@synnaxlabs/pluto
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Package has 106 versions; this is an active project with regular releases, not a dormant takeover. | ai | |
| source-diff | obfuscated-file:dist/input-Cmz5uJMy.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React input component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/list-DxLbFFst.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React list component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/menu-CzVsAF7t.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React menu component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/select-CdXH4a4a.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/tabs-pxTYUqCG.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/text-GEWlI5lm.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/theming-_5ule7oW.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React theming code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/tree-DWGO_dK5.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/triggers-BICFF-PC.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React triggers code, no malicious patterns. | ai | |
| source-diff | net-exec-file:dist/color-CbZfMuXM.js | AI (source-diff): False positive; same lodash-style environment detection pattern, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/input-obi4xzpE.js | AI (source-diff): Standard Vite/Rollup minified ESM chunk; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/theming-BIw63nuf.js | AI (source-diff): Standard Vite/Rollup minified ESM chunk; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/triggers-dlQ9UJNW.js | AI (source-diff): Standard Vite/Rollup minified ESM chunk; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/button-B83-F42f.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/color-DrArYQj4.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React component code, no malicious patterns. | ai | |
| source-diff | net-exec-file:dist/color-DrArYQj4.cjs | AI (source-diff): False positive; dynamic code in sample is lodash-style Object detection (Function('return this')), not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/dialog-D__pKJwf.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React component code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/haul-UF0eYwTk.cjs | AI (source-diff): Standard Vite/Rollup minified chunk; readable React DnD component code, no malicious patterns. | ai | |
| dependencies | unvetted-dep:compromise-dates | AI (dependencies): compromise-dates is a legitimate NLP plugin for the compromise library, consistently declared across versions of this package. | ai | |
| phantom-deps | phantom-dep:d3-scale | AI (phantom-deps): Bundled output pattern; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:pluralize | AI (phantom-deps): Bundled output pattern; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:compromise | AI (phantom-deps): Bundled output pattern; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:async-mutex | AI (phantom-deps): Bundled output pattern; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:react-color | AI (phantom-deps): Bundled output pattern; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:compromise-dates | AI (phantom-deps): Bundled output pattern; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@fontsource/inter | AI (phantom-deps): Font package imported via CSS; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@fontsource/geist-mono | AI (phantom-deps): Font package imported via CSS; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-virtual | AI (phantom-deps): Bundled output pattern; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:@fontsource-variable/inter | AI (phantom-deps): Font package imported via CSS; stable false positive for this UI library. | ai | |
| phantom-deps | phantom-dep:fuse.js | AI (phantom-deps): Font/utility deps referenced in config files; bundled output pattern for this UI library. | ai | |
| provenance | slsa-provenance | AI (provenance): CI/CD with Sigstore attestation; stable for this package. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 0.56.3 | 24 / 26 | |
| 0.56.1 | 23 / 26 | |
| 0.56.0 | 23 / 26 | |
| 0.55.0 | 22 / 25 | |
| 0.54.2 | 22 / 25 | |
| 0.54.1 | 22 / 25 | |
| 0.54.0 | 22 / 25 |
v0.56.3
24 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.56.0
25 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.55.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.54.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.54.1
19 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.54.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.