@vechain/vechain-kit
All-in-one React library for building VeChain applications with wallet integration, social logins, developer hooks, and pre-built UI components.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-tcllbHHw.d.mts | AI (source-diff): Generated TS type-defs, large but legitimate. | ai | |
| source-diff | obfuscated-file:dist/index-DJ6mUqNG.d.cts | AI (source-diff): Generated TS type-defs, large but legitimate. | ai | |
| source-diff | obfuscated-file:dist/index-Gbh5IBmK.d.cts | AI (source-diff): TypeScript declaration file, long lines from type unions - not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-BDSRzvcF.d.mts | AI (source-diff): TypeScript declaration file, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-kNQk5OHF.d.mts | AI (source-diff): Type declaration file, long lines from bundling not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-d7QJmcUK.d.cts | AI (source-diff): Type declaration file, long lines from bundling not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-fXJ3K1K6.mjs | AI (source-diff): Bundled minified output, benign. | ai | |
| source-diff | obfuscated-file:dist/utils-B3mmhtVy.cjs | AI (source-diff): Bundled minified output containing known contract addresses, benign. | ai | |
| source-diff | obfuscated-file:dist/index-DQiXM6hu.d.cts | AI (source-diff): TypeScript declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-D0SCAGbu.d.mts | AI (source-diff): TypeScript declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-KHIaOcYe.d.cts | AI (source-diff): TypeScript declaration bundle, long lines from type re-exports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-FTYW_KQc.d.mts | AI (source-diff): TypeScript declaration bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-3EuDo9II.d.mts | AI (source-diff): TypeScript declaration file, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-o92cc2nW.d.cts | AI (source-diff): TypeScript declaration file, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-CX-PoQpp.d.mts | AI (source-diff): Long-line .d.mts type declaration bundle from tsdown build, not obfuscated JS. | ai | |
| source-diff | obfuscated-file:dist/index-BSgtiDLw.d.cts | AI (source-diff): Long-line .d.cts type declaration bundle from tsdown build, not obfuscated JS. | ai | |
| source-diff | obfuscated-file:dist/index-3NLPTwiP.d.cts | AI (source-diff): Long-line .d.cts type declaration bundle, not executable obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-CxZnepbh.d.mts | AI (source-diff): Long-line .d.mts type declaration bundle, not executable obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-C6RT-d4L.d.cts | AI (source-diff): Type declaration bundle with long lines, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-DzM-sMYy.d.mts | AI (source-diff): Type declaration bundle with long lines, not obfuscated code. | ai | |
| phantom-deps | phantom-dep:i18next-resources-to-backend | AI (phantom-deps): Used via config/dynamic import pattern for i18n backend. | ai | |
| source-diff | obfuscated-file:dist/index-B_77CDYZ.d.mts | AI (source-diff): Minified .d.mts type declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-CkflGtlh.d.cts | AI (source-diff): Minified .d.cts type declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/utils-DjpjrcqQ.mjs | AI (source-diff): Bundled ESM build output, legitimate SDK usage. | ai | |
| source-diff | obfuscated-file:dist/index-lLN0Fy0E.d.mts | AI (source-diff): TypeScript declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-DQsJ0-2w.d.cts | AI (source-diff): TypeScript declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/utils-DLxoAo_P.cjs | AI (source-diff): Bundled build output referencing legitimate vechain SDK contract addresses. | ai | |
| source-diff | obfuscated-file:dist/index-BCaysYhr.d.cts | AI (source-diff): Bundled .d.cts type declarations with long import lines, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-BZRpQp3M.d.mts | AI (source-diff): Bundled .d.mts type declarations with long import lines, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-eQhlDtCI.d.cts | AI (source-diff): TypeScript declaration bundle, long lines from type re-exports. | ai | |
| source-diff | obfuscated-file:dist/index-BNVPAknF.d.mts | AI (source-diff): TypeScript declaration bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-BQSKWDL8.d.cts | AI (source-diff): TypeScript declaration bundle, long lines are normal for generated .d.cts. | ai | |
| source-diff | obfuscated-file:dist/index-CpmIWCFY.d.mts | AI (source-diff): Generated TypeScript declaration bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-9Nctr1tw.d.mts | AI (source-diff): Type declaration bundle, not obfuscated JS; long lines from type re-exports only. | ai | |
| source-diff | obfuscated-file:dist/index-CoM8jwiv.d.cts | AI (source-diff): Type declaration bundle, not obfuscated JS; long lines from type re-exports only. | ai | |
| source-diff | obfuscated-file:dist/index-w0Yyp3-t.d.mts | AI (source-diff): Type declaration file, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-BI93V0nR.d.cts | AI (source-diff): TypeScript declaration bundle, plain readable types, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-8BC07wqK.d.mts | AI (source-diff): TypeScript declaration bundle, plain readable types, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/utils-ctNraYqK.mjs | AI (source-diff): Bundled minified ESM output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-DeETrpws.cjs | AI (source-diff): Bundled minified output with known contract addresses, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-CNYVq6tT.mjs | AI (source-diff): Bundled minified output, matches sibling cjs file, no malicious code. | ai | |
| source-diff | obfuscated-file:dist/index-DQ-Jm6mW.d.mts | AI (source-diff): Minified type declarations, build artifact. | ai | |
| source-diff | obfuscated-file:dist/utils-DcAJej3n.cjs | AI (source-diff): Bundled minified output (tsdown/rollup), not true obfuscation; no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/index-C6zk462M.d.cts | AI (source-diff): Minified .d.cts type declarations, build artifact not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-BJiGRuYS.d.mts | AI (source-diff): Long-line .d.mts type bundle from tsdown build, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-wCp9v8PQ.d.cts | AI (source-diff): Long-line .d.cts type bundle from tsdown build, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-CozseDtf.d.cts | AI (source-diff): Type declaration bundle (.d.cts) with long import lines, not executable obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-DWGrsVoL.d.mts | AI (source-diff): Type declaration bundle (.d.mts) with long import lines, not executable obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-BqitwzCD.d.cts | AI (source-diff): Generated .d.cts type declaration bundle, not obfuscated executable code. | ai | |
| source-diff | obfuscated-file:dist/index-C29c--c1.d.mts | AI (source-diff): Generated .d.mts type declaration bundle, not obfuscated executable code. | ai | |
| phantom-deps | phantom-dep:translo-cli | AI (phantom-deps): Used only in translate script, dev tooling. | ai | |
| dependencies | unvetted-dep:@choc-ui/chakra-autocomplete | AI (dependencies): Legitimate UI library used by the kit's autocomplete components. | ai | |
| dependencies | unvetted-dep:@vechain/vebetterdao-contracts | AI (dependencies): Same-org VeChain contract package, expected dependency. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): Used indirectly via config; common false positive. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Browser polyfill referenced in bundler config, not direct import. | ai | |
| phantom-deps | phantom-dep:stream-http | AI (phantom-deps): Browser polyfill, bundler config usage. | ai | |
| phantom-deps | phantom-dep:https-browserify | AI (phantom-deps): Browser polyfill, bundler config usage. | ai | |
| phantom-deps | phantom-dep:crypto-browserify | AI (phantom-deps): Browser polyfill, bundler config usage. | ai | |
| phantom-deps | phantom-dep:stream-browserify | AI (phantom-deps): Browser polyfill, bundler config usage. | ai | |
| phantom-deps | phantom-dep:@rainbow-me/rainbowkit | AI (phantom-deps): Peer/optional integration used indirectly. | ai | |
| phantom-deps | phantom-dep:@choc-ui/chakra-autocomplete | AI (phantom-deps): UI component library used indirectly. | ai | |
| phantom-deps | phantom-dep:@vechain/vebetterdao-contracts | AI (phantom-deps): Same org scope, expected. | ai | |
| source-diff | obfuscated-file:dist/index-aWHEC3vV.d.cts | AI (source-diff): Type declaration bundle with long import lines from tsdown build, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-Gsp1h6d7.d.mts | AI (source-diff): Type declaration bundle with long import lines from tsdown build, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-CpRbZET6.d.mts | AI (source-diff): Generated TypeScript declaration bundle, not code obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-BQ9mZctf.cjs | AI (source-diff): Bundled build output, references known VeChain contract addresses. | ai | |
| source-diff | obfuscated-file:dist/utils-BxZj2QIg.mjs | AI (source-diff): Bundled build output (ESM chunk). | ai | |
| source-diff | obfuscated-file:dist/index-D4rz985m.d.cts | AI (source-diff): Generated TypeScript declaration bundle, not code obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-C13QSjNa.d.mts | AI (source-diff): Generated TypeScript declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-DadZUdez.d.cts | AI (source-diff): Generated TypeScript declaration bundle, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-hEPoYu2o.d.cts | AI (source-diff): TypeScript declaration bundle, not code obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-DwvqIQlc.d.mts | AI (source-diff): TypeScript declaration bundle, not code obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-DpCZuqUP.d.mts | AI (source-diff): Bundled TS declaration file with long import lines, not executable obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-BAtr2iQI.d.cts | AI (source-diff): Bundled TS declaration file with long import lines, not executable obfuscated code. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Normal org maintainer list churn for active VeChain Foundation project. | ai | |
| source-diff | obfuscated-file:dist/assets-BL24r-Yp.mjs | AI (source-diff): Minified bundler output, matches cjs counterpart. | ai | |
| source-diff | obfuscated-file:dist/index-DShXeWMB.d.cts | AI (source-diff): Generated TypeScript declaration file, long line is type unions not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-CzaSErgL.cjs | AI (source-diff): Minified bundler output, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/assets-DNJsQD7_.cjs | AI (source-diff): Minified bundler output (tsdown/esbuild), not true obfuscation; matches known VeChain contract code. | ai | |
| source-diff | obfuscated-file:dist/index-BZGlw9Hy.d.mts | AI (source-diff): Generated TypeScript declaration file, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-D6wgzl57.mjs | AI (source-diff): Minified bundler output, matches cjs counterpart. | ai | |
| source-diff | obfuscated-file:dist/index-CWCXsRcP.d.cts | AI (source-diff): Type declaration bundle with long import lines, not obfuscated executable code. | ai | |
| source-diff | obfuscated-file:dist/index-w9zDQB56.d.mts | AI (source-diff): Type declaration bundle with long import lines, not obfuscated executable code. | ai | |
| source-diff | obfuscated-file:dist/index-hAce7WHc.d.mts | AI (source-diff): Long-line .d.mts type bundle, not obfuscated code; verified readable content. | ai | |
| source-diff | obfuscated-file:dist/index-DI76m1AO.d.cts | AI (source-diff): Long-line .d.cts type bundle, not obfuscated code; verified readable content. | ai | |
| source-diff | obfuscated-file:dist/index-BlCAiOq5.d.mts | AI (source-diff): Bundled TS declaration file (tsdown output), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-5_zBNaxA.d.cts | AI (source-diff): Bundled TS declaration file (tsdown output), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/utils-C4gc1L9t.cjs | AI (source-diff): Standard minified build output; content shows readable contract addresses and utility functions. | ai | |
| source-diff | obfuscated-file:dist/index-DqmXn4Mz.d.mts | AI (source-diff): TypeScript declaration file with long lines due to bundled type exports; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/utils-DPIscp9_.mjs | AI (source-diff): Standard minified ESM build output; content shows readable contract addresses and utility functions. | ai | |
| source-diff | obfuscated-file:dist/assets-C0RHiZ9a.mjs | AI (source-diff): Standard minified ESM build output; content is SVG assets and UI components. | ai | |
| source-diff | obfuscated-file:dist/index-lFyi52Xi.d.cts | AI (source-diff): TypeScript declaration file with long lines due to bundled type exports; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/assets-CZs6EVH8.cjs | AI (source-diff): Standard minified build output from tsdown bundler; content is UI components and SVG assets. | ai | |
| source-diff | obfuscated-file:dist/index-CirBvNlg.d.mts | AI (source-diff): TypeScript declaration file with long lines due to bundled type exports; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-CR1vQAAH.d.cts | AI (source-diff): TypeScript declaration file with long lines due to bundled type exports; not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-BJC0UjWs.d.mts | AI (source-diff): TypeScript declaration file with long import lines; not obfuscated, just bundled type defs. | ai | |
| source-diff | obfuscated-file:dist/index-CakR5Xyt.d.cts | AI (source-diff): TypeScript declaration file with long import lines; not obfuscated, just bundled type defs. | ai | |
| source-diff | obfuscated-file:dist/utils-DJKLAzLP.cjs | AI (source-diff): Standard bundler minification output; content is readable JS with plaintext contract addresses, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-C4fIl4KD.d.cts | AI (source-diff): TypeScript declaration file with long lines; not executable code, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-BvKpDLIo.d.mts | AI (source-diff): TypeScript declaration file with long lines; not executable code, not obfuscated. | ai | |
| phantom-deps | phantom-dep:i18next-browser-languagedetector | AI (phantom-deps): Declared as runtime dep, used via i18next plugin config; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/utils-KYzX9d5n.mjs | AI (source-diff): Standard bundler minification output; ESM equivalent of the CJS bundle, same pattern. | ai | |
| source-diff | obfuscated-file:dist/index-B93L_AT2.d.mts | AI (source-diff): TypeScript declaration file with long single-line type exports; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/utils-B1rpHKZq.mjs | AI (source-diff): Standard minified ESM bundle from tsdown build; same pattern as CJS counterpart. | ai | |
| source-diff | obfuscated-file:dist/utils-D0w5dcVX.cjs | AI (source-diff): Standard minified CJS bundle from tsdown build; content is readable blockchain config, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/index-QQ-9cIOs.d.cts | AI (source-diff): TypeScript declaration file with long single-line type exports; not obfuscated code. | ai | |
| phantom-deps | phantom-dep:ethers | AI (phantom-deps): ethers declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): framer-motion is an optional peer dep and declared dep; stable false positive. | ai | |
| phantom-deps | phantom-dep:i18next | AI (phantom-deps): i18next declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react-i18next | AI (phantom-deps): react-i18next declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@wagmi/core | AI (phantom-deps): @wagmi/core declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): bignumber.js declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:vaul | AI (phantom-deps): vaul declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): @emotion/styled declared as runtime and peer dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:process | AI (phantom-deps): Node 'process' polyfill declared for browser bundling; stable false positive. | ai | |
| phantom-deps | phantom-dep:@vechain/vechain-contract-types | AI (phantom-deps): First-party @vechain dep declared in dependencies; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query-devtools | AI (phantom-deps): @tanstack/react-query-devtools declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@privy-io/cross-app-connect | AI (phantom-deps): @privy-io/cross-app-connect declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@adraffy/ens-normalize | AI (phantom-deps): @adraffy/ens-normalize declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react-device-detect | AI (phantom-deps): react-device-detect declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:react-qrcode-logo | AI (phantom-deps): react-qrcode-logo declared as runtime dep; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@vechain/picasso | AI (phantom-deps): First-party @vechain dep declared in dependencies; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@solana/web3.js | AI (phantom-deps): @solana/web3.js declared as runtime dep (privy cross-chain support); phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:wagmi | AI (phantom-deps): wagmi is a declared runtime dep used transitively; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:net | AI (phantom-deps): Node 'net' polyfill declared as dep for browser bundling; stable false positive for this package. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 2.12.0 | 31 / 9 | |
| 2.11.0 | 31 / 9 | |
| 2.10.1 | 31 / 9 | |
| 2.10.0 | 31 / 9 | |
| 2.9.0 | 31 / 9 | |
| 2.8.2 | 31 / 9 | |
| 2.8.1 | 31 / 9 | |
| 2.8.0 | 31 / 9 | |
| 2.7.0 | 31 / 9 | |
| 2.6.9 | 31 / 9 | |
| 2.6.8 | 32 / 9 | |
| 2.6.7 | 31 / 9 | |
| 2.6.6 | 31 / 9 | |
| 2.6.5 | 31 / 9 | |
| 2.6.4 | 31 / 9 | |
| 2.6.3 | 31 / 9 | |
| 2.6.2 | 31 / 9 | |
| 2.6.1 | 32 / 9 | |
| 2.6.0 | 31 / 9 | |
| 2.5.1 | 31 / 9 | |
| 2.5.0 | 31 / 9 | |
| 2.4.5 | 31 / 9 | |
| 2.4.4 | 31 / 9 | |
| 2.4.3 | 31 / 9 | |
| 2.4.2 | 31 / 9 | |
| 2.4.1 | 31 / 9 | |
| 2.4.0 | 31 / 9 | |
| 2.3.0 | 31 / 9 | |
| 2.2.3 | 30 / 9 | |
| 2.2.2 | 30 / 9 | |
| 2.2.1 | 30 / 9 | |
| 2.2.0 | 30 / 9 | |
| 2.1.1 | 30 / 9 | |
| 2.1.0 | 30 / 9 | |
| 2.0.4 | 30 / 9 | |
| 2.0.3 | 30 / 9 | |
| 2.0.2 | 30 / 9 | |
| 2.0.1 | 30 / 9 | |
| 2.0.0 | 30 / 9 | |
| 1.10.5 | 40 / 11 | |
| 1.10.4 | 40 / 11 |
v2.6.9
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.8
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.7
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.6
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.5
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.4
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.3
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.2
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.1
23 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.5.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.4.5
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.4.4
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.4.3
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.4.2
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.4.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.4.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.