← Home

@syncular/console

Embeddable Syncular console UI

5
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

bkniffler

Keywords

syncoffline-firstrealtimeconsolereact

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:web-dist/assets/index-YZpERKzf.js AI (source-diff): Standard Vite-minified web bundle for an embeddable UI; not obfuscated, content matches declared deps. ai
source-diff obfuscated-file:web-dist/assets/index-CtCv6B8y.js AI (source-diff): Standard Vite-minified web bundle containing declared deps (React, Sentry, Recharts); not malicious obfuscation. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get in bundled React/Recharts code; stable false positive for this package's web bundle. ai
source-diff obfuscated-file:web-dist/assets/index-BvE-SDNP.js AI (source-diff): Standard Vite-minified bundle of declared deps (Sentry, React, recharts); not obfuscated malware. ai
phantom-deps phantom-dep:@sentry/react AI (phantom-deps): Used in config/runtime setup rather than direct import; stable false positive for this package. ai
phantom-deps phantom-dep:openapi-fetch AI (phantom-deps): Used via generated client wrappers; stable false positive for this package. ai
source-diff obfuscated-file:dist/pages/ClientDetails.js AI (source-diff): Readable compiled TypeScript/React; long lines from minified JSX output, not obfuscation. ai
source-diff obfuscated-file:dist/pages/Stream.js AI (source-diff): Same pattern — compiled React component with long lines, not obfuscated malicious code. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation; legitimate CI/CD transition. ai
npm-metadata suspicious-initial-version AI (npm-metadata): Entire @syncular monorepo uses 0.0.0 versioning consistently; not a throwaway package. ai

Versions (showing 5 of 5)

Version Deps Published
0.1.3 12 / 9
0.1.2 12 / 9
0.1.1 12 / 9
0.1.0 12 / 9
0.0.0 6 / 5

v0.1.3

2 findings
HIGH New obfuscated file: web-dist/assets/index-CtCv6B8y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.2

2 findings
HIGH New obfuscated file: web-dist/assets/index-YZpERKzf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.1

4 findings
HIGH Publisher changed: bkniffler → GitHub Actions (on 2026-06-30) provenance

This version was published by a different npm account than previous versions on 2026-06-30. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/pages/ClientDetails.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/pages/Stream.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.1.0

2 findings
HIGH New obfuscated file: web-dist/assets/index-BvE-SDNP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.