@varlock/infisical-plugin
Varlock plugin to load secrets from Infisical
8
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
philmillmantheo
Keywords
varlockpluginvarlock-plugininfisicalsecretssecret-managementenv.envdotenvenvironment variablesenv varsconfig
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/plugin.cjs | AI (source-diff): tsup-bundled CJS output; minified lines are expected for this build artifact. | ai | |
| source-diff | net-exec-file:dist/plugin.cjs | AI (source-diff): Network calls are to Infisical API; child_process comes from bundled SDK deps — expected for a secrets plugin. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): 0.0.0 is a deliberate placeholder version for this monorepo package, not a malicious throwaway. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Stub/reserved namespace package with empty files; low-value signals are expected here. | ai |