@superblocksteam/vite-plugin-file-sync
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-migration/references/yaml-block-mapping.generated.d.ts | AI (source-diff): Same pattern: generated TypeScript declaration exporting AI skill reference content as a string constant. | ai | |
| source-diff | obfuscated-file:dist/ai-service/test-utils/app-generation-mocks/orders-app.d.ts | AI (source-diff): Long lines are test mock strings containing readable TypeScript/JSON, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/third-party-migration/skill.generated.d.ts | AI (source-diff): Same pattern: generated .d.ts exporting a markdown string constant; plainly readable content. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-migration/skill.generated.d.ts | AI (source-diff): Same pattern: generated .d.ts exporting a markdown string constant; plainly readable content. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/third-party-migration/replit.generated.d.ts | AI (source-diff): Same pattern: generated .d.ts exporting a markdown string constant; plainly readable content. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/third-party-migration/lovable.generated.d.ts | AI (source-diff): Same pattern: generated .d.ts exporting a markdown string constant; plainly readable content. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-migration/references/focused-debug.generated.d.ts | AI (source-diff): Long-line .d.ts files are generated TypeScript declarations exporting readable markdown strings, not obfuscated code. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): zod is a declared runtime dep used in config/type validation; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/subprompts/full-examples.js | AI (source-diff): Auto-generated markdown-as-string export; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-components/DatePickerPropsDocs.js | AI (source-diff): Auto-generated markdown-as-string export; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-typedefs/EventFlow.js | AI (source-diff): Auto-generated markdown-as-string export; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-components/InputPropsDocs.d.ts | AI (source-diff): Auto-generated type declaration with markdown string; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/subprompts/full-examples.d.ts | AI (source-diff): Auto-generated type declaration with markdown string; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-typedefs/EventFlow.d.ts | AI (source-diff): Auto-generated type declaration with markdown string; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-components/DatePickerPropsDocs.d.ts | AI (source-diff): Auto-generated type declaration with markdown string; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-components/TextPropsDocs.js | AI (source-diff): Auto-generated markdown-as-string export; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-components/TablePropsDocs.js | AI (source-diff): Auto-generated markdown-as-string export; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompts/generated/library-components/InputPropsDocs.js | AI (source-diff): Auto-generated markdown-as-string export; long lines are string content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-frontend/skill.generated.d.ts | AI (source-diff): Generated .d.ts with long string literal containing markdown docs; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-api/skill.generated.d.ts | AI (source-diff): Generated .d.ts with long string literal containing markdown docs; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-api/references/sql-databases.generated.d.ts | AI (source-diff): Generated .d.ts with long string literal containing markdown docs; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompt-builder-service/static-fragments/platform-parts/system-incremental.js | AI (source-diff): Long-line content is an AI prompt string literal auto-generated from markdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompt-builder-service/static-fragments/platform-parts/system-specific-edit.d.ts | AI (source-diff): Type declaration for an AI prompt string; long line is the prompt content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompt-builder-service/static-fragments/platform-parts/system-incremental.d.ts | AI (source-diff): Type declaration for an AI prompt string; long line is the prompt content, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompt-builder-service/static-fragments/platform-parts/system-specific-edit.js | AI (source-diff): Long-line content is an AI prompt string literal auto-generated from markdown; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ai-service/prompt-builder-service/static-fragments/platform-parts/superblocks-theming-chakra-new.js | AI (source-diff): Long lines are embedded markdown documentation strings (AI prompts), not obfuscated code. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:dist/ai-service/agent/apis-system-prompt.d.ts | AI (source-diff): Long lines are embedded AI system prompt strings in a .d.ts declaration file, not obfuscated executable code. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 260 new files correspond to the new ai-service module; consistent with feature expansion, not injection. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New deps (tar, tokenlens, @babel/types, etc.) are all reputable packages matching the new AI service feature. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are within the same Superblocks org; consistent with team growth. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-frontend/references/embedding.generated.d.ts | AI (source-diff): Long-line .d.ts files export markdown documentation strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-api/references/graphql.generated.d.ts | AI (source-diff): Long-line .d.ts files export markdown documentation strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-api/references/rest-apis.generated.d.ts | AI (source-diff): Long-line .d.ts files export markdown documentation strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/superblocks-api/references/code-blocks.generated.d.ts | AI (source-diff): Long-line .d.ts files export markdown documentation strings; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/ai-service/skills/system/third-party-migration/claude-design.generated.d.ts | AI (source-diff): Long lines are markdown documentation embedded as a string literal in a generated .d.ts file, not obfuscated code. | ai | |
| phantom-deps | phantom-dep:@babel/core | AI (phantom-deps): Framework-scoped, loaded by convention in build tooling. | ai | |
| phantom-deps | phantom-dep:lucide-static | AI (phantom-deps): Config-referenced; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/turndown | AI (phantom-deps): Type-only dep; not directly imported at runtime by design. | ai | |
| phantom-deps | phantom-dep:eventsource-parser | AI (phantom-deps): Config-referenced; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:lru-cache | AI (phantom-deps): Config-referenced dep in a build tool; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@superblocksteam/linter | AI (phantom-deps): Same-org sibling dep; stable false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:tokenlens | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:winston | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:acorn | AI (phantom-deps): Monorepo build tool; phantom-dep heuristic fires on config-referenced deps, stable false positive. | ai | |
| phantom-deps | phantom-dep:ignore | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/api-logs | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@anthropic-ai/tokenizer | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@lezer/common | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:path-to-regexp | AI (phantom-deps): Same monorepo pattern; stable false positive for this package. | ai |
Versions (showing 100 of 136)
| Version | Deps | Published |
|---|---|---|
| 2.0.141 | 50 / 43 | |
| 2.0.140 | 50 / 43 | |
| 2.0.139 | 49 / 43 | |
| 2.0.138 | 49 / 43 | |
| 2.0.137 | 49 / 43 | |
| 2.0.136 | 49 / 43 | |
| 2.0.135 | 49 / 43 | |
| 2.0.134 | 49 / 43 | |
| 2.0.133 | 49 / 43 | |
| 2.0.132 | 49 / 43 | |
| 2.0.131 | 49 / 43 | |
| 2.0.130 | 49 / 43 | |
| 2.0.129 | 49 / 43 | |
| 2.0.128 | 49 / 43 | |
| 2.0.127 | 49 / 43 | |
| 2.0.126 | 49 / 43 | |
| 2.0.125 | 49 / 43 | |
| 2.0.124 | 49 / 43 | |
| 2.0.123 | 46 / 40 | |
| 2.0.122 | 46 / 40 | |
| 2.0.121 | 46 / 40 | |
| 2.0.120 | 46 / 40 | |
| 2.0.119 | 46 / 39 | |
| 2.0.118 | 46 / 39 | |
| 2.0.117 | 46 / 39 | |
| 2.0.116 | 46 / 39 | |
| 2.0.115 | 46 / 39 | |
| 2.0.114 | 45 / 39 | |
| 2.0.113 | 45 / 39 | |
| 2.0.112 | 45 / 39 | |
| 2.0.111 | 45 / 39 | |
| 2.0.110 | 45 / 39 | |
| 2.0.109 | 45 / 39 | |
| 2.0.108 | 45 / 39 | |
| 2.0.107 | 45 / 39 | |
| 2.0.106 | 45 / 39 | |
| 2.0.105 | 45 / 39 | |
| 2.0.104 | 45 / 39 | |
| 2.0.103 | 45 / 38 | |
| 2.0.102 | 44 / 38 | |
| 2.0.101 | 44 / 38 | |
| 2.0.100 | 44 / 38 | |
| 2.0.99 | 44 / 38 | |
| 2.0.98 | 44 / 38 | |
| 2.0.97 | 44 / 38 | |
| 2.0.96 | 43 / 38 | |
| 2.0.95 | 43 / 38 | |
| 2.0.94 | 43 / 38 | |
| 2.0.93 | 42 / 38 | |
| 2.0.92 | 42 / 37 | |
| 2.0.91 | 42 / 37 | |
| 2.0.90 | 42 / 37 | |
| 2.0.89 | 40 / 35 | |
| 2.0.88 | 40 / 35 | |
| 2.0.87 | 40 / 35 | |
| 2.0.86 | 40 / 29 | |
| 2.0.85 | 40 / 29 | |
| 2.0.84 | 40 / 29 | |
| 2.0.83 | 39 / 28 | |
| 2.0.82 | 39 / 28 | |
| 2.0.81 | 39 / 28 | |
| 2.0.80 | 49 / 35 | |
| 2.0.79 | 49 / 35 | |
| 2.0.78 | 49 / 35 | |
| 2.0.77 | 46 / 33 | |
| 2.0.76 | 46 / 32 | |
| 2.0.75 | 46 / 32 | |
| 2.0.74 | 46 / 32 | |
| 2.0.73 | 46 / 32 | |
| 2.0.72 | 46 / 32 | |
| 2.0.71 | 46 / 32 | |
| 2.0.70 | 46 / 32 | |
| 2.0.69 | 46 / 32 | |
| 2.0.68 | 46 / 32 | |
| 2.0.67 | 46 / 31 | |
| 2.0.66 | 46 / 31 | |
| 2.0.65 | 46 / 31 | |
| 2.0.64 | 46 / 31 | |
| 2.0.63 | 46 / 31 | |
| 2.0.62 | 46 / 31 | |
| 2.0.61 | 46 / 31 | |
| 2.0.60 | 46 / 31 | |
| 2.0.59 | 46 / 31 | |
| 2.0.58 | 46 / 31 | |
| 2.0.57 | 46 / 31 | |
| 2.0.56 | 46 / 31 | |
| 2.0.55 | 45 / 31 | |
| 2.0.54 | 45 / 31 | |
| 2.0.53 | 45 / 31 | |
| 2.0.52 | 45 / 31 | |
| 2.0.51 | 45 / 31 | |
| 2.0.50 | 45 / 31 | |
| 2.0.49 | 45 / 31 | |
| 2.0.42 | 43 / 32 | |
| 2.0.41 | 43 / 32 | |
| 2.0.40 | 41 / 32 | |
| 2.0.39 | 41 / 32 | |
| 2.0.38 | 41 / 32 | |
| 2.0.37 | 41 / 32 | |
| 2.0.36 | 41 / 32 |
v2.0.141
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.140
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.139
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.138
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.137
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.136
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.100
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.99
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.98
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.97
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.96
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.95
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.94
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.93
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.92
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.91
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.90
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.