@teambit/node
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.b23dc86e21e565be31ac.js | AI (source-diff): Bundled build output, analyzer itself labels non-obfuscated. | ai | |
| publish-pattern | rapid-publish | AI (publish-pattern): Teambit publishes dozens of monorepo packages together in short windows routinely. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.3e1f9bd12ac3d9e10956.js | AI (source-diff): React/webpack runtime code misidentified as net+exec dropper pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.3e1f9bd12ac3d9e10956.js | AI (source-diff): Webpack bundle containing React/MDX runtime, not obfuscated malware. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js | AI (source-diff): Standard webpack module runtime; no external fetch+exec behavior evident. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.617496fcc89620f59f28.js | AI (source-diff): Bundled build output, analyzer itself labels non-obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/54.9e90b5c8f2ad6246d0bd.js | AI (source-diff): Webpack-bundled preview UI chunk; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js | AI (source-diff): Webpack-bundled preview UI chunk containing Bit's own dependency policy config, not malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/368.7f4510ee81e9120e0b0a.js | AI (source-diff): Bundled webpack module, benign. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.2ccfb064bf34702ba20b.js | AI (source-diff): Bundled build output, minified. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.70ac7750777324d9fefc.js | AI (source-diff): Bundled build output, minified. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.e95e08a4e31e9848daee.js | AI (source-diff): Bundled React runtime code, benign. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.e95e08a4e31e9848daee.js | AI (source-diff): Bundled build output, benign. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js | AI (source-diff): Bundled build output, no fetched-binary/exfil behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js | AI (source-diff): Webpack-bundled preview UI asset, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.701e47606ddfc074bb91.js | AI (source-diff): Bundled webpack output, regenerator-runtime boilerplate. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.3210f6cfda3ea182f4fc.js | AI (source-diff): React/MDX bundle, no evidence of exfil or dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.3210f6cfda3ea182f4fc.js | AI (source-diff): Bundled webpack output for MDX/React preview scope. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.5762cc1ae208c080a02b.js | AI (source-diff): Bundled webpack output, regenerator-runtime boilerplate. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/753.633354a157780af09402.js | AI (source-diff): Bundled Bit workspace/dependency-resolver config data, not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/753.633354a157780af09402.js | AI (source-diff): Webpack-bundled preview UI asset containing workspace config, not malicious payload. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/244.508e6438cc297ec46e93.js | AI (source-diff): Webpack-bundled preview UI asset; minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.d234ce3f647bf7375488.js | AI (source-diff): Bundled loader pattern, no hostile destination. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js | AI (source-diff): Bundled loader pattern, benign config data. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/586.3b2f16376c69f7f926c8.js | AI (source-diff): Bundled preview-module code, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js | AI (source-diff): Bundled chunk loader pattern, no exfil destination present. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js | AI (source-diff): Bundled Bit workspace config JS, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.10a01b3ba530ac5257ed.js | AI (source-diff): Minified bundler output confirmed by artifact label. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.f2945ef274ccad3165a6.js | AI (source-diff): Minified bundler output confirmed by artifact label. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.d234ce3f647bf7375488.js | AI (source-diff): Bundled polyfills/MDX scope code, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js | AI (source-diff): Webpack-bundled UI deps (floating-ui etc.), not obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): Provenance adoption is optional; absence is common and not a risk for this mature package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established package; missing description is benign metadata. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.aca5a9abd56efb01f661.js | AI (source-diff): Bundled preview-module linking code, standard build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/976.131be05c5afb105432da.js | AI (source-diff): Bundled dependency-resolver policy/config chunk, standard build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/320.901d818bee5d1e4c5580.js | AI (source-diff): Bundled MDX library chunk, standard build output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js | AI (source-diff): Bundled third-party UI libs, no dropper/loader behavior present. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js | AI (source-diff): Webpack-bundled UI preview chunk (floating-ui/react libs), not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.843c7f03e8ab810459fc.js | AI (source-diff): Confirmed bundler minified output per finding detail. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.87bf52fdc03ea774bc2d.js | AI (source-diff): Confirmed bundler minified output per finding detail. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Sibling @bitdev/@teambit generator package, consistent with monorepo tooling. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/976.131be05c5afb105432da.js | AI (source-diff): GraphQL library internals bundled in, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/320.762ef2b410b3d3456b80.js | AI (source-diff): Bundled MDX library output, minified not obfuscated. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Large monorepo publisher with 6033 approved packages; routine maintainer roster change. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.365e203b2fc35c3b2579.js | AI (source-diff): Bundled peer-exposure shim, minified webpack output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.567af5919fc6dc2d8f4c.js | AI (source-diff): Bundled preview code, minified webpack output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.b77f46880298d1bad0b5.js | AI (source-diff): Bundled preview-module linking code, standard minified output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/847.926d4d3482765239c0b9.js | AI (source-diff): Same bundle; no dropper/exfil behavior evident. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/847.926d4d3482765239c0b9.js | AI (source-diff): Env-template dependency policy bundle; legitimate config data, not malicious. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.041540aaf75a9dc05f44.js | AI (source-diff): Bundled UI lib; no exfil/dropper behavior found in sample. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.041540aaf75a9dc05f44.js | AI (source-diff): Webpack-bundled floating-ui library, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.b5ab902b1a0f137defb9.js | AI (source-diff): Webpack-bundled UI preview chunk, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.3e05d46329040ae867db.js | AI (source-diff): Bundled peers-exposure helper for React/ReactDOM globals. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.ccca614c065f74d2ea59.js | AI (source-diff): Bundled webpack chunk with regenerator-runtime helper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.7c6728df46cb8b08d582.js | AI (source-diff): Bundled preview-modules chunk. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/608.e6d2d2cfbf48fb5a7ad7.js | AI (source-diff): Bundled config/runtime, not a dropper. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/608.e6d2d2cfbf48fb5a7ad7.js | AI (source-diff): Bundled env config chunk from teambit's own template. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.b5ab902b1a0f137defb9.js | AI (source-diff): Bundled webpack runtime, no dropper behavior. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/96.ee1cbf5a28d053ff9d4f.js | AI (source-diff): Bundled config/runtime setup code, no fetched binary or exfil destination. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.a1c638f4dd41363220bf.js | AI (source-diff): Bundled peer-exposure shim for React/ReactDOM, standard Bit env-template pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.692ed07fdb68bb8ce268.js | AI (source-diff): Bundled preview module with regenerator-runtime helper, standard build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.7b87f6c7c76ce3490a10.js | AI (source-diff): Bundled preview module code, minified build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/96.ee1cbf5a28d053ff9d4f.js | AI (source-diff): Webpack-bundled preview UI chunk, not true obfuscation; part of documented env-template build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.51a844e9507d9e7134b0.js | AI (source-diff): Standard webpack bundle output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.181c53322f0a17fd6f2f.js | AI (source-diff): Webpack bootstrap bundle exposing peers globally, documented pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.93d3a0dfdcf975fd9e9b.js | AI (source-diff): Standard webpack bundle output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/134.05dcf5ec5c072f2a1e5f.js | AI (source-diff): Bundled webpack runtime, no fetched-binary or exfil behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.d1f4bb6e74ef33dffe75.js | AI (source-diff): Bundled peer-exposure shim, minified build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.9d287744d5fa8c79c2ff.js | AI (source-diff): Bundled preview module chunk, minified build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.2509fe8d4be8f459070a.js | AI (source-diff): Bundled preview module chunk, minified build output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.6cade8d3bfeee6fa9560.js | AI (source-diff): Bundled webpack runtime, no malicious network target. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.6cade8d3bfeee6fa9560.js | AI (source-diff): Bundled third-party UI lib (floating-ui) chunk, minified build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/134.05dcf5ec5c072f2a1e5f.js | AI (source-diff): Webpack-bundled preview artifact, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.9de18b929171b16a2b43.js | AI (source-diff): Bundled preview UI code, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.5fca524d5de3899dfbb7.js | AI (source-diff): Bundled peer-exposure chunk, standard webpack pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.2cc858092325681ebd15.js | AI (source-diff): Bundled preview module chunk with regenerator-runtime. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.f1294097892eff1540ba.js | AI (source-diff): Bundled preview module chunk. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/652.d81ff018143c2d893013.js | AI (source-diff): Bundled config/build code, no malicious dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/652.d81ff018143c2d893013.js | AI (source-diff): Bundled Bit workspace config chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/548.793da35237bf9f418835.js | AI (source-diff): Bundled MDX library chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.9de18b929171b16a2b43.js | AI (source-diff): Webpack-bundled UI chunk, not true obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.8625d6b119225858feee.js | AI (source-diff): Standard webpack bundle output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.26b418143697aa562177.js | AI (source-diff): Bundled peer-exposure shim, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.aab56ff891341170ca0b.js | AI (source-diff): Standard webpack bundle output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/885.e718bc54f2f10a05b585.js | AI (source-diff): Bundled preview config/build artifact, not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.4b29a16fd35fccc41dd4.js | AI (source-diff): Bundled preview code; no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.4b29a16fd35fccc41dd4.js | AI (source-diff): Webpack-bundled preview UI code, minified not obfuscated. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/885.e718bc54f2f10a05b585.js | AI (source-diff): Bundled preview code; no exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.e47642c040dc15a6775d.js | AI (source-diff): Bundled webpack preview asset. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.bd15eed8c9f5390df3f3.js | AI (source-diff): Bundled webpack preview asset, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.bd15eed8c9f5390df3f3.js | AI (source-diff): Webpack chunk loader, no exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/686.66255e0b1247f8b13a2a.js | AI (source-diff): Bundled webpack preview asset, not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/686.66255e0b1247f8b13a2a.js | AI (source-diff): Webpack chunk loader, no exfil/dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.af5154485afafb07e392.js | AI (source-diff): Bundled webpack preview asset. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.8e15181df47bfc9caee4.js | AI (source-diff): Bundled webpack preview asset. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.cfbbe78375029bf4f4fa.js | AI (source-diff): Webpack-bundled UI preview artifact; minification is expected for this package's env-template output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.0296edc69ee2c529bc9e.js | AI (source-diff): Webpack-bundled UI preview artifact; minification expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.2c57bcd330fdc4c1718e.js | AI (source-diff): Webpack-bundled UI preview artifact; minification expected. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.2c57bcd330fdc4c1718e.js | AI (source-diff): Webpack chunk loader pattern in browser preview bundle, not malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.1f75bec3ea1f3ee349fc.js | AI (source-diff): Webpack-bundled UI preview artifact; minification expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/944.23c7a42c25b29314f834.js | AI (source-diff): Webpack-bundled UI preview artifact; minification expected. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/616.cffce716fb743542f985.js | AI (source-diff): Webpack chunk loader pattern in browser preview bundle, not malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/616.cffce716fb743542f985.js | AI (source-diff): Webpack-bundled UI preview artifact; minification expected. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.cfbbe78375029bf4f4fa.js | AI (source-diff): Network+exec pattern is from webpack chunk loader in browser preview bundle, not malware. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.c9ab17bbccedfe3d2254.js | AI (source-diff): Webpack chunk loader pattern; network refs are CDN icon URLs and dynamic require is webpack's __webpack_require__, not malicious. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.5b3e3e6216c2613f1990.js | AI (source-diff): Dynamic execution is webpack chunk loading; no malicious network calls present. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.5b3e3e6216c2613f1990.js | AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.c570932c16085d8cda15.js | AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.827ddc797268dbf4dd8a.js | AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/541.3e2065c1d9de461ef814.js | AI (source-diff): Network refs are static.bit.dev icon URLs; dynamic execution is webpack __webpack_require__. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/541.3e2065c1d9de461ef814.js | AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/348.c7479d1547f3ca674a78.js | AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.c9ab17bbccedfe3d2254.js | AI (source-diff): Standard webpack-minified UI bundle; part of Bit env-template preview artifacts shipped in every release. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js | AI (source-diff): Standard webpack bundle for Bit env-template UI preview; not obfuscated malware. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/peers.8609c56a3038c8ebc4b7.js | AI (source-diff): Webpack chunk; net-exec pattern is normal for bundled UI artifacts. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.8609c56a3038c8ebc4b7.js | AI (source-diff): Webpack bundle shipping MDX/React peer deps; minified but clearly legitimate. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.9174546e5244c954aeb0.js | AI (source-diff): Webpack bundle for overview preview; standard minified React code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.ffef72a48c5a5cc311ac.js | AI (source-diff): Webpack bundle for compositions preview; regenerator-runtime and standard React code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/874.3ef824f68e8be46dbe18.js | AI (source-diff): Webpack bundle for Bit preview modules; minified but not obfuscated malware. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.f6cbad17a9f4c2c3a1c9.js | AI (source-diff): Webpack chunk; net-exec pattern is normal for bundled UI artifacts. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.f6cbad17a9f4c2c3a1c9.js | AI (source-diff): Standard webpack bundle shipping floating-ui React library; not malicious. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js | AI (source-diff): Webpack chunk with __webpack_require__; network+exec pattern is normal for bundled UI code. | ai | |
| dependencies | unvetted-dep:@bitdev/node.generators.node-starters | AI (dependencies): Internal bitdev scoped package; consistent with established Bit ecosystem publisher. | ai | |
| dependencies | unvetted-dep:@teambit/toolbox.path.path | AI (dependencies): First-party Teambit ecosystem dep; consistent with this package's component toolchain pattern. | ai | |
| dependencies | unvetted-dep:@bitdev/node.generators.node-templates | AI (dependencies): Bitdev/Teambit ecosystem dep; expected dependency for node environment/generator tooling. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.d8c63cae14c8e0c9477f.js | AI (source-diff): Standard webpack-minified peer bundle exposing React/MDX globals for Bit preview; benign pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.f38d8c0becc101e2acaa.js | AI (source-diff): Standard webpack-minified UI preview chunk for Bit component preview system. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.41ee340a90bc2ac5075a.js | AI (source-diff): Standard webpack-minified UI preview chunk; contains regenerator-runtime and Bit preview module code. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.e95ef396af1977740144.js | AI (source-diff): Standard webpack bundle in Bit env-template preview artifacts; consistent with teambit build pipeline across all versions. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.87f56294904adf4fe9ad.js | AI (source-diff): Standard webpack bundle exposing React/MDX peers for Bit preview; consistent with teambit build pipeline. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.66b9227529c261d0a62a.js | AI (source-diff): Standard webpack bundle in Bit env-template preview artifacts; consistent with teambit build pipeline across all versions. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.8ee1fc46c15733b32f9c.js | AI (source-diff): Webpack-bundled env-template preview chunk; minification expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.88c645eebaf3a51be3f4.js | AI (source-diff): Webpack-bundled env-template preview chunk; minification expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.fe4b301b30825fe7ebd3.js | AI (source-diff): Webpack-bundled env-template preview chunk; minification expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js | AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.403bb39a4ad28f6ad7f6.js | AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.278cf9c7e3930c08fb1c.js | AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.8a4e03fc8ba8ef6890d6.js | AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js | AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; standard bundler pattern, not dropper. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/760.847613853bcbcc911626.js | AI (source-diff): Network refs and dynamic require are webpack runtime patterns in Bit preview bundles, not dropper behavior. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.bb185d544a29f45b74bb.js | AI (source-diff): Standard webpack-minified peers bundle for Bit preview; new Function is webpack runtime pattern. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.55589fe7b2efb028382c.js | AI (source-diff): Standard webpack-minified UI preview chunk for Bit component overview. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.78414b1d03731ec8ab70.js | AI (source-diff): Standard webpack-minified UI preview chunk for Bit component compositions. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/760.847613853bcbcc911626.js | AI (source-diff): Standard webpack-minified UI preview chunk; pattern is stable across all @teambit/node versions. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js | AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; not dropper malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js | AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js | AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; not dropper malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.ceaa34095d2f6321efcf.js | AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.df61829d14e1257c0499.js | AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.421ef9c615d8af6eb7f4.js | AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js | AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.03557bc770ae79381b47.js | AI (source-diff): Webpack-bundled Bit preview module artifact; minification expected. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js | AI (source-diff): Standard webpack chunk; net+exec pattern is from bundled UI preview, not malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js | AI (source-diff): Webpack-bundled floating-ui/React UI artifact; minification expected in env-template build output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js | AI (source-diff): Standard webpack chunk with __webpack_require__; network+exec pattern is from bundled UI preview, not malware. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js | AI (source-diff): Webpack-bundled UI preview artifact; minification is expected for this package's env-template build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.3f9923d78ac19fbc8c0c.js | AI (source-diff): Webpack-bundled peers bundle for Bit env-template; minification expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.9afe0976ce35f6a6a6a4.js | AI (source-diff): Webpack-bundled Bit preview artifact; minification expected. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.ff8699ad93908740082a.js | AI (source-diff): Standard webpack build artifact for Bit preview; content is recognizable React/regenerator code, not malicious. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.9efab5c153d48c47b643.js | AI (source-diff): Standard webpack build artifact for Bit preview; content is recognizable React/preview module code, not malicious. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.29b71fc864b102427c73.js | AI (source-diff): Standard webpack build artifact exposing peer deps (React, ReactDom) for Bit preview; not malicious. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js | AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/overview.c6321ae4b79c6bb228ee.js | AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/peers.612ea8565c133d85ac66.js | AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output. | ai | |
| source-diff | obfuscated-file:artifacts/env-template/public/compositions.902a1287b720668a5349.js | AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output. | ai | |
| source-diff | net-exec-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js | AI (source-diff): Network+exec pattern is webpack module loading in a browser preview bundle, not dropper malware. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-mdx | AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. | ai | |
| typosquat | typosquat.levenshtein:zod | AI (typosquat): Scoped @teambit/node package; Levenshtein match to 'zod' is a clear false positive. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside a webpack bundle artifact; standard build tool pattern for this package. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. | ai | |
| phantom-deps | phantom-dep:core-js | AI (phantom-deps): Known implicit runtime dependency pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:eslint-mdx | AI (phantom-deps): Referenced in ESLint config files; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/eslint-plugin | AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react-hooks | AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:@typescript-eslint/parser | AI (phantom-deps): ESLint config reference; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jsx-a11y | AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-import | AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-react | AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. | ai | |
| phantom-deps | phantom-dep:eslint-plugin-jest | AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. | ai |
Versions (showing 42 of 42)
| Version | Deps | Published |
|---|---|---|
| 1.0.1064 | 39 / 7 | |
| 1.0.1060 | 39 / 7 | |
| 1.0.1055 | 39 / 7 | |
| 1.0.1052 | 39 / 7 | |
| 1.0.1021 | 39 / 7 | |
| 1.0.1008 | 39 / 7 | |
| 1.0.995 | 39 / 7 | |
| 1.0.982 | 39 / 7 | |
| 1.0.975 | 39 / 7 | |
| 1.0.972 | 39 / 7 | |
| 1.0.971 | 39 / 7 | |
| 1.0.970 | 39 / 7 | |
| 1.0.969 | 39 / 7 | |
| 1.0.968 | 39 / 7 | |
| 1.0.967 | 39 / 7 | |
| 1.0.945 | 39 / 7 | |
| 1.0.944 | 39 / 7 | |
| 1.0.943 | 39 / 7 | |
| 1.0.938 | 39 / 7 | |
| 1.0.936 | 39 / 7 | |
| 1.0.935 | 39 / 7 | |
| 1.0.933 | 39 / 7 | |
| 1.0.930 | 39 / 7 | |
| 1.0.926 | 39 / 7 | |
| 1.0.925 | 39 / 7 | |
| 1.0.867 | 39 / 7 | |
| 1.0.797 | 39 / 7 | |
| 1.0.630 | 39 / 7 | |
| 1.0.628 | 39 / 7 | |
| 1.0.626 | 39 / 7 | |
| 1.0.625 | 39 / 7 | |
| 1.0.624 | 39 / 7 | |
| 1.0.623 | 39 / 7 | |
| 1.0.621 | 39 / 7 | |
| 1.0.617 | 39 / 7 | |
| 1.0.573 | 39 / 7 | |
| 1.0.571 | 39 / 7 | |
| 1.0.535 | 37 / 7 | |
| 1.0.515 | 37 / 7 | |
| 1.0.514 | 37 / 7 | |
| 1.0.277 | 36 / 7 | |
| 1.0.261 | 36 / 7 |
v1.0.1064
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1060
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1055
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1052
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.867
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.797
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.573
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.571
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.535
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.515
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.514
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.277
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.261
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.