@unisphere/dev
Local development server for the Unisphere ecosystem
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/assets/index-EuN0GUZY.js | AI (source-diff): Vite-bundled client asset from documented build:client script, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-TN2rkTcm.js | AI (source-diff): Vite-bundled React client asset, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BZ151Qz9.js | AI (source-diff): Vite/React bundled client asset, not obfuscation; expected from build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DR98fMFP.js | AI (source-diff): Standard vite-bundled client asset, not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-ByKPHt5Z.js | AI (source-diff): Vite/React client bundle, minified build output not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-oMGNRAFL.js | AI (source-diff): Vite-bundled client JS (React), long lines are minification not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-leXUSHZx.js | AI (source-diff): Vite/React bundled client asset, long minified lines mislabeled as obfuscation; no malicious code. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-CXgu97el.js | AI (source-diff): Vite-bundled client JS (React internals visible); minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Dw3v7_fu.js | AI (source-diff): Minified Vite/React client bundle, not obfuscation; expected build output for this package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-CLfw_pOy.js | AI (source-diff): Vite/esbuild bundled client asset, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DBnOqAME.js | AI (source-diff): Vite/React bundled client asset, not obfuscation; matches documented build:client output. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-C4j82llY.js | AI (source-diff): Vite-bundled client JS, minified not obfuscated; expected build artifact for this dev-server package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BqJFyRM2.js | AI (source-diff): Vite/React bundled client output, not obfuscation; consistent with project's build tooling. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BIvfiF7H.js | AI (source-diff): Vite-bundled frontend asset, not obfuscation; consistent with declared build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BRwktYbh.js | AI (source-diff): Vite-bundled client JS, not obfuscation; matches package's own build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-NLN2vz6G.js | AI (source-diff): Vite-bundled client assets from build:client script; long lines are minification, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-CMxErQlL.js | AI (source-diff): Vite-bundled client asset, minified not obfuscated; matches build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-AuJ8FV68.js | AI (source-diff): Vite/React client bundle output, not obfuscation; matches build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Dke03Nmd.js | AI (source-diff): Vite-bundled React client build output, minified not obfuscated; regenerated each build. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-CMGq3D0V.js | AI (source-diff): Vite build output for the client dev UI, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BPkm2fPx.js | AI (source-diff): Vite/React bundled client asset, not obfuscated code; matches build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-mtoe9JBD.js | AI (source-diff): Vite-bundled client JS (React/modulepreload code visible), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-B6yxjrh0.js | AI (source-diff): Vite/rollup bundled client output, not obfuscation; matches build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BmNcJ5Oq.js | AI (source-diff): Vite-bundled client asset, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DK2OCoO5.js | AI (source-diff): Vite/esbuild bundle output from documented build:client step, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DFnjE7s3.js | AI (source-diff): Vite/React minified client bundle, not obfuscation; matches build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-BO2bcpuz.js | AI (source-diff): Vite/React client bundle, standard minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Bh8fZUx8.js | AI (source-diff): Vite-bundled client asset, minified not obfuscated; matches build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-7HHJuihh.js | AI (source-diff): Vite/React bundled client output, not obfuscation; matches package's own build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-JmbQcnUD.js | AI (source-diff): Vite/esbuild bundled client asset, not obfuscation; matches build:client script. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Cc1nQsfU.js | AI (source-diff): Vite-bundled client asset (React/module-preload), not obfuscation; matches build:client output. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): multer is a standard, well-vetted upload middleware fitting the dev-server's express stack. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-CXsMe6-4.js | AI (source-diff): Vite/React client bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-CvColpAg.js | AI (source-diff): Vite-bundled React client asset; standard minified build output for this package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-D6mF3iRu.js | AI (source-diff): Vite-bundled React client asset; minification is expected for this package's client UI build output. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-Cf-6uRgv.js | AI (source-diff): Standard Vite-bundled React client asset; minification is expected for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DDjL5KRh.js | AI (source-diff): Vite-bundled React client asset; minification is expected for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-DC1yrJxY.js | AI (source-diff): Vite-bundled React client bundle; minification is expected for this dev-server UI package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from personal account to GitHub Actions CI publish for kaltura org. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-C_Zi6nKq.js | AI (source-diff): Vite-bundled React client asset; minification is expected for this package's build output. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-B43K663f.js | AI (source-diff): Standard Vite/React minified bundle; expected build artifact for this dev-server package. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-CipQKMvF.js | AI (source-diff): Vite-bundled React client asset; minification is expected for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/client/assets/index-9nMLcZ35.js | AI (source-diff): Vite-minified React bundle; consistent with declared build pipeline (vite+react). Expected for this package. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): Scoped package @unisphere/dev is a Kaltura dev-server tool; Levenshtein match to 'ajv' is coincidental and not a typosquat. | ai |
Versions (showing 51 of 58)
| Version | Deps | Published |
|---|---|---|
| 3.12.0 | 5 / 20 | |
| 3.11.1 | 4 / 19 | |
| 3.11.0 | 4 / 19 | |
| 3.10.0 | 4 / 19 | |
| 3.9.3 | 4 / 19 | |
| 3.9.2 | 4 / 19 | |
| 3.9.1 | 4 / 19 | |
| 3.9.0 | 4 / 19 | |
| 3.8.6 | 4 / 19 | |
| 3.8.5 | 4 / 19 | |
| 3.8.4 | 4 / 19 | |
| 3.8.3 | 4 / 19 | |
| 3.8.2 | 4 / 19 | |
| 3.8.1 | 4 / 19 | |
| 3.8.0 | 4 / 19 | |
| 3.7.0 | 4 / 19 | |
| 3.6.5 | 4 / 19 | |
| 3.6.4 | 4 / 19 | |
| 3.6.3 | 4 / 19 | |
| 3.6.2 | 4 / 19 | |
| 3.6.1 | 4 / 19 | |
| 3.6.0 | 4 / 19 | |
| 3.5.1 | 4 / 19 | |
| 3.5.0 | 4 / 19 | |
| 3.4.1 | 4 / 19 | |
| 3.4.0 | 4 / 19 | |
| 3.3.6 | 4 / 19 | |
| 3.3.5 | 4 / 19 | |
| 3.3.4 | 4 / 19 | |
| 3.3.3 | 4 / 19 | |
| 3.3.2 | 4 / 19 | |
| 3.3.0 | 4 / 19 | |
| 3.2.1 | 4 / 19 | |
| 3.2.0 | 4 / 19 | |
| 3.1.1 | 4 / 19 | |
| 3.1.0 | 4 / 19 | |
| 3.0.2 | 4 / 19 | |
| 3.0.1 | 4 / 19 | |
| 3.0.0 | 4 / 19 | |
| 2.2.0 | 4 / 19 | |
| 2.1.2 | 4 / 19 | |
| 2.1.1 | 4 / 19 | |
| 2.1.0 | 4 / 19 | |
| 2.0.0 | 4 / 19 | |
| 1.5.1 | 4 / 19 | |
| 1.5.0 | 4 / 19 | |
| 1.4.2 | 4 / 19 | |
| 1.4.1 | 4 / 19 | |
| 1.4.0 | 4 / 19 | |
| 1.3.1 | 4 / 19 | |
| 1.3.0 | 4 / 19 |
v3.12.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.11.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.10.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.3
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.9.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.3.6
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.0.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.5.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.