@veupathdb/ortho-site
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/bundles/modern/977.bundle-dd7098262380fc478cd1.js | AI (source-diff): Standard webpack minified bundle output for this package. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/977.bundle-2595ec3cd13ab2b88e08.js | AI (source-diff): Standard webpack minified bundle output for this package. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/145.bundle-00e60ed32445e796e224.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/145.bundle-ee1678a86d4619750553.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/142.bundle-ef09de6457738c75731d.js | AI (source-diff): Standard webpack minified bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/977.bundle-f64211b7b707fbc6562a.js | AI (source-diff): Standard webpack minified bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/977.bundle-b7d77454f4b0a870a437.js | AI (source-diff): Standard webpack minified bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/142.bundle-13a80f07a37e67be1a36.js | AI (source-diff): Standard webpack minified bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/977.bundle-d86ad0cd6c07c04cc255.js | AI (source-diff): Standard webpack bundle output; readable React code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/977.bundle-4daa7b72b66a49a1ddf7.js | AI (source-diff): Standard webpack bundle output; readable React code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/977.bundle-aed61b5f6b675ed64260.js | AI (source-diff): Standard webpack minified bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/977.bundle-432671b13f934ac45617.js | AI (source-diff): Standard webpack minified bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/977.bundle-5211c2ff1a008ea524a3.js | AI (source-diff): Standard webpack minified bundle output, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/528.bundle-92fd1503118e0509685c.js | AI (source-diff): Standard webpack minified bundle output, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/528.bundle-501dda4698c2e38edd12.js | AI (source-diff): Standard webpack minified bundle output, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/142.bundle-4431709d06ace4fd7978.js | AI (source-diff): Standard webpack minified bundle output, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/142.bundle-351d5434918ae639e279.js | AI (source-diff): Standard webpack minified bundle output, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/977.bundle-5d6565bc939e7f28376a.js | AI (source-diff): Standard webpack minified bundle output, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/bundles/modern/605.bundle-cd355e346402c3611162.js | AI (source-diff): Webpack bundle naturally contains fetch + dynamic module eval; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/142.bundle-2ddb846c61521660c101.js | AI (source-diff): Standard webpack minified bundle output; readable React UI code visible in sample. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/142.bundle-f573e20a2f498dc95750.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/273.bundle-9ae5027ba869e9db2864.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/324.bundle-24a9156300d000c8ae2a.js | AI (source-diff): Standard webpack minified bundle output; saveAs/FileSaver pattern visible. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/324.bundle-3b30564b8eb5f1078bc6.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/528.bundle-6f624b3fbcdd4ae55a52.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/528.bundle-933109319402ba880b62.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/605.bundle-cd355e346402c3611162.js | AI (source-diff): Standard webpack minified bundle output; sankey/d3 library code visible. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/605.bundle-cd355e346402c3611162.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | net-exec-file:dist/bundles/legacy/605.bundle-cd355e346402c3611162.js | AI (source-diff): Webpack bundle naturally contains fetch + dynamic module eval; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/977.bundle-8b02acbf2a6346ab043a.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/977.bundle-e11eca4ff787fab0fabd.js | AI (source-diff): Standard webpack minified bundle output. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/142.bundle-34bbee4288f1b7d7417c.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/528.bundle-181a5f3250fc4f07c0a3.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/528.bundle-cbd47b0eb07aa52555d4.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/977.bundle-897949daff5d9687e54b.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/977.bundle-bb864a2acbdca5b69f7c.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/324.bundle-8a688b3f00e278fb9e6e.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/324.bundle-4e27829ce51c1ae1d116.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/142.bundle-6f2c92cb326cd20a71f1.js | AI (source-diff): Standard webpack minified bundle for this site package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/324.bundle-2717752ce5a8bd49d31a.js | AI (source-diff): Standard webpack bundle; sample shows FileSaver.js saveAs implementation, a well-known library. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/142.bundle-732fdfff5122abeaac8a.js | AI (source-diff): Standard webpack production bundle with source map; readable UI component code visible. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/12.bundle-fc8d9179ca3e69ba81d0.js | AI (source-diff): Standard webpack production bundle; same pattern as legacy counterpart. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/12.bundle-3a0bf16aec1f7ca9e6ec.js | AI (source-diff): Standard webpack production bundle; webpackChunk pattern and readable React code confirm minification, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/982.bundle-3ce1b666ded43f117aa2.js | AI (source-diff): Standard webpack bundle; same EDA workspace pattern as modern counterpart. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/982.bundle-272698454c23a3d17b28.js | AI (source-diff): Standard webpack bundle; readable EDA workspace React code visible in sample. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/324.bundle-e4eeb41e9a72f6e06c7a.js | AI (source-diff): Standard webpack bundle; same FileSaver.js pattern as legacy counterpart. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/142.bundle-d9b5c0b64beb8da19bf0.js | AI (source-diff): Standard webpack production bundle; same pattern as legacy counterpart. | ai | |
| source-diff | encoded-string-file:dist/bundles/modern/site-client.bundle.js | AI (source-diff): Same as legacy bundle; emotion/webpack runtime encoded strings are expected in this package. | ai | |
| source-diff | obfuscated-file:dist/bundles/legacy/324.bundle-427a93819496e578ec46.js | AI (source-diff): Standard webpack legacy bundle; same pattern as modern bundle, expected minification. | ai | |
| source-diff | obfuscated-file:dist/bundles/modern/324.bundle-0a2b932cf7820783466c.js | AI (source-diff): Standard webpack production bundle (webpackChunk prefix); minification is expected for this site package. | ai | |
| source-diff | encoded-string-file:dist/bundles/legacy/site-client.bundle.js | AI (source-diff): Long strings are emotion CSS-in-JS and webpack runtime patterns; stable false positive for this bundled site package. | ai | |
| phantom-deps | phantom-dep:@veupathdb/preferred-organisms | AI (phantom-deps): Same-org workspace dep; phantom-dep heuristic unreliable for monorepo workspace packages. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Monorepo workspace package; missing description is a stable pattern across this org's packages, not a malware signal. | ai |
Versions (showing 14 of 14)
| Version | Deps | Published |
|---|---|---|
| 1.4.15 | 0 / 72 | |
| 1.4.14 | 0 / 72 | |
| 1.4.13 | 0 / 72 | |
| 1.4.12 | 0 / 72 | |
| 1.4.10 | 0 / 72 | |
| 1.4.9 | 0 / 72 | |
| 1.4.7 | 0 / 72 | |
| 1.4.6 | 0 / 72 | |
| 1.4.4 | 2 / 70 | |
| 1.4.2 | 2 / 70 | |
| 1.4.1 | 2 / 70 | |
| 1.3.49 | 2 / 70 | |
| 1.3.48 | 2 / 70 | |
| 1.3.46 | 1 / 70 |
v1.4.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.14
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.