← Home

@tailor-platform/sdk

Tailor Platform SDK - The SDK to work with Tailor Platform

37
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jackchuka-tailornpm-tailor

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/list-BCl3ViG0.mjs AI (source-diff): Bundled CLI output; long line is minified build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/index-ByDQH56l.d.mts AI (source-diff): Type declaration bundle with long lines; not executable obfuscation. ai
source-diff net-exec-file:dist/list-BCl3ViG0.mjs AI (source-diff): Legit CLI bundle importing network/exec libs (connectrpc, child_process) for stated SDK CLI function. ai
source-diff obfuscated-file:dist/index-CTExbeYE.d.mts AI (source-diff): Type declaration file, long lines are generated types not obfuscation. ai
source-diff obfuscated-file:dist/jiti-31_Wx1yz.mjs AI (source-diff): Bundled dependency (jiti) output from rolldown/tsdown build, not obfuscation. ai
source-diff obfuscated-file:dist/list-1cs_CGF8.mjs AI (source-diff): Bundled CLI file with many legit imports; long lines are bundler output. ai
source-diff net-exec-file:dist/list-1cs_CGF8.mjs AI (source-diff): CLI tool legitimately uses network+child_process (deploy/build CLI), no exfil target found. ai
source-diff obfuscated-file:dist/index-D-0knE68.d.mts AI (source-diff): Generated .d.mts type declarations, long lines are normal. ai
source-diff obfuscated-file:dist/token-PbgBrNwb.mjs AI (source-diff): Bundled ESM build output with readable imports, not obfuscation. ai
source-diff obfuscated-file:dist/client-CGO7gniI.mjs AI (source-diff): tsdown/rolldown bundle output with readable imports and protobuf descriptors, not obfuscation. ai
source-diff obfuscated-file:dist/workspace_resource_pb-Db3fv68L.mjs AI (source-diff): Generated protobuf bundle with long base64 descriptors, not obfuscation. ai
source-diff obfuscated-file:dist/service_pb-BoLM0X4K.mjs AI (source-diff): Generated protobuf bundle with long base64 descriptors, not obfuscation. ai
publish-pattern new-deps-added AI (publish-pattern): get-tsconfig is a well-known small utility dep, benign. ai
source-diff bulk-obfuscated-files:dist AI (source-diff): Protobuf-generated bundled code, not true obfuscation. ai
source-diff obfuscated-file:dist/application-iRp2OYMz.mjs AI (source-diff): Bundled build output (rolldown), accompanied by .map files; not true obfuscation. ai
source-diff obfuscated-file:dist/service_pb-B5w9rjPY.mjs AI (source-diff): Generated protobuf descriptor file with base64 blobs, not obfuscation. ai
source-diff obfuscated-file:dist/resource_pb-BRv7AMXK.mjs AI (source-diff): Generated protobuf descriptor file with base64 blobs, not obfuscation. ai
source-diff obfuscated-file:dist/index-DHpKRtq3.d.mts AI (source-diff): Bundled type declaration file, minified formatting only. ai
source-diff obfuscated-file:dist/token-Cbs_El75.mjs AI (source-diff): Bundled tsdown/rolldown build output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-Bwrm8M8p.d.mts AI (source-diff): Bundled type-declaration output, not obfuscation. ai
phantom-deps phantom-dep:smol-toml AI (phantom-deps): Used via config parsing, not direct import. ai
source-diff obfuscated-file:dist/token-B9zkxSMS.mjs AI (source-diff): Bundled tsdown/rolldown output with readable imports, not obfuscation. ai
source-diff obfuscated-file:dist/index-Df0aH5zp.d.mts AI (source-diff): Bundled type declaration file, readable imports, not obfuscated. ai
source-diff obfuscated-file:dist/application-DThE2HW7.mjs AI (source-diff): Bundled tsdown/rolldown output with source maps, not true obfuscation. ai
source-diff obfuscated-file:dist/configure/index.d.mts AI (source-diff): Generated .d.mts type-declaration bundle, not obfuscated code. ai
source-diff obfuscated-file:dist/index-Br4XCvX1.d.mts AI (source-diff): Generated .d.mts type-declaration bundle, not obfuscated code. ai
source-diff obfuscated-file:dist/client-DQl5NPG9.mjs AI (source-diff): Bundled rolldown output with long import lines, not true obfuscation. ai
phantom-deps phantom-dep:@tailor-platform/function-types AI (phantom-deps): Same-org type-only dep referenced via triple-slash reference in .d.mts; stable FP. ai
source-diff obfuscated-file:dist/client-CKlZhiq4.mjs AI (source-diff): Bundled protobuf/connectrpc codegen, not obfuscation; clean import head. ai
source-diff net-exec-file:dist/application-DQ2F9UmJ.mjs AI (source-diff): Bundled CLI code with normal network/exec libs, no hostile target. ai
source-diff obfuscated-file:dist/index-1V_2bvT4.d.mts AI (source-diff): Generated type declaration file, long lines only. ai
source-diff obfuscated-file:dist/update-C5jgLxpK.mjs AI (source-diff): Bundled build output. ai
source-diff obfuscated-file:dist/application-DQ2F9UmJ.mjs AI (source-diff): Bundled tsdown/rolldown output, not true obfuscation. ai
source-diff obfuscated-file:dist/application-DnWZVbDO.mjs AI (source-diff): Bundled/minified rolldown output, not true obfuscation; readable imports/comments visible. ai
source-diff obfuscated-file:dist/update-2eb6jz9o.mjs AI (source-diff): Bundled CLI subcommand output, not obfuscated. ai
source-diff obfuscated-file:dist/jiti-DuCiUfMj.mjs AI (source-diff): Bundled jiti/webpack loader, standard bundler output. ai
source-diff net-exec-file:dist/application-DnWZVbDO.mjs AI (source-diff): CLI bundle legitimately combines network (connectrpc) and dynamic code per its function. ai
source-diff obfuscated-file:dist/update-Exhc9AkY.mjs AI (source-diff): Bundled CLI code, imports are legitimate deps. ai
source-diff obfuscated-file:dist/jiti-ygK9KoRA.mjs AI (source-diff): Bundled third-party lib (jiti/webpack loader), not obfuscation. ai
source-diff net-exec-file:dist/application-BKBo5tGD.mjs AI (source-diff): CLI bundle imports network/exec libs for its documented functionality, no malicious target. ai
source-diff obfuscated-file:dist/application-BKBo5tGD.mjs AI (source-diff): Bundled build output (tsdown/rolldown), not true obfuscation. ai
source-diff obfuscated-file:dist/index-BZTdfjoO.d.mts AI (source-diff): Type declaration bundle, long lines from generated types not obfuscation. ai
source-diff net-exec-file:dist/list-BrjIcqAX.mjs AI (source-diff): CLI legitimately uses child_process/network for its documented commands. ai
source-diff obfuscated-file:dist/list-BrjIcqAX.mjs AI (source-diff): Minified CLI bundle from rolldown/tsdown, not obfuscation. ai
source-diff obfuscated-file:dist/index-BkfOioTo.d.mts AI (source-diff): Long-line .d.mts type declaration file, not obfuscated code. ai
source-diff net-exec-file:dist/list-D1V0haDR.mjs AI (source-diff): CLI command file; spawn/network usage matches stated SDK CLI function. ai
source-diff obfuscated-file:dist/list-D1V0haDR.mjs AI (source-diff): Bundled CLI file with legitimate imports, not obfuscation. ai
phantom-deps phantom-dep:@liam-hq/cli AI (phantom-deps): Likely used indirectly/CLI tool, not a security concern. ai
source-diff obfuscated-file:dist/application-B0TR65qY.mjs AI (source-diff): Bundled build output (rolldown), not obfuscation; imports are plain ESM. ai
source-diff net-exec-file:dist/application-B0TR65qY.mjs AI (source-diff): CLI bundle uses network/fs/exec APIs for its stated function, no exfil target found. ai
source-diff obfuscated-file:dist/jiti-BrELlEYT.mjs AI (source-diff): Bundled third-party dep (jiti) via webpack, minified not obfuscated. ai
source-diff obfuscated-file:dist/update-CnSKzwg6.mjs AI (source-diff): Bundled build output, plain imports, part of CLI functionality. ai
source-diff obfuscated-file:dist/index-Bs9AsQb2.d.mts AI (source-diff): TypeScript declaration file, long lines from generated types not obfuscation. ai
source-diff obfuscated-file:dist/cli/lib.d.mts AI (source-diff): TypeScript declaration file, generated types not obfuscation. ai
phantom-deps phantom-dep:tsx AI (phantom-deps): Used dynamically via node:module register(), config-referenced. ai
phantom-deps phantom-dep:serve AI (phantom-deps): Likely invoked as CLI binary not direct import. ai
phantom-deps phantom-dep:consola AI (phantom-deps): Used within bundled dist, false positive from source scan. ai
phantom-deps phantom-dep:std-env AI (phantom-deps): Used within bundled dist, false positive from source scan. ai
source-diff net-exec-file:dist/list-BBzbTu9X.mjs AI (source-diff): CLI bundle legitimately uses child_process/network APIs for its stated functionality. ai
source-diff obfuscated-file:dist/list-BBzbTu9X.mjs AI (source-diff): Bundled CLI code (rolldown/tsdown output) with long lines, not true obfuscation. ai
source-diff obfuscated-file:dist/list-BvYJeydE.mjs AI (source-diff): Bundled CLI output with legit imports, not obfuscation. ai
source-diff obfuscated-file:dist/index-CANeLBB6.d.mts AI (source-diff): Type declaration bundling, not obfuscation. ai
source-diff net-exec-file:dist/list-BvYJeydE.mjs AI (source-diff): Bundled CLI file, imports match declared deps. ai
source-diff net-exec-file:dist/resume-8Y9mmXHa.mjs AI (source-diff): Bundler output with normal node/network APIs for CLI tool, no dropper behavior. ai
source-diff obfuscated-file:dist/index-Ba6ekRxa.d.mts AI (source-diff): Type declaration bundle, minified but not malicious. ai
source-diff obfuscated-file:dist/resume-8Y9mmXHa.mjs AI (source-diff): Bundled CLI output (rolldown), not true obfuscation. ai
source-diff net-exec-file:dist/resume-kyHIaNvK.mjs AI (source-diff): Bundled CLI tool code, legitimate network/CLI libs imported, no malicious behavior. ai
source-diff obfuscated-file:dist/index-Bin7-j3v.d.mts AI (source-diff): Generated .d.mts type declarations, not obfuscation. ai
source-diff obfuscated-file:dist/resume-kyHIaNvK.mjs AI (source-diff): Bundled CLI output via rolldown/tsdown, not true obfuscation. ai
source-diff obfuscated-file:dist/index-BcDejW72.d.mts AI (source-diff): Generated .d.mts type declarations, long lines are type unions not obfuscation. ai
source-diff obfuscated-file:dist/resume-ar5nEitS.mjs AI (source-diff): Bundled CLI output (rolldown/tsdown), not obfuscation; imports are legitimate first-party/CLI deps. ai
source-diff net-exec-file:dist/resume-ar5nEitS.mjs AI (source-diff): Bundled CLI code using child_process/network libs for legitimate SDK CLI functions, not a dropper. ai
phantom-deps phantom-dep:ora AI (phantom-deps): CLI tooling dep used indirectly via bundled CLI code. ai
source-diff obfuscated-file:dist/index-DBWm2TOg.d.mts AI (source-diff): Long-line type declaration file, not obfuscated code. ai
source-diff net-exec-file:dist/resume-CVNNM93m.mjs AI (source-diff): Bundled CLI with legit network/CLI deps, not a dropper. ai
source-diff obfuscated-file:dist/resume-CVNNM93m.mjs AI (source-diff): Bundled CLI output (rolldown/tsdown), not true obfuscation. ai
source-diff obfuscated-file:dist/index--_tMHIHD.d.mts AI (source-diff): Generated .d.mts type declaration file, not obfuscated code. ai
source-diff net-exec-file:dist/list-B11wQhss.mjs AI (source-diff): Bundled CLI using spawn/network for legitimate SDK features. ai
source-diff obfuscated-file:dist/list-B11wQhss.mjs AI (source-diff): Bundled CLI command file, long lines from bundler not obfuscation. ai
source-diff net-exec-file:dist/list-CQ-V5Ddn.mjs AI (source-diff): CLI tool using connectrpc/child_process legitimately, no exfil behavior. ai
source-diff obfuscated-file:dist/index-CEJUQFNe.d.mts AI (source-diff): Generated TypeScript declaration file, not obfuscated code. ai
source-diff obfuscated-file:dist/list-CQ-V5Ddn.mjs AI (source-diff): Bundled/minified CLI output from rolldown, not obfuscation. ai
source-diff obfuscated-file:dist/list-DLqfJ2jD.mjs AI (source-diff): Bundled CLI code with normal imports (zod, chalk, citty), not obfuscation. ai
source-diff net-exec-file:dist/list-DLqfJ2jD.mjs AI (source-diff): Bundled CLI code, no malicious network/exec behavior evident. ai
source-diff obfuscated-file:dist/index-QGMXFOXH.d.mts AI (source-diff): Long type-declaration file, not obfuscated code. ai
source-diff obfuscated-file:dist/jiti-CuWZt63q.mjs AI (source-diff): Bundled jiti/webpack output, not obfuscation; no malicious behavior in sample. ai
source-diff net-exec-file:dist/jiti-CuWZt63q.mjs AI (source-diff): Bundled CLI tooling, dynamic require is jiti's own module loader, not a dropper. ai
source-diff net-exec-file:dist/resume-DSfYKl2w.mjs AI (source-diff): Bundled CLI file with normal fs/network deps, no dropper behavior found. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with move to CI/CD (GitHub Actions) publishing pipeline. ai
source-diff obfuscated-file:dist/index-Zqsfkae6.d.mts AI (source-diff): Minified .d.mts type-declaration bundle, not obfuscation. ai
source-diff obfuscated-file:dist/resume-DSfYKl2w.mjs AI (source-diff): Bundled rolldown CLI output, not true obfuscation; legit imports visible in source. ai
provenance publisher-changed AI (provenance): Transition from npm-tailor to GitHub Actions is an IMPROVED provenance direction (CI/CD attestation adopted), not a takeover signal. ai
phantom-deps phantom-dep:@oxc-project/types AI (phantom-deps): Type-only dependency used in config/type files; phantom-dep heuristic false positive for type packages. ai
install-scripts install-script:postinstall AI (install-scripts): postinstall.mjs is a local file bundled with the package; consistent with SDK setup for an established platform SDK. ai
source-diff obfuscated-file:dist/cli/index.mjs AI (source-diff): Bundled CLI output via rolldown/tsdown; long lines are minification, not obfuscation. No _0x arrays, eval/atob, or packer signatures. ai

Versions (showing 37 of 37)

Version Deps Published
1.80.0 52 / 16
1.76.2 51 / 16
1.76.1 51 / 16
1.73.0 51 / 16
1.72.0 51 / 16
1.69.0 51 / 16
1.54.2 52 / 15
1.52.0 52 / 15
1.44.0 54 / 20
1.39.1 51 / 20
1.28.0 47 / 19
1.25.1 46 / 19
1.24.0 45 / 20
1.16.0 37 / 20
1.15.1 37 / 20
1.14.1 37 / 20
1.10.1 32 / 22
1.4.0 32 / 20
1.3.0 32 / 20
1.1.2 31 / 17
1.0.0 31 / 15
0.23.4 31 / 15
0.23.2 31 / 15
0.23.0 31 / 15
0.22.0 30 / 15
0.21.4 30 / 14
0.20.0 30 / 14
0.18.2 30 / 14
0.18.1 30 / 14
0.16.3 27 / 13
0.16.0 27 / 13
0.14.3 27 / 13
0.12.4 26 / 13
0.8.6 25 / 10
0.8.5 25 / 10
0.8.0 25 / 10
0.0.1 0 / 0

v1.80.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.76.2

3 findings
HIGH New obfuscated file: dist/service_pb-BoLM0X4K.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/workspace_resource_pb-Db3fv68L.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.76.1

3 findings
HIGH New obfuscated file: dist/resource_pb-BRv7AMXK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/service_pb-B5w9rjPY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.73.0

4 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.mjs

HIGH Publisher changed: npm-tailor → GitHub Actions (on 2026-07-02) provenance

This version was published by a different npm account than previous versions on 2026-07-02. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cli/index.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.72.0

4 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.mjs

HIGH Publisher changed: npm-tailor → GitHub Actions (on 2026-07-01) provenance

This version was published by a different npm account than previous versions on 2026-07-01. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cli/index.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.69.0

4 findings
HIGH Package has 'postinstall' script install-scripts

Script: node postinstall.mjs

HIGH Publisher changed: npm-tailor → GitHub Actions (on 2026-06-26) provenance

This version was published by a different npm account than previous versions on 2026-06-26. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cli/index.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.16.0

8 findings
HIGH New obfuscated file: dist/application-DQ2F9UmJ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/application-DQ2F9UmJ.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/jiti-BrELlEYT.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/update-C5jgLxpK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-1V_2bvT4.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cli/lib.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2026-02-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (npm-tailor) on 2026-02-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.15.1

8 findings
HIGH New obfuscated file: dist/application-B0TR65qY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/application-B0TR65qY.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/jiti-BrELlEYT.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/update-CnSKzwg6.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Bs9AsQb2.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cli/lib.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2026-02-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (npm-tailor) on 2026-02-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.14.1

8 findings
HIGH New obfuscated file: dist/application-DnWZVbDO.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/application-DnWZVbDO.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/jiti-DuCiUfMj.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/update-2eb6jz9o.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BlUBAAvu.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cli/lib.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2026-02-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (npm-tailor) on 2026-02-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.10.1

8 findings
HIGH New obfuscated file: dist/application-BKBo5tGD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/application-BKBo5tGD.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/jiti-ygK9KoRA.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/update-Exhc9AkY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BQw6I-mY.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/cli/lib.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2026-02-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (npm-tailor) on 2026-02-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.4.0

6 findings
HIGH New obfuscated file: dist/jiti-31_Wx1yz.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/list-1cs_CGF8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-1cs_CGF8.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CTExbeYE.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2026-01-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (npm-tailor) on 2026-01-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.3.0

6 findings
HIGH New obfuscated file: dist/jiti-31_Wx1yz.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/list-BCl3ViG0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-BCl3ViG0.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-ByDQH56l.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2026-01-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (npm-tailor) on 2026-01-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.1.2

7 findings
HIGH New obfuscated file: dist/jiti-CuWZt63q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jiti-CuWZt63q.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/list-BrjIcqAX.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-BrjIcqAX.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BZTdfjoO.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (npm-tailor) on 2025-12-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.0.0

7 findings
HIGH New obfuscated file: dist/jiti-CuWZt63q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jiti-CuWZt63q.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/list-D1V0haDR.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-D1V0haDR.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BkfOioTo.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-25) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-25. This could indicate a legitimate maintainer transition or an account compromise.

v0.23.4

7 findings
HIGH New obfuscated file: dist/jiti-CuWZt63q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jiti-CuWZt63q.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/list-BBzbTu9X.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-BBzbTu9X.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CANeLBB6.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-24. This could indicate a legitimate maintainer transition or an account compromise.

v0.23.2

7 findings
HIGH New obfuscated file: dist/jiti-CuWZt63q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jiti-CuWZt63q.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/list-BvYJeydE.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-BvYJeydE.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CANeLBB6.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-24. This could indicate a legitimate maintainer transition or an account compromise.

v0.23.0

7 findings
HIGH New obfuscated file: dist/jiti-CuWZt63q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jiti-CuWZt63q.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/list-DLqfJ2jD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-DLqfJ2jD.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-QGMXFOXH.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-23) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-23. This could indicate a legitimate maintainer transition or an account compromise.

v0.22.0

7 findings
HIGH New obfuscated file: dist/jiti-CuWZt63q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/jiti-CuWZt63q.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/list-B11wQhss.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-B11wQhss.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index--_tMHIHD.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-22. This could indicate a legitimate maintainer transition or an account compromise.

v0.21.4

5 findings
HIGH New obfuscated file: dist/list-CQ-V5Ddn.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/list-CQ-V5Ddn.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-CEJUQFNe.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-21) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-21. This could indicate a legitimate maintainer transition or an account compromise.

v0.20.0

5 findings
HIGH New obfuscated file: dist/resume-DSfYKl2w.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resume-DSfYKl2w.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Zqsfkae6.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-19) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-19. This could indicate a legitimate maintainer transition or an account compromise.

v0.18.2

5 findings
HIGH New obfuscated file: dist/resume-8Y9mmXHa.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resume-8Y9mmXHa.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Ba6ekRxa.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-18. This could indicate a legitimate maintainer transition or an account compromise.

v0.18.1

5 findings
HIGH New obfuscated file: dist/resume-8Y9mmXHa.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resume-8Y9mmXHa.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Ba6ekRxa.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-18. This could indicate a legitimate maintainer transition or an account compromise.

v0.16.3

5 findings
HIGH New obfuscated file: dist/resume-kyHIaNvK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resume-kyHIaNvK.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Bin7-j3v.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-15) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-15. This could indicate a legitimate maintainer transition or an account compromise.

v0.16.0

5 findings
HIGH New obfuscated file: dist/resume-ar5nEitS.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resume-ar5nEitS.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BcDejW72.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-11) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-11. This could indicate a legitimate maintainer transition or an account compromise.

v0.14.3

5 findings
HIGH New obfuscated file: dist/resume-CVNNM93m.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/resume-CVNNM93m.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-DBWm2TOg.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: npm-tailor → GitHub Actions (on 2025-12-10) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2025-12-10. This could indicate a legitimate maintainer transition or an account compromise.