← Home

@teambit/node

42
Versions
SEE LICENSE IN UNLICENSED
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

teambit-ownershohamgiladdavidfirstranm8guysaaritaymendelerezbitjoshk2redigmayona007

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:artifacts/env-template/public/compositions.b23dc86e21e565be31ac.js AI (source-diff): Bundled build output, analyzer itself labels non-obfuscated. ai
publish-pattern rapid-publish AI (publish-pattern): Teambit publishes dozens of monorepo packages together in short windows routinely. ai
source-diff net-exec-file:artifacts/env-template/public/peers.3e1f9bd12ac3d9e10956.js AI (source-diff): React/webpack runtime code misidentified as net+exec dropper pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3e1f9bd12ac3d9e10956.js AI (source-diff): Webpack bundle containing React/MDX runtime, not obfuscated malware. ai
source-diff net-exec-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js AI (source-diff): Standard webpack module runtime; no external fetch+exec behavior evident. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.617496fcc89620f59f28.js AI (source-diff): Bundled build output, analyzer itself labels non-obfuscated. ai
source-diff obfuscated-file:artifacts/env-template/public/54.9e90b5c8f2ad6246d0bd.js AI (source-diff): Webpack-bundled preview UI chunk; minified build output, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/611.2e7acbee3ea0502837ad.js AI (source-diff): Webpack-bundled preview UI chunk containing Bit's own dependency policy config, not malware. ai
source-diff obfuscated-file:artifacts/env-template/public/368.7f4510ee81e9120e0b0a.js AI (source-diff): Bundled webpack module, benign. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.2ccfb064bf34702ba20b.js AI (source-diff): Bundled build output, minified. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.70ac7750777324d9fefc.js AI (source-diff): Bundled build output, minified. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.e95e08a4e31e9848daee.js AI (source-diff): Bundled React runtime code, benign. ai
source-diff net-exec-file:artifacts/env-template/public/peers.e95e08a4e31e9848daee.js AI (source-diff): Bundled build output, benign. ai
source-diff net-exec-file:artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js AI (source-diff): Bundled build output, no fetched-binary/exfil behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js AI (source-diff): Webpack-bundled preview UI asset, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.701e47606ddfc074bb91.js AI (source-diff): Bundled webpack output, regenerator-runtime boilerplate. ai
source-diff net-exec-file:artifacts/env-template/public/peers.3210f6cfda3ea182f4fc.js AI (source-diff): React/MDX bundle, no evidence of exfil or dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3210f6cfda3ea182f4fc.js AI (source-diff): Bundled webpack output for MDX/React preview scope. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.5762cc1ae208c080a02b.js AI (source-diff): Bundled webpack output, regenerator-runtime boilerplate. ai
source-diff net-exec-file:artifacts/env-template/public/753.633354a157780af09402.js AI (source-diff): Bundled Bit workspace/dependency-resolver config data, not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/753.633354a157780af09402.js AI (source-diff): Webpack-bundled preview UI asset containing workspace config, not malicious payload. ai
source-diff obfuscated-file:artifacts/env-template/public/244.508e6438cc297ec46e93.js AI (source-diff): Webpack-bundled preview UI asset; minified not obfuscated. ai
source-diff net-exec-file:artifacts/env-template/public/peers.d234ce3f647bf7375488.js AI (source-diff): Bundled loader pattern, no hostile destination. ai
source-diff net-exec-file:artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js AI (source-diff): Bundled loader pattern, benign config data. ai
source-diff obfuscated-file:artifacts/env-template/public/586.3b2f16376c69f7f926c8.js AI (source-diff): Bundled preview-module code, not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js AI (source-diff): Bundled chunk loader pattern, no exfil destination present. ai
source-diff obfuscated-file:artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js AI (source-diff): Bundled Bit workspace config JS, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.10a01b3ba530ac5257ed.js AI (source-diff): Minified bundler output confirmed by artifact label. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.f2945ef274ccad3165a6.js AI (source-diff): Minified bundler output confirmed by artifact label. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d234ce3f647bf7375488.js AI (source-diff): Bundled polyfills/MDX scope code, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js AI (source-diff): Webpack-bundled UI deps (floating-ui etc.), not obfuscation. ai
provenance no-provenance AI (provenance): Provenance adoption is optional; absence is common and not a risk for this mature package. ai
npm-metadata no-description AI (npm-metadata): Established package; missing description is benign metadata. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.aca5a9abd56efb01f661.js AI (source-diff): Bundled preview-module linking code, standard build output. ai
source-diff obfuscated-file:artifacts/env-template/public/976.131be05c5afb105432da.js AI (source-diff): Bundled dependency-resolver policy/config chunk, standard build output. ai
source-diff obfuscated-file:artifacts/env-template/public/320.901d818bee5d1e4c5580.js AI (source-diff): Bundled MDX library chunk, standard build output. ai
source-diff net-exec-file:artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js AI (source-diff): Bundled third-party UI libs, no dropper/loader behavior present. ai
source-diff obfuscated-file:artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js AI (source-diff): Webpack-bundled UI preview chunk (floating-ui/react libs), not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.843c7f03e8ab810459fc.js AI (source-diff): Confirmed bundler minified output per finding detail. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.87bf52fdc03ea774bc2d.js AI (source-diff): Confirmed bundler minified output per finding detail. ai
publish-pattern new-deps-added AI (publish-pattern): Sibling @bitdev/@teambit generator package, consistent with monorepo tooling. ai
source-diff net-exec-file:artifacts/env-template/public/976.131be05c5afb105432da.js AI (source-diff): GraphQL library internals bundled in, not a loader/dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/320.762ef2b410b3d3456b80.js AI (source-diff): Bundled MDX library output, minified not obfuscated. ai
maintainer-change maintainer-removed AI (maintainer-change): Large monorepo publisher with 6033 approved packages; routine maintainer roster change. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.365e203b2fc35c3b2579.js AI (source-diff): Bundled peer-exposure shim, minified webpack output. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.567af5919fc6dc2d8f4c.js AI (source-diff): Bundled preview code, minified webpack output. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.b77f46880298d1bad0b5.js AI (source-diff): Bundled preview-module linking code, standard minified output. ai
source-diff net-exec-file:artifacts/env-template/public/847.926d4d3482765239c0b9.js AI (source-diff): Same bundle; no dropper/exfil behavior evident. ai
source-diff obfuscated-file:artifacts/env-template/public/847.926d4d3482765239c0b9.js AI (source-diff): Env-template dependency policy bundle; legitimate config data, not malicious. ai
source-diff net-exec-file:artifacts/env-template/public/252.041540aaf75a9dc05f44.js AI (source-diff): Bundled UI lib; no exfil/dropper behavior found in sample. ai
source-diff obfuscated-file:artifacts/env-template/public/252.041540aaf75a9dc05f44.js AI (source-diff): Webpack-bundled floating-ui library, minified not obfuscated. ai
source-diff obfuscated-file:artifacts/env-template/public/252.b5ab902b1a0f137defb9.js AI (source-diff): Webpack-bundled UI preview chunk, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3e05d46329040ae867db.js AI (source-diff): Bundled peers-exposure helper for React/ReactDOM globals. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.ccca614c065f74d2ea59.js AI (source-diff): Bundled webpack chunk with regenerator-runtime helper. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.7c6728df46cb8b08d582.js AI (source-diff): Bundled preview-modules chunk. ai
source-diff net-exec-file:artifacts/env-template/public/608.e6d2d2cfbf48fb5a7ad7.js AI (source-diff): Bundled config/runtime, not a dropper. ai
source-diff obfuscated-file:artifacts/env-template/public/608.e6d2d2cfbf48fb5a7ad7.js AI (source-diff): Bundled env config chunk from teambit's own template. ai
source-diff net-exec-file:artifacts/env-template/public/252.b5ab902b1a0f137defb9.js AI (source-diff): Bundled webpack runtime, no dropper behavior. ai
source-diff net-exec-file:artifacts/env-template/public/96.ee1cbf5a28d053ff9d4f.js AI (source-diff): Bundled config/runtime setup code, no fetched binary or exfil destination. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.a1c638f4dd41363220bf.js AI (source-diff): Bundled peer-exposure shim for React/ReactDOM, standard Bit env-template pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.692ed07fdb68bb8ce268.js AI (source-diff): Bundled preview module with regenerator-runtime helper, standard build output. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.7b87f6c7c76ce3490a10.js AI (source-diff): Bundled preview module code, minified build output. ai
source-diff obfuscated-file:artifacts/env-template/public/96.ee1cbf5a28d053ff9d4f.js AI (source-diff): Webpack-bundled preview UI chunk, not true obfuscation; part of documented env-template build output. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.51a844e9507d9e7134b0.js AI (source-diff): Standard webpack bundle output. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.181c53322f0a17fd6f2f.js AI (source-diff): Webpack bootstrap bundle exposing peers globally, documented pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.93d3a0dfdcf975fd9e9b.js AI (source-diff): Standard webpack bundle output. ai
source-diff net-exec-file:artifacts/env-template/public/134.05dcf5ec5c072f2a1e5f.js AI (source-diff): Bundled webpack runtime, no fetched-binary or exfil behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d1f4bb6e74ef33dffe75.js AI (source-diff): Bundled peer-exposure shim, minified build output. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.9d287744d5fa8c79c2ff.js AI (source-diff): Bundled preview module chunk, minified build output. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.2509fe8d4be8f459070a.js AI (source-diff): Bundled preview module chunk, minified build output. ai
source-diff net-exec-file:artifacts/env-template/public/252.6cade8d3bfeee6fa9560.js AI (source-diff): Bundled webpack runtime, no malicious network target. ai
source-diff obfuscated-file:artifacts/env-template/public/252.6cade8d3bfeee6fa9560.js AI (source-diff): Bundled third-party UI lib (floating-ui) chunk, minified build output. ai
source-diff obfuscated-file:artifacts/env-template/public/134.05dcf5ec5c072f2a1e5f.js AI (source-diff): Webpack-bundled preview artifact, minified not obfuscated. ai
source-diff net-exec-file:artifacts/env-template/public/252.9de18b929171b16a2b43.js AI (source-diff): Bundled preview UI code, no malicious network/exec behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.5fca524d5de3899dfbb7.js AI (source-diff): Bundled peer-exposure chunk, standard webpack pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.2cc858092325681ebd15.js AI (source-diff): Bundled preview module chunk with regenerator-runtime. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.f1294097892eff1540ba.js AI (source-diff): Bundled preview module chunk. ai
source-diff net-exec-file:artifacts/env-template/public/652.d81ff018143c2d893013.js AI (source-diff): Bundled config/build code, no malicious dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/652.d81ff018143c2d893013.js AI (source-diff): Bundled Bit workspace config chunk, minified not obfuscated. ai
source-diff obfuscated-file:artifacts/env-template/public/548.793da35237bf9f418835.js AI (source-diff): Bundled MDX library chunk, minified not obfuscated. ai
source-diff obfuscated-file:artifacts/env-template/public/252.9de18b929171b16a2b43.js AI (source-diff): Webpack-bundled UI chunk, not true obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.8625d6b119225858feee.js AI (source-diff): Standard webpack bundle output. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.26b418143697aa562177.js AI (source-diff): Bundled peer-exposure shim, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.aab56ff891341170ca0b.js AI (source-diff): Standard webpack bundle output. ai
source-diff obfuscated-file:artifacts/env-template/public/885.e718bc54f2f10a05b585.js AI (source-diff): Bundled preview config/build artifact, not obfuscated. ai
source-diff net-exec-file:artifacts/env-template/public/252.4b29a16fd35fccc41dd4.js AI (source-diff): Bundled preview code; no malicious network/exec behavior found. ai
source-diff obfuscated-file:artifacts/env-template/public/252.4b29a16fd35fccc41dd4.js AI (source-diff): Webpack-bundled preview UI code, minified not obfuscated. ai
source-diff net-exec-file:artifacts/env-template/public/885.e718bc54f2f10a05b585.js AI (source-diff): Bundled preview code; no exfil/dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.e47642c040dc15a6775d.js AI (source-diff): Bundled webpack preview asset. ai
source-diff obfuscated-file:artifacts/env-template/public/252.bd15eed8c9f5390df3f3.js AI (source-diff): Bundled webpack preview asset, not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/252.bd15eed8c9f5390df3f3.js AI (source-diff): Webpack chunk loader, no exfil/dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/686.66255e0b1247f8b13a2a.js AI (source-diff): Bundled webpack preview asset, not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/686.66255e0b1247f8b13a2a.js AI (source-diff): Webpack chunk loader, no exfil/dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.af5154485afafb07e392.js AI (source-diff): Bundled webpack preview asset. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.8e15181df47bfc9caee4.js AI (source-diff): Bundled webpack preview asset. ai
source-diff obfuscated-file:artifacts/env-template/public/252.cfbbe78375029bf4f4fa.js AI (source-diff): Webpack-bundled UI preview artifact; minification is expected for this package's env-template output. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.0296edc69ee2c529bc9e.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.2c57bcd330fdc4c1718e.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected. ai
source-diff net-exec-file:artifacts/env-template/public/peers.2c57bcd330fdc4c1718e.js AI (source-diff): Webpack chunk loader pattern in browser preview bundle, not malware. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.1f75bec3ea1f3ee349fc.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/944.23c7a42c25b29314f834.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected. ai
source-diff net-exec-file:artifacts/env-template/public/616.cffce716fb743542f985.js AI (source-diff): Webpack chunk loader pattern in browser preview bundle, not malware. ai
source-diff obfuscated-file:artifacts/env-template/public/616.cffce716fb743542f985.js AI (source-diff): Webpack-bundled UI preview artifact; minification expected. ai
source-diff net-exec-file:artifacts/env-template/public/252.cfbbe78375029bf4f4fa.js AI (source-diff): Network+exec pattern is from webpack chunk loader in browser preview bundle, not malware. ai
source-diff net-exec-file:artifacts/env-template/public/252.c9ab17bbccedfe3d2254.js AI (source-diff): Webpack chunk loader pattern; network refs are CDN icon URLs and dynamic require is webpack's __webpack_require__, not malicious. ai
source-diff net-exec-file:artifacts/env-template/public/peers.5b3e3e6216c2613f1990.js AI (source-diff): Dynamic execution is webpack chunk loading; no malicious network calls present. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.5b3e3e6216c2613f1990.js AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.c570932c16085d8cda15.js AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.827ddc797268dbf4dd8a.js AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. ai
source-diff net-exec-file:artifacts/env-template/public/541.3e2065c1d9de461ef814.js AI (source-diff): Network refs are static.bit.dev icon URLs; dynamic execution is webpack __webpack_require__. ai
source-diff obfuscated-file:artifacts/env-template/public/541.3e2065c1d9de461ef814.js AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. ai
source-diff obfuscated-file:artifacts/env-template/public/348.c7479d1547f3ca674a78.js AI (source-diff): Standard webpack-minified UI bundle for Bit env-template preview. ai
source-diff obfuscated-file:artifacts/env-template/public/252.c9ab17bbccedfe3d2254.js AI (source-diff): Standard webpack-minified UI bundle; part of Bit env-template preview artifacts shipped in every release. ai
source-diff obfuscated-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js AI (source-diff): Standard webpack bundle for Bit env-template UI preview; not obfuscated malware. ai
source-diff net-exec-file:artifacts/env-template/public/peers.8609c56a3038c8ebc4b7.js AI (source-diff): Webpack chunk; net-exec pattern is normal for bundled UI artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.8609c56a3038c8ebc4b7.js AI (source-diff): Webpack bundle shipping MDX/React peer deps; minified but clearly legitimate. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.9174546e5244c954aeb0.js AI (source-diff): Webpack bundle for overview preview; standard minified React code. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.ffef72a48c5a5cc311ac.js AI (source-diff): Webpack bundle for compositions preview; regenerator-runtime and standard React code. ai
source-diff obfuscated-file:artifacts/env-template/public/874.3ef824f68e8be46dbe18.js AI (source-diff): Webpack bundle for Bit preview modules; minified but not obfuscated malware. ai
source-diff net-exec-file:artifacts/env-template/public/252.f6cbad17a9f4c2c3a1c9.js AI (source-diff): Webpack chunk; net-exec pattern is normal for bundled UI artifacts. ai
source-diff obfuscated-file:artifacts/env-template/public/252.f6cbad17a9f4c2c3a1c9.js AI (source-diff): Standard webpack bundle shipping floating-ui React library; not malicious. ai
source-diff net-exec-file:artifacts/env-template/public/243.dac9adbf4f7ad2acb210.js AI (source-diff): Webpack chunk with __webpack_require__; network+exec pattern is normal for bundled UI code. ai
dependencies unvetted-dep:@bitdev/node.generators.node-starters AI (dependencies): Internal bitdev scoped package; consistent with established Bit ecosystem publisher. ai
dependencies unvetted-dep:@teambit/toolbox.path.path AI (dependencies): First-party Teambit ecosystem dep; consistent with this package's component toolchain pattern. ai
dependencies unvetted-dep:@bitdev/node.generators.node-templates AI (dependencies): Bitdev/Teambit ecosystem dep; expected dependency for node environment/generator tooling. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.d8c63cae14c8e0c9477f.js AI (source-diff): Standard webpack-minified peer bundle exposing React/MDX globals for Bit preview; benign pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.f38d8c0becc101e2acaa.js AI (source-diff): Standard webpack-minified UI preview chunk for Bit component preview system. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.41ee340a90bc2ac5075a.js AI (source-diff): Standard webpack-minified UI preview chunk; contains regenerator-runtime and Bit preview module code. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.e95ef396af1977740144.js AI (source-diff): Standard webpack bundle in Bit env-template preview artifacts; consistent with teambit build pipeline across all versions. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.87f56294904adf4fe9ad.js AI (source-diff): Standard webpack bundle exposing React/MDX peers for Bit preview; consistent with teambit build pipeline. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.66b9227529c261d0a62a.js AI (source-diff): Standard webpack bundle in Bit env-template preview artifacts; consistent with teambit build pipeline across all versions. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.8ee1fc46c15733b32f9c.js AI (source-diff): Webpack-bundled env-template preview chunk; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.88c645eebaf3a51be3f4.js AI (source-diff): Webpack-bundled env-template preview chunk; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.fe4b301b30825fe7ebd3.js AI (source-diff): Webpack-bundled env-template preview chunk; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.403bb39a4ad28f6ad7f6.js AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.278cf9c7e3930c08fb1c.js AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.8a4e03fc8ba8ef6890d6.js AI (source-diff): Standard webpack-minified UI preview chunk from Bit platform; not obfuscation. ai
source-diff net-exec-file:artifacts/env-template/public/32.4a5bfd3b1b4cefd65f08.js AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; standard bundler pattern, not dropper. ai
source-diff net-exec-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Network refs and dynamic require are webpack runtime patterns in Bit preview bundles, not dropper behavior. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.bb185d544a29f45b74bb.js AI (source-diff): Standard webpack-minified peers bundle for Bit preview; new Function is webpack runtime pattern. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.55589fe7b2efb028382c.js AI (source-diff): Standard webpack-minified UI preview chunk for Bit component overview. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.78414b1d03731ec8ab70.js AI (source-diff): Standard webpack-minified UI preview chunk for Bit component compositions. ai
source-diff obfuscated-file:artifacts/env-template/public/760.847613853bcbcc911626.js AI (source-diff): Standard webpack-minified UI preview chunk; pattern is stable across all @teambit/node versions. ai
source-diff net-exec-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. ai
source-diff net-exec-file:artifacts/env-template/public/271.8983b12775e9c1379e11.js AI (source-diff): Webpack chunk with __webpack_require__ dynamic loading; not dropper malware. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.ceaa34095d2f6321efcf.js AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.df61829d14e1257c0499.js AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.421ef9c615d8af6eb7f4.js AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. ai
source-diff obfuscated-file:artifacts/env-template/public/252.a4ec8971a39563ffeeaa.js AI (source-diff): Standard webpack bundle artifact; minification is expected for UI preview chunks in this package. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.03557bc770ae79381b47.js AI (source-diff): Webpack-bundled Bit preview module artifact; minification expected. ai
source-diff net-exec-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Standard webpack chunk; net+exec pattern is from bundled UI preview, not malware. ai
source-diff obfuscated-file:artifacts/env-template/public/624.bc39f54c0b0fdd16b3a5.js AI (source-diff): Webpack-bundled floating-ui/React UI artifact; minification expected in env-template build output. ai
source-diff net-exec-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Standard webpack chunk with __webpack_require__; network+exec pattern is from bundled UI preview, not malware. ai
source-diff obfuscated-file:artifacts/env-template/public/372.747516dd003c8cd1f1c0.js AI (source-diff): Webpack-bundled UI preview artifact; minification is expected for this package's env-template build output. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.3f9923d78ac19fbc8c0c.js AI (source-diff): Webpack-bundled peers bundle for Bit env-template; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.9afe0976ce35f6a6a6a4.js AI (source-diff): Webpack-bundled Bit preview artifact; minification expected. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.ff8699ad93908740082a.js AI (source-diff): Standard webpack build artifact for Bit preview; content is recognizable React/regenerator code, not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.9efab5c153d48c47b643.js AI (source-diff): Standard webpack build artifact for Bit preview; content is recognizable React/preview module code, not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.29b71fc864b102427c73.js AI (source-diff): Standard webpack build artifact exposing peer deps (React, ReactDom) for Bit preview; not malicious. ai
source-diff obfuscated-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output, not obfuscation. ai
source-diff obfuscated-file:artifacts/env-template/public/overview.c6321ae4b79c6bb228ee.js AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output. ai
source-diff obfuscated-file:artifacts/env-template/public/peers.612ea8565c133d85ac66.js AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output. ai
source-diff obfuscated-file:artifacts/env-template/public/compositions.902a1287b720668a5349.js AI (source-diff): Standard webpack bundle for Bit env-template preview; minification is expected build output. ai
source-diff net-exec-file:artifacts/env-template/public/382.565b03c5d3748e06fc46.js AI (source-diff): Network+exec pattern is webpack module loading in a browser preview bundle, not dropper malware. ai
phantom-deps phantom-dep:eslint-plugin-mdx AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Scoped @teambit/node package; Levenshtein match to 'zod' is a clear false positive. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside a webpack bundle artifact; standard build tool pattern for this package. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Known implicit runtime dependency pattern; stable false positive for this package. ai
phantom-deps phantom-dep:eslint-mdx AI (phantom-deps): Referenced in ESLint config files; not a direct import by design. ai
phantom-deps phantom-dep:@typescript-eslint/eslint-plugin AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. ai
phantom-deps phantom-dep:eslint-plugin-react-hooks AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. ai
phantom-deps phantom-dep:@typescript-eslint/parser AI (phantom-deps): ESLint config reference; not directly imported by design. ai
phantom-deps phantom-dep:eslint-plugin-jsx-a11y AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. ai
phantom-deps phantom-dep:eslint-plugin-import AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. ai
phantom-deps phantom-dep:eslint-plugin-react AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. ai
phantom-deps phantom-dep:eslint-plugin-jest AI (phantom-deps): ESLint plugin referenced in config; not directly imported by design. ai

Versions (showing 42 of 42)

Version Deps Published
1.0.1064 39 / 7
1.0.1060 39 / 7
1.0.1055 39 / 7
1.0.1052 39 / 7
1.0.1021 39 / 7
1.0.1008 39 / 7
1.0.995 39 / 7
1.0.982 39 / 7
1.0.975 39 / 7
1.0.972 39 / 7
1.0.971 39 / 7
1.0.970 39 / 7
1.0.969 39 / 7
1.0.968 39 / 7
1.0.967 39 / 7
1.0.945 39 / 7
1.0.944 39 / 7
1.0.943 39 / 7
1.0.938 39 / 7
1.0.936 39 / 7
1.0.935 39 / 7
1.0.933 39 / 7
1.0.930 39 / 7
1.0.926 39 / 7
1.0.925 39 / 7
1.0.867 39 / 7
1.0.797 39 / 7
1.0.630 39 / 7
1.0.628 39 / 7
1.0.626 39 / 7
1.0.625 39 / 7
1.0.624 39 / 7
1.0.623 39 / 7
1.0.621 39 / 7
1.0.617 39 / 7
1.0.573 39 / 7
1.0.571 39 / 7
1.0.535 37 / 7
1.0.515 37 / 7
1.0.514 37 / 7
1.0.277 36 / 7
1.0.261 36 / 7

v1.0.1064

8 findings
HIGH New obfuscated file: artifacts/env-template/public/54.9e90b5c8f2ad6246d0bd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/611.2e7acbee3ea0502837ad.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/611.2e7acbee3ea0502837ad.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.b23dc86e21e565be31ac.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.617496fcc89620f59f28.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.3e1f9bd12ac3d9e10956.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.3e1f9bd12ac3d9e10956.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1060

8 findings
HIGH New obfuscated file: artifacts/env-template/public/244.508e6438cc297ec46e93.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/753.633354a157780af09402.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/753.633354a157780af09402.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.5762cc1ae208c080a02b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.701e47606ddfc074bb91.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.3210f6cfda3ea182f4fc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.3210f6cfda3ea182f4fc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1055

10 findings
HIGH New obfuscated file: artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/137.4d4a5db1e3ac30f40668.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/368.7f4510ee81e9120e0b0a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.2ccfb064bf34702ba20b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.70ac7750777324d9fefc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.e95e08a4e31e9848daee.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.e95e08a4e31e9848daee.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1052

10 findings
HIGH New obfuscated file: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.337fa9edd6cd19b0bf10.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/444.f9f45c33cfc87ef93e69.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/586.3b2f16376c69f7f926c8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.10a01b3ba530ac5257ed.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/overview.f2945ef274ccad3165a6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.d234ce3f647bf7375488.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/peers.d234ce3f647bf7375488.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.867

9 findings
HIGH New obfuscated file: artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.ef92e2e1cc9cf5b4d8e8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/320.901d818bee5d1e4c5580.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/976.131be05c5afb105432da.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/976.131be05c5afb105432da.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.aca5a9abd56efb01f661.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/overview.843c7f03e8ab810459fc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.87bf52fdc03ea774bc2d.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.797

9 findings
HIGH New obfuscated file: artifacts/env-template/public/252.041540aaf75a9dc05f44.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/252.041540aaf75a9dc05f44.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/320.762ef2b410b3d3456b80.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/847.926d4d3482765239c0b9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: artifacts/env-template/public/847.926d4d3482765239c0b9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/compositions.b77f46880298d1bad0b5.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: artifacts/env-template/public/overview.567af5919fc6dc2d8f4c.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: artifacts/env-template/public/peers.365e203b2fc35c3b2579.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.573

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.571

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.535

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.515

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.514

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.277

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.261

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.