@vectorize-io/hindsight-control-plane
Control plane for Hindsight - Semantic memory system
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:standalone/.next/static/chunks/aab765b99de6028e.js | AI (source-diff): Turbopack bundled client chunk, not obfuscation. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Next.js app framework dep used via build tooling, not direct import. | ai | |
| source-diff | obfuscated-file:standalone/.next/server/chunks/ssr/_0ge9j1.._.js | AI (source-diff): Turbopack/Next.js bundled build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:standalone/.next/static/chunks/17uw~~tnvu9pw.js | AI (source-diff): Next.js bundle chunk with framework fetch+eval patterns, not a dropper. | ai | |
| source-diff | obfuscated-file:standalone/.next/static/chunks/9eef728357965f0b.js | AI (source-diff): Turbopack client bundle, build output. | ai | |
| source-diff | obfuscated-file:standalone/.next/server/chunks/ssr/_e8cbc2be._.js | AI (source-diff): Turbopack/webpack build output from next build, not obfuscation. | ai | |
| source-diff | net-exec-file:standalone/.next/static/chunks/9eef728357965f0b.js | AI (source-diff): Bundled Next.js client runtime, not a loader/dropper. | ai | |
| source-diff | net-exec-file:standalone/.next/server/chunks/ssr/_e8cbc2be._.js | AI (source-diff): Standard Next.js SSR chunk; fetch+eval pattern is bundler runtime, not dropper code. | ai | |
| source-diff | net-exec-file:standalone/.next/static/chunks/474cf502a4f856c3.js | AI (source-diff): fetch() calls target package's own API endpoints, not exfil. | ai | |
| source-diff | obfuscated-file:standalone/node_modules/next/dist/compiled/superstruct/index.cjs | AI (source-diff): Bundled Next.js vendor dep, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:standalone/node_modules/next/dist/compiled/zod/index.cjs | AI (source-diff): Bundled Next.js vendor dep, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:standalone/node_modules/typescript/lib/_tsc.js | AI (source-diff): Standard TypeScript compiler bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:standalone/.next/static/chunks/0e662c07abb2cacd.js | AI (source-diff): Turbopack/Next.js client bundle, build output. | ai | |
| source-diff | obfuscated-file:standalone/.next/static/chunks/474cf502a4f856c3.js | AI (source-diff): Turbopack/Next.js client bundle, build output. | ai | |
| source-diff | obfuscated-file:standalone/.next/static/chunks/9bc5002cc495aadf.js | AI (source-diff): Turbopack/Next.js client bundle, build output. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): UI toolkit used via config, false positive pattern for this package. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): CLI launcher that spawns the Next.js server process — expected pattern for this package. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): sharp libvips prebuilt binaries bundled transitively in Next.js standalone output — not backdoors. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Fires in Turbopack runtime chunk loader — standard bundler pattern. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Fires in bundled Next.js server chunk; not authored payload. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Fires in bundled Next.js/Turbopack runtime chunks, not authored code. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Passes process.env to child server process; standard for CLI wrappers. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 0.8.4 | 46 / 9 | |
| 0.8.2 | 44 / 9 | |
| 0.7.2 | 47 / 9 | |
| 0.7.0 | 47 / 9 | |
| 0.6.2 | 46 / 7 | |
| 0.5.6 | 46 / 7 | |
| 0.2.1 | 36 / 7 | |
| 0.2.0 | 36 / 7 | |
| 0.1.16 | 35 / 7 | |
| 0.1.15 | 35 / 7 | |
| 0.1.14 | 34 / 7 | |
| 0.1.13 | 34 / 7 | |
| 0.1.12 | 34 / 7 | |
| 0.1.11 | 34 / 7 | |
| 0.1.10 | 34 / 7 | |
| 0.1.9 | 34 / 7 |
v0.8.4
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.1
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.0
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.16
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.15
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.14
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.13
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.12
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.1.11
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.