@tangle-network/agent-runtime
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/coordination-o0TzS7Ms.d.ts | AI (source-diff): Long-line .d.ts type bundle from tsup, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-7HH22XN4.js | AI (source-diff): Bundled tsup chunk implementing the package's own sandbox/executor loop, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-DzXsfxre.d.ts | AI (source-diff): Long-line .d.ts type declaration bundle, not obfuscated executable code. | ai | |
| source-diff | net-exec-file:dist/chunk-7PSFJTJZ.js | AI (source-diff): Bundled library code implementing sandbox/executor features, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-SDR45ZQB.js | AI (source-diff): Bundled executor/sandbox module, matches stated agent-runtime execution purpose. | ai | |
| source-diff | obfuscated-file:dist/coordination-CdU8LyvB.d.ts | AI (source-diff): Long-line TypeScript declaration file from build, not obfuscated executable code. | ai | |
| source-diff | net-exec-file:dist/chunk-L4CACVIJ.js | AI (source-diff): tsup-bundled re-export chunk, not a dropper; no actual net+exec payload shown. | ai | |
| source-diff | obfuscated-file:dist/coordination-pOGZuYS7.d.ts | AI (source-diff): Long-line .d.ts is generated type declarations, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-GKZ6DFDN.js | AI (source-diff): Bundled tsup output re-exporting sandbox/executor code; no actual dropper/loader behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/coordination-EGoRbbsd.d.ts | AI (source-diff): Long-line .d.ts type-export file from bundler, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-OO4EK3JB.js | AI (source-diff): Bundled tsup chunk re-exporting internal modules; no actual network+exec malware pattern. | ai | |
| source-diff | obfuscated-file:dist/delegates-htF7l_H6.d.ts | AI (source-diff): Long-line .d.ts type declarations, not code obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-ZADWPBOE.js | AI (source-diff): Bundled utility chunk (tsup output); no actual network+exec dropper behavior in sample. | ai | |
| source-diff | net-exec-file:dist/chunk-I7WVPJBZ.js | AI (source-diff): Bundled tsup chunk importing sibling chunks; no fetched-binary or exfil behavior in sample. | ai | |
| provenance | regressed-provenance | AI (provenance): Manual publish by known maintainer per publisher-changed-known-maintainer INFO finding. | ai | |
| source-diff | net-exec-file:dist/chunk-6K5CI33W.js | AI (source-diff): tsup-bundled chunk; sample shows plain module re-exports, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-BVVRQ4YC.js | AI (source-diff): Bundled sandbox/executor code matching package purpose, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-DxJ83oZA.d.ts | AI (source-diff): Long type-declaration import line, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-D336OZHK.js | AI (source-diff): Bundled tsup chunk for sandbox/executor runtime; sample shows normal module re-exports, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/coordination-B3ZuApR_.d.ts | AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-JYURIKPF.js | AI (source-diff): Bundled build output of sandbox/executor runtime, not a dropper; matches package's stated function. | ai | |
| source-diff | net-exec-file:dist/chunk-FQH33M5N.js | AI (source-diff): tsup-bundled chunk with normal async/crypto helpers, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-DU0saWeg.d.ts | AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-HPYWEFVY.js | AI (source-diff): Bundled build output; sample shows normal runtime logic, no fetched/executed payload. | ai | |
| source-diff | obfuscated-file:dist/coordination-Csxsy39a.d.ts | AI (source-diff): Generated .d.ts type-declaration file with long import lines, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-YHS6I2IS.js | AI (source-diff): tsup-bundled chunk of runtime code, no fetched binary or exfil destination. | ai | |
| source-diff | net-exec-file:dist/chunk-VKVNDNG4.js | AI (source-diff): Bundled tsup output for a sandbox-executor library; sample shows normal module re-exports, not a loader payload. | ai | |
| source-diff | net-exec-file:dist/chunk-3TZOXS7B.js | AI (source-diff): tsup bundle chunk containing runtime executor code, not a dropper; readable JS with normal imports. | ai | |
| source-diff | net-exec-file:dist/chunk-SN3XBTTH.js | AI (source-diff): Bundled orchestration code (tsup chunk), no dropper/loader behavior in sample. | ai | |
| source-diff | net-exec-file:dist/chunk-3RAXZ6LB.js | AI (source-diff): Bundled build chunk with normal imports; no fetch+exec of foreign payload. | ai | |
| source-diff | net-exec-file:dist/chunk-QSO2TVDS.js | AI (source-diff): Bundled agent-runtime orchestration code, not a network+exec dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-DCmljYDf.d.ts | AI (source-diff): Long-line TypeScript .d.ts import list, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-AG335EXG.js | AI (source-diff): Bundled tsup chunk of runtime logic, not a network dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-CZe4lTxy.d.ts | AI (source-diff): Minified .d.ts with long import lines from bundler, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-CEW5BMGN.js | AI (source-diff): Bundled tsup output, not a dropper; sample shows normal runtime module code. | ai | |
| source-diff | obfuscated-file:dist/coordination-CFVF0OzX.d.ts | AI (source-diff): Long-line minified .d.ts type declarations, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-PHKNOAOU.js | AI (source-diff): Bundled runtime code (tsup chunk), not a dropper; sample shows normal module imports. | ai | |
| source-diff | net-exec-file:dist/chunk-45D64J7B.js | AI (source-diff): Bundled runtime chunk (tsup output), sample shows benign sandbox/journal utility code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-CM2IK7VS.js | AI (source-diff): Sample shows normal runtime utility code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/delegates-CWMv_rKL.d.ts | AI (source-diff): Long-line .d.ts is verbose type declarations/comments, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-VCOT7XEQ.js | AI (source-diff): Bundled tsup chunk; sample shows benign utility/crypto code, not a dropper. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Consistent with legit build growth, no obfuscation/exfil found. | ai | |
| provenance | missing-githead | AI (provenance): Publish env variance for trusted maintainer, no behavioral signal. | ai | |
| source-diff | obfuscated-file:dist/coordination-rRj5hjJK.d.ts | AI (source-diff): Long-line .d.ts type declarations, not obfuscated JS. | ai | |
| dependencies | unvetted-dep:@tangle-network/agent-profile-materialize | AI (dependencies): First-party @tangle-network sibling package, part of same monorepo ecosystem. | ai | |
| source-diff | net-exec-file:dist/chunk-AD7JW4QG.js | AI (source-diff): Bundled tsup chunk re-exporting internal executor/sandbox modules, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-YFOPWG74.js | AI (source-diff): Bundled build chunk implementing documented sandbox harness spawning, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-QDVLTRCP.js | AI (source-diff): Bundled sandbox/executor code, not a dropper; consistent with package's stated function. | ai | |
| source-diff | net-exec-file:dist/chunk-22HPUH77.js | AI (source-diff): Bundled tsup output of package's own sandbox/executor runtime, not injected code. | ai | |
| source-diff | obfuscated-file:dist/kb-gate-CKfykcYQ.d.ts | AI (source-diff): Long-line .d.ts from bundled type declarations, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-K6WP7PYW.js | AI (source-diff): Bundled tsup chunk containing normal runtime utility/crypto code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-VKUHUFX7.js | AI (source-diff): Bundled tsup chunk with normal runtime logic, not a dropper; no fetched binary or exfil target. | ai | |
| source-diff | net-exec-file:dist/chunk-MDFZSPHA.js | AI (source-diff): Bundled build chunk with legit runtime code, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/delegates-C94qchkz.d.ts | AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-RLDUT4JL.js | AI (source-diff): Bundled build chunk with normal async/crypto usage, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-UJW6EVNY.js | AI (source-diff): Bundled agent-runtime code (sandbox executor/loop primitives), not a dropper; matches package's own purpose. | ai | |
| source-diff | obfuscated-file:dist/coordination-BoEPhGas.d.ts | AI (source-diff): Minified .d.ts type file, not obfuscated malicious code. | ai | |
| source-diff | net-exec-file:dist/chunk-75V2XXYJ.js | AI (source-diff): Bundled tsup chunk of legit executor/sandbox code, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-MT4XM3G6.js | AI (source-diff): Bundled build chunk from tsup; sample shows ordinary async utility code, not a loader. | ai | |
| source-diff | net-exec-file:dist/chunk-AHZ3YBL6.js | AI (source-diff): Bundled tsup chunk with normal runtime imports, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-BFVtgRax.d.ts | AI (source-diff): Minified .d.ts type declarations from build tool, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-NLRA6434.js | AI (source-diff): Bundled runtime code implementing agent sandbox execution, not dropper/loader behavior. | ai | |
| source-diff | obfuscated-file:dist/coordination-c_7Olmtq.d.ts | AI (source-diff): Long-line .d.ts type declarations, not obfuscated executable code. | ai | |
| source-diff | net-exec-file:dist/chunk-DLAEEF26.js | AI (source-diff): Bundled tsup chunk with legible named exports for sandbox/agent runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-BI9tpcmF.d.ts | AI (source-diff): Long-line .d.ts is generated type bundling, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-D6GIWPKD.js | AI (source-diff): Bundled tsup chunk with normal imports/network client code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/coordination-09JTQnlF.d.ts | AI (source-diff): Long-line .d.ts is bundled type declarations, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-N2JJDGLJ.js | AI (source-diff): Bundled tsup chunk with sandbox/executor abstractions matching package's stated function, not a loader. | ai | |
| source-diff | obfuscated-file:dist/coordination-DEVknvQo.d.ts | AI (source-diff): Generated .d.ts with long import lines, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-SA5GCF2X.js | AI (source-diff): Bundled build chunk of legitimate runtime code, not a dropper. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from tsup bundling/type generation across many versions. | ai | |
| source-diff | obfuscated-file:dist/kb-gate-CHAyt4aI.d.ts | AI (source-diff): Long lines are bundled .d.ts type re-exports, not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-2OU7ZQPD.js | AI (source-diff): Bundled TS helper code (crypto/util), no fetched-binary or exfil behavior. | ai | |
| source-diff | obfuscated-file:dist/coordination-CuDLO8wj.d.ts | AI (source-diff): Long-line .d.ts type declarations from tsup/rollup dts bundling, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-PIPPLSOF.js | AI (source-diff): Bundled ESM chunk re-exporting library functions, not a dropper/loader. | ai | |
| source-diff | net-exec-file:dist/chunk-4IBAMGBE.js | AI (source-diff): Bundled executor/sandbox runtime code, not a dropper; no fetched-binary or exfil pattern in sample. | ai | |
| source-diff | obfuscated-file:dist/coordination-DxHduZg7.d.ts | AI (source-diff): Minified .d.ts type declarations from tsup bundling, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/delegates-DqAgo32T.d.ts | AI (source-diff): Long-line .d.ts type declaration file from bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-QXWGSDAQ.js | AI (source-diff): Bundled tsup output for an agent-runtime package; sample shows normal utility code, no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/chunk-JTH2FPCK.js | AI (source-diff): Bundled agent-runtime logic; sample shows no malicious network/exec behavior, just normal async utilities. | ai | |
| source-diff | obfuscated-file:dist/delegates-BPLIl8EC.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; standard tsup bundler output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/delegates-CLFNAKyi.d.ts | AI (source-diff): TypeScript declaration file with long JSDoc/type lines; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-J6DAU44N.js | AI (source-diff): Bundled dist chunk with standard agent-runtime logic; no fetched binaries or exfil behavior. | ai | |
| source-diff | net-exec-file:dist/chunk-5ISW5JUF.js | AI (source-diff): Bundled tsup/esbuild output with first-party imports; no dropper behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/delegates-CsXJPZDH.d.ts | AI (source-diff): TypeScript declaration file; long lines are concatenated type signatures, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-IW2LMLK6.js | AI (source-diff): Bundled tsup/esbuild output with readable TS source; network+exec pattern is the agent runtime's core function, not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-PXUTIMGJ.js | AI (source-diff): Sample shows normal bundled TS runtime utilities (crypto.randomUUID, sleep, abort helpers); no malicious payload. | ai | |
| provenance | no-provenance | AI (provenance): Established tangle-network package; lack of Sigstore provenance is a process gap, not a security risk here. | ai | |
| source-diff | obfuscated-file:dist/delegates-D9o5_VFj.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; not obfuscated code. | ai | |
| source-diff | net-exec-file:dist/chunk-4H2FML7G.js | AI (source-diff): Sample shows legitimate agent-runtime bundled code (crypto, sandbox utilities); no dropper/loader patterns. | ai | |
| provenance | publisher-changed | AI (provenance): Change from drewstone to GitHub Actions reflects CI/CD automation, consistent with SLSA provenance attestation present on this package. | ai | |
| source-diff | obfuscated-file:dist/runtime.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; not obfuscated code. | ai |
Versions (showing 100 of 138)
| Version | Deps | Published |
|---|---|---|
| 0.94.9 | 3 / 13 | |
| 0.94.8 | 3 / 13 | |
| 0.94.7 | 3 / 13 | |
| 0.94.6 | 3 / 13 | |
| 0.94.5 | 2 / 12 | |
| 0.94.4 | 2 / 12 | |
| 0.94.3 | 2 / 12 | |
| 0.94.2 | 2 / 12 | |
| 0.94.1 | 2 / 12 | |
| 0.94.0 | 2 / 12 | |
| 0.93.2 | 2 / 12 | |
| 0.93.1 | 2 / 12 | |
| 0.93.0 | 2 / 12 | |
| 0.92.1 | 2 / 12 | |
| 0.92.0 | 2 / 12 | |
| 0.91.0 | 2 / 12 | |
| 0.90.1 | 1 / 12 | |
| 0.90.0 | 1 / 12 | |
| 0.89.0 | 0 / 12 | |
| 0.88.0 | 0 / 12 | |
| 0.87.0 | 0 / 12 | |
| 0.86.0 | 0 / 12 | |
| 0.85.0 | 0 / 12 | |
| 0.84.0 | 0 / 12 | |
| 0.83.0 | 0 / 12 | |
| 0.82.0 | 0 / 12 | |
| 0.81.1 | 0 / 12 | |
| 0.81.0 | 0 / 12 | |
| 0.80.1 | 0 / 12 | |
| 0.80.0 | 0 / 12 | |
| 0.79.4 | 0 / 12 | |
| 0.79.3 | 0 / 12 | |
| 0.79.2 | 0 / 12 | |
| 0.79.1 | 0 / 12 | |
| 0.79.0 | 0 / 12 | |
| 0.78.0 | 0 / 12 | |
| 0.77.0 | 0 / 12 | |
| 0.76.0 | 0 / 11 | |
| 0.75.1 | 0 / 11 | |
| 0.75.0 | 0 / 11 | |
| 0.74.0 | 0 / 11 | |
| 0.73.0 | 0 / 11 | |
| 0.72.0 | 0 / 11 | |
| 0.71.1 | 0 / 11 | |
| 0.71.0 | 0 / 11 | |
| 0.70.1 | 0 / 11 | |
| 0.70.0 | 0 / 11 | |
| 0.69.0 | 0 / 9 | |
| 0.68.0 | 0 / 9 | |
| 0.67.0 | 0 / 9 | |
| 0.66.0 | 0 / 9 | |
| 0.65.0 | 0 / 9 | |
| 0.63.0 | 0 / 9 | |
| 0.62.0 | 0 / 9 | |
| 0.61.0 | 0 / 9 | |
| 0.60.0 | 0 / 9 | |
| 0.59.0 | 0 / 9 | |
| 0.58.0 | 0 / 8 | |
| 0.57.0 | 0 / 8 | |
| 0.56.1 | 0 / 8 | |
| 0.56.0 | 0 / 8 | |
| 0.55.0 | 0 / 8 | |
| 0.54.0 | 0 / 8 | |
| 0.53.0 | 0 / 8 | |
| 0.52.0 | 0 / 8 | |
| 0.51.0 | 0 / 8 | |
| 0.50.0 | 0 / 8 | |
| 0.49.0 | 0 / 8 | |
| 0.48.0 | 0 / 8 | |
| 0.47.0 | 0 / 8 | |
| 0.46.0 | 0 / 8 | |
| 0.45.0 | 0 / 8 | |
| 0.44.0 | 0 / 7 | |
| 0.43.0 | 0 / 7 | |
| 0.42.1 | 0 / 7 | |
| 0.42.0 | 0 / 7 | |
| 0.41.0 | 0 / 7 | |
| 0.40.0 | 0 / 7 | |
| 0.39.0 | 0 / 7 | |
| 0.38.0 | 0 / 7 | |
| 0.37.0 | 0 / 7 | |
| 0.36.0 | 0 / 7 | |
| 0.35.0 | 0 / 7 | |
| 0.34.0 | 0 / 7 | |
| 0.33.0 | 0 / 7 | |
| 0.32.0 | 0 / 7 | |
| 0.30.1 | 1 / 6 | |
| 0.30.0 | 1 / 6 | |
| 0.29.0 | 1 / 6 | |
| 0.28.0 | 1 / 6 | |
| 0.27.0 | 1 / 6 | |
| 0.25.2 | 1 / 6 | |
| 0.25.1 | 1 / 6 | |
| 0.25.0 | 1 / 6 | |
| 0.23.1 | 1 / 6 | |
| 0.23.0 | 1 / 6 | |
| 0.22.0 | 1 / 6 | |
| 0.21.1 | 1 / 6 | |
| 0.21.0 | 1 / 6 | |
| 0.20.4 | 1 / 6 |
v0.94.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.7
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.6
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.5
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.94.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.93.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.92.0
5 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: drewstone.
This version was published by a different npm account (drewstone) than the most recent previously approved version (GitHub Actions) on 2026-07-11, but drewstone is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.91.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.90.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.90.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.89.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.88.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.87.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.86.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.85.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.84.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.83.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.82.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.81.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.80.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.79.4
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.79.3
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.