← Home

@vectorize-io/hindsight-control-plane

Control plane for Hindsight - Semantic memory system

16
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

nicoloboschidk09876benfrank241

Keywords

hindsightmemorysemanticai

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:standalone/.next/static/chunks/aab765b99de6028e.js AI (source-diff): Turbopack bundled client chunk, not obfuscation. ai
phantom-deps phantom-dep:react AI (phantom-deps): Next.js app framework dep used via build tooling, not direct import. ai
source-diff obfuscated-file:standalone/.next/server/chunks/ssr/_0ge9j1.._.js AI (source-diff): Turbopack/Next.js bundled build output, not true obfuscation. ai
source-diff net-exec-file:standalone/.next/static/chunks/17uw~~tnvu9pw.js AI (source-diff): Next.js bundle chunk with framework fetch+eval patterns, not a dropper. ai
source-diff obfuscated-file:standalone/.next/static/chunks/9eef728357965f0b.js AI (source-diff): Turbopack client bundle, build output. ai
source-diff obfuscated-file:standalone/.next/server/chunks/ssr/_e8cbc2be._.js AI (source-diff): Turbopack/webpack build output from next build, not obfuscation. ai
source-diff net-exec-file:standalone/.next/static/chunks/9eef728357965f0b.js AI (source-diff): Bundled Next.js client runtime, not a loader/dropper. ai
source-diff net-exec-file:standalone/.next/server/chunks/ssr/_e8cbc2be._.js AI (source-diff): Standard Next.js SSR chunk; fetch+eval pattern is bundler runtime, not dropper code. ai
source-diff net-exec-file:standalone/.next/static/chunks/474cf502a4f856c3.js AI (source-diff): fetch() calls target package's own API endpoints, not exfil. ai
source-diff obfuscated-file:standalone/node_modules/next/dist/compiled/superstruct/index.cjs AI (source-diff): Bundled Next.js vendor dep, minified not obfuscated. ai
source-diff obfuscated-file:standalone/node_modules/next/dist/compiled/zod/index.cjs AI (source-diff): Bundled Next.js vendor dep, minified not obfuscated. ai
source-diff obfuscated-file:standalone/node_modules/typescript/lib/_tsc.js AI (source-diff): Standard TypeScript compiler bundle, not obfuscation. ai
source-diff obfuscated-file:standalone/.next/static/chunks/0e662c07abb2cacd.js AI (source-diff): Turbopack/Next.js client bundle, build output. ai
source-diff obfuscated-file:standalone/.next/static/chunks/474cf502a4f856c3.js AI (source-diff): Turbopack/Next.js client bundle, build output. ai
source-diff obfuscated-file:standalone/.next/static/chunks/9bc5002cc495aadf.js AI (source-diff): Turbopack/Next.js client bundle, build output. ai
phantom-deps phantom-dep:clsx AI (phantom-deps): UI toolkit used via config, false positive pattern for this package. ai
semgrep semgrep:child-process-import AI (semgrep): CLI launcher that spawns the Next.js server process — expected pattern for this package. ai
npm-metadata bundled-binaries AI (npm-metadata): sharp libvips prebuilt binaries bundled transitively in Next.js standalone output — not backdoors. ai
semgrep semgrep:dynamic-require AI (semgrep): Fires in Turbopack runtime chunk loader — standard bundler pattern. ai
semgrep semgrep:base64-decode AI (semgrep): Fires in bundled Next.js server chunk; not authored payload. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires in bundled Next.js/Turbopack runtime chunks, not authored code. ai
semgrep semgrep:env-spread AI (semgrep): Passes process.env to child server process; standard for CLI wrappers. ai

Versions (showing 16 of 16)

Version Deps Published
0.8.4 46 / 9
0.8.2 44 / 9
0.7.2 47 / 9
0.7.0 47 / 9
0.6.2 46 / 7
0.5.6 46 / 7
0.2.1 36 / 7
0.2.0 36 / 7
0.1.16 35 / 7
0.1.15 35 / 7
0.1.14 34 / 7
0.1.13 34 / 7
0.1.12 34 / 7
0.1.11 34 / 7
0.1.10 34 / 7
0.1.9 34 / 7

v0.8.4

10 findings
HIGH New obfuscated file: standalone/.next/server/chunks/ssr/[root-of-the-server]__0_99rmk._.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/server/chunks/ssr/[root-of-the-server]__0_99rmk._.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: standalone/.next/server/chunks/[root-of-the-server]__1v4w5-b._.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/08b_2i7ky7st8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/1zwqw64e9qw3h.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/29g93sxwnx69n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/static/chunks/29g93sxwnx69n.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: standalone/.next/static/chunks/3htua5xk2odwv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/turbopack-037qtgeo-0gy1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

10 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/server/chunks/ssr/_e8cbc2be._.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/server/chunks/ssr/_e8cbc2be._.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/0e662c07abb2cacd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/9bc5002cc495aadf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/9eef728357965f0b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/static/chunks/9eef728357965f0b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

10 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/server/chunks/ssr/_e8cbc2be._.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/server/chunks/ssr/_e8cbc2be._.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/0e662c07abb2cacd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/9bc5002cc495aadf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/9eef728357965f0b.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/static/chunks/9eef728357965f0b.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.16

8 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/0e662c07abb2cacd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/474cf502a4f856c3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/static/chunks/474cf502a4f856c3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: standalone/.next/static/chunks/9bc5002cc495aadf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.15

8 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/0e662c07abb2cacd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/474cf502a4f856c3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: standalone/.next/static/chunks/474cf502a4f856c3.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: standalone/.next/static/chunks/9bc5002cc495aadf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.14

5 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/aab765b99de6028e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.13

5 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/.next/static/chunks/aab765b99de6028e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.12

4 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.11

4 findings
HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/superstruct/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/next/dist/compiled/zod/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: standalone/node_modules/typescript/lib/_tsc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.