@syngrisi/syngrisi
Syngrisi - Visual Testing Tool
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-BWQlt1Vy.js | AI (source-diff): Vite-bundled React asset; source maps present; no obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/LogicalGroup-CfD-lAqZ.js | AI (source-diff): Vite-bundled React asset; source maps present; no obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-DlfD1_U0.js | AI (source-diff): Vite-bundled root bundle confirmed by __vite__mapDeps banner; source maps present. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-DnBkR_xn.js | AI (source-diff): Vite-bundled React asset; source maps present; no obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-ot3xAPN9.js | AI (source-diff): Vite-bundled React asset; source maps present; no obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-C6bit5Bb.js | AI (source-diff): Vite-bundled React frontend asset; minified ESM, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-CGvz4L62.js | AI (source-diff): Vite-bundled React frontend asset; minified ESM, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-BJk8Fw7_.js | AI (source-diff): Vite-bundled React frontend asset; minified ESM, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-CWgeJNvi.js | AI (source-diff): Vite-bundled React frontend asset with explicit vite banner; minified ESM, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-DHMdMUK0.js | AI (source-diff): Vite bundle; readable React query and routing patterns confirm build output. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-BrYw7YnR.js | AI (source-diff): __vite__mapDeps preamble explicitly identifies this as a Vite bundle entry point. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-CEnvFAqh.js | AI (source-diff): Standard Vite-bundled React output; ESM imports and readable component names confirm bundled, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-DU_1LKLU.js | AI (source-diff): Vite bundle; readable component/icon names confirm build output. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-iwU6Md3Q.js | AI (source-diff): Vite-bundled React output; long lines are minified ESM, not obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/use-form-BUOqQ-6C.js | AI (source-diff): Vite-bundled React output; long lines are minified ESM, not obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-BmFiC17-.js | AI (source-diff): Vite-bundled React output with __vite__mapDeps banner; standard build artifact. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/LogicalGroup-4dw9WJlz.js | AI (source-diff): Vite-bundled React output; long lines are minified ESM, not obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/http-BTrAqpfD.js | AI (source-diff): Vite-bundled React/library bundle with sourcemap; standard build artifact. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-1yRPEW3P.js | AI (source-diff): Vite-bundled React output; long lines are minified ESM, not obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-D71uMcr0.js | AI (source-diff): Vite-bundled React output; long lines are minified ESM, not obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/auth-CTKKMKlG.js | AI (source-diff): Vite-bundled React output; long lines are minified ESM, not obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-DtbhhAjt.js | AI (source-diff): Standard Vite/ESM bundle output; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-CinOqS9u.js | AI (source-diff): Standard Vite/ESM bundle output with sourcemap; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-BHDbOBSK.js | AI (source-diff): Vite-bundled React output; sourcemap present. | ai | |
| source-diff | encoded-string-file:dist/server/routes/v1/baselines.route.js | AI (source-diff): Normal TypeScript compilation output; no exfil behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-BegN3Ycq.js | AI (source-diff): Vite-bundled React output; sourcemap present, readable identifiers, not true obfuscation. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-CEOBeomU.js | AI (source-diff): Vite-bundled React output with __vite__mapDeps banner; sourcemap present. | ai | |
| source-diff | encoded-string-file:dist/server/routes/ui/admin.js | AI (source-diff): Same pattern; no exfiltration target or hostile behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-DjZloDVH.js | AI (source-diff): Vite build output confirmed by __vite__mapDeps banner; stable pattern for this UI-serving package. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/http-Bevb7X_W.js | AI (source-diff): Vite-bundled React/library chunk; source maps shipped alongside. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-B75SHiJE.js | AI (source-diff): Vite-bundled React UI chunk; no malicious behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/auth-Cu2BjBbU.js | AI (source-diff): Vite-bundled React UI chunk; no malicious behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-BkbbPZdx.js | AI (source-diff): Vite-bundled React UI chunk; no malicious behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-COkZnVZw.js | AI (source-diff): Vite-bundled React UI chunk; no malicious behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/LogicalGroup-DSdSpgA9.js | AI (source-diff): Vite-bundled React UI chunk; no malicious behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/use-form-BvT2Zn9f.js | AI (source-diff): Vite-bundled React UI chunk; no malicious behavior. | ai | |
| source-diff | encoded-string-file:dist/server/routes/v1/admin-data.route.js | AI (source-diff): Long strings in Express route files are typical OpenAPI/Swagger spec literals in this server package. | ai | |
| source-diff | encoded-string-file:dist/server/routes/ai.route.js | AI (source-diff): Same pattern; no exfiltration target or hostile behavior. | ai | |
| source-diff | encoded-string-file:dist/server/app.js | AI (source-diff): Same pattern; no exfiltration target or hostile behavior. | ai | |
| source-diff | encoded-string-file:dist/server/routes/v1/app.route.js | AI (source-diff): Same pattern; no exfiltration target or hostile behavior. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-HlnZwB0O.js | AI (source-diff): Vite-bundled React output with source maps; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/use-form-BQHvpeRo.js | AI (source-diff): Vite-bundled React output with source maps; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-DDNQ_qnD.js | AI (source-diff): Vite-bundled React output with __vite__mapDeps banner; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/LogicalGroup-DabLQWX5.js | AI (source-diff): Vite-bundled React output with source maps; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/http-BFQnkr_N.js | AI (source-diff): Vite-bundled React/library bundle with source maps; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-B8Zq92xQ.js | AI (source-diff): Vite-bundled React output with source maps; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-CYX50Hqy.js | AI (source-diff): Vite-bundled React output with source maps; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/auth-BXsSkTTQ.js | AI (source-diff): Vite-bundled React output with source maps; not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/auth-DP7XsPLL.js | AI (source-diff): Vite-bundled React output; minified ES module imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/use-form-KNXb_kPI.js | AI (source-diff): Vite-bundled React output; minified ES module imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/root-Od9EcQSe.js | AI (source-diff): Vite root bundle with __vite__mapDeps preamble; standard build artifact. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/LogicalGroup-BUgotl6i.js | AI (source-diff): Vite-bundled React output; minified ES module imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/http-CpGhdiV4.js | AI (source-diff): Vite-bundled React/library bundle; standard minified output with source map. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/ChecksList-BIMtAjB8.js | AI (source-diff): Vite-bundled React output; minified ES module imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/CheckDetails-DAoqdV9x.js | AI (source-diff): Vite-bundled React output; minified ES module imports, not obfuscated. | ai | |
| source-diff | obfuscated-file:mvc/views/react/assets/admin-BInDlTd3.js | AI (source-diff): Vite-bundled React output; minified ES module imports, not obfuscated. | ai | |
| semgrep | semgrep:toplevel-fetch | AI (semgrep): Fires in minified React asset bundle; expected HTTP client code in bundled frontend. | ai | |
| phantom-deps | phantom-dep:bson | AI (phantom-deps): Transitive dep via MongoDB stack; not directly imported but legitimately used. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): UUID hex-to-base32 conversion for API key generation; benign utility code. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Used to decompress stored DOM dump data; legitimate data handling, not payload hiding. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fires in minified React asset bundle; normal build output, not obfuscation. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 3.15.0 | 47 / 32 | |
| 3.14.1 | 29 / 31 | |
| 3.14.0 | 29 / 31 | |
| 3.12.0 | 29 / 31 | |
| 3.11.0 | 29 / 31 | |
| 3.10.0 | 29 / 31 | |
| 3.9.1 | 29 / 31 | |
| 3.9.0 | 29 / 31 | |
| 3.8.0 | 29 / 31 | |
| 3.6.0 | 28 / 31 | |
| 3.5.1 | 28 / 31 | |
| 3.5.0 | 28 / 31 |
v3.15.0
39 findingsDeclared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Declared in package.json dependencies but never imported in source code. Phantom dependencies may exist solely to execute install scripts or inject transitive malicious code. This was the exact attack vector in the axios compromise (plain-crypto-js).
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux Source: https://github.com/syngrisi/syngrisi/blob/8399aedee1cf7a73fa4ca4a3cb38f303f1593004/src/server/utils/__tests__/safeJoinWithin.test.ts#L18 16 | test('rejects a parent-traversal entry name', () => { 17 | assert.equal(safeJoinWithin(dest, '../evil'), null); > 18 | assert.equal(safeJoinWithin(dest, '../../../../etc/passwd'), null); 19 | }); 20 |
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/syngrisi/syngrisi/blob/8399aedee1cf7a73fa4ca4a3cb38f303f1593004/src/server/utils/__tests__/validateWebhookUrl.test.ts#L6 4 | 5 | test('accepts a public https URL (IP literal, no DNS lookup)', async () => { > 6 | const parsed = await validateWebhookUrl('https://93.184.216.34/hook', { ssrfProtection: true }); 7 | assert.equal(parsed.hostname, '93.184.216.34'); 8 | });
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/syngrisi/syngrisi/blob/8399aedee1cf7a73fa4ca4a3cb38f303f1593004/src/server/utils/__tests__/validateWebhookUrl.test.ts#L11 9 | 10 | test('rejects loopback IPv4 literal', async () => { > 11 | await assert.rejects(() => validateWebhookUrl('https://127.0.0.1/x', { ssrfProtection: true })); 12 | }); 13 |
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/syngrisi/syngrisi/blob/8399aedee1cf7a73fa4ca4a3cb38f303f1593004/src/server/utils/__tests__/validateWebhookUrl.test.ts#L15 13 | 14 | test('rejects RFC-1918 private IPv4 literal (10.0.0.0/8)', async () => { > 15 | await assert.rejects(() => validateWebhookUrl('https://10.0.0.5/x', { ssrfProtection: true })); 16 | }); 17 |
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/syngrisi/syngrisi/blob/8399aedee1cf7a73fa4ca4a3cb38f303f1593004/src/server/utils/__tests__/validateWebhookUrl.test.ts#L19 17 | 18 | test('rejects RFC-1918 private IPv4 literal (192.168.0.0/16)', async () => { > 19 | await assert.rejects(() => validateWebhookUrl('https://192.168.1.10/x', { ssrfProtection: true })); 20 | }); 21 |
HTTP request to raw IP address — legitimate packages use domain names Source: https://github.com/syngrisi/syngrisi/blob/8399aedee1cf7a73fa4ca4a3cb38f303f1593004/src/server/utils/__tests__/validateWebhookUrl.test.ts#L23 21 | 22 | test('rejects link-local IPv4 literal, incl. cloud metadata address', async () => { > 23 | await assert.rejects(() => validateWebhookUrl('https://169.254.169.254/latest/meta-data', { ssrfProtection: true })) 24 | }); 25 |
Accessing /etc/passwd or /etc/shadow — credential harvesting on Linux Source: https://github.com/syngrisi/syngrisi/blob/8399aedee1cf7a73fa4ca4a3cb38f303f1593004/src/server/utils/__tests__/validateWebhookUrl.test.ts#L35 33 | 34 | test('rejects non-http(s) scheme (file:)', async () => { > 35 | await assert.rejects(() => validateWebhookUrl('file:///etc/passwd', { ssrfProtection: true })); 36 | }); 37 |
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.14.1
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.14.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.12.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.11.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.10.0
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.1
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.0
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.8.0
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.