@visulima/pail
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from manual publish (prisis) to GitHub Actions CI with SLSA provenance is an improvement, not a compromise signal. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/PrettyReporter-CcDdPQSt.js | AI (source-diff): Bundled packem output; minified logger/pretty-printer code, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/packem_shared/PrettyReporter-CcDdPQSt.js | AI (source-diff): Same pattern as abstract-pretty-reporter; TTY/terminal detection in a logger is benign. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/AbstractJsonReporter-Bp_JCrMQ.js | AI (source-diff): Bundled packem output; error serialization logic, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/addKnownErrorConstructor-C1OJTj2D-0FlJMfXz.js | AI (source-diff): Bundled packem output; error constructor registration code, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/index-Q1764hvO.js | AI (source-diff): Bundled packem output; color name map and logger utilities, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/serializeError-C-NFvZ8_-D0CA_Qlx.js | AI (source-diff): Bundled packem output; error serialization logic, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/abstract-pretty-reporter-DrLBJ6ds.js | AI (source-diff): Bundled packem output for a logger package; no obfuscation, just minified build artifacts. | ai | |
| source-diff | net-exec-file:dist/packem_shared/abstract-pretty-reporter-DrLBJ6ds.js | AI (source-diff): execFileSync and network calls are part of the logger's TTY/terminal detection; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/index-DqKWykfa.js | AI (source-diff): Standard packem bundler output; sample shows readable ANSI/emoji utilities, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/format-label-CpyyTBom.js | AI (source-diff): Minified bundler output (packem); content is readable logging/formatting logic, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/index-CysYvHXs.js | AI (source-diff): Minified bundler output; content is ANSI/terminal handling utilities, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/progress-bar.js | AI (source-diff): Minified bundler output; content is clearly a progress bar implementation. | ai | |
| source-diff | obfuscated-file:dist/spinner.js | AI (source-diff): Minified bundler output; content is spinner animation frames and logic. | ai | |
| dependencies | unvetted-dep:@visulima/colorize | AI (dependencies): Same-monorepo sibling package; stable false positive for this package family. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 4.0.2 | 2 / 0 | |
| 4.0.1 | 2 / 0 | |
| 4.0.0 | 2 / 0 | |
| 3.2.2 | 1 / 0 | |
| 3.2.1 | 1 / 0 | |
| 3.2.0 | 2 / 0 | |
| 3.1.0 | 2 / 0 | |
| 3.0.3 | 2 / 0 | |
| 3.0.2 | 2 / 0 | |
| 3.0.1 | 2 / 0 | |
| 3.0.0 | 2 / 0 |
v4.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.0.0
10 findingsThis version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.