | ai | |
| phantom-deps | phantom-dep:vite-plugin-inspect | AI (phantom-deps): Used via vite config, not direct import. | ai | |
| dependencies | unvetted-dep:@superblocksteam/vite-custom-component-reload-plugin | AI (dependencies): First-party Superblocks sibling package, version-pinned. | ai | |
| dependencies | unvetted-dep:@superblocksteam/react-shim | AI (dependencies): First-party Superblocks sibling package, version-pinned. | ai | |
| dependencies | unvetted-dep:@superblocksteam/css-plugin | AI (dependencies): First-party Superblocks sibling package, version-pinned. | ai | |
| source-diff | obfuscated-file:dist/glimmer-QDMNGQII.js | AI (source-diff): Bundled vendored prettier plugin, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/html-B22LWR6T.js | AI (source-diff): Bundled vendored prettier plugin, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/markdown-OFVHZSS7.js | AI (source-diff): Bundled vendored prettier plugin, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/meriyah-SWKOTMS4.js | AI (source-diff): Bundled vendored parser dep, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/typescript-RMZJBBSY.js | AI (source-diff): Bundled vendored typescript compiler, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-RW5VI4GE.js | AI (source-diff): Bundled fs-extra/universalify utility code, no malicious network+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/jiti-4OGTST45.js | AI (source-diff): Bundled webpack output of vendored jiti dep. | ai | |
| source-diff | obfuscated-file:dist/acorn-M6MAFGXP.js | AI (source-diff): Bundled vendored prettier plugin, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/babel-KLOMDQFX.js | AI (source-diff): Bundled vendored prettier plugin, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/flow-GWFKYCP4.js | AI (source-diff): Bundled vendored prettier plugin, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/estree-HWVA5PPX.js | AI (source-diff): Bundled vendored prettier plugin, not obfuscation. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Preinstall is a Node.js version check only; no network access or arbitrary code execution. | ai | |
| phantom-deps | phantom-dep:@oclif/plugin-help | AI (phantom-deps): @oclif/plugin-help is referenced in oclif config (plugins array); phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): axios is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped package from established superblocksteam org; Levenshtein match to 'joi' is a false positive. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 2.0.77 | 12 / 39 | |
| 1.14.4 | 16 / 27 | |
| 1.14.3 | 16 / 27 | |
| 1.14.2 | 16 / 27 | |
| 1.14.0 | 16 / 27 | |
| 1.7.0 | 20 / 21 |
v2.0.77
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.