← Home

@visulima/pail

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

prisis

Keywords

ansianolilabbrowserbrowser-loggercallsitecallsitesclicolorcolorfulcolorizeconsolaconsoleconsole-loggerdebugerror-loggingfile-loggerfile-loggingfilesystem-loggerfilterfs-loggerhandling exceptionsjsonjson-loggerjson-logginglog levelloglog-cleanerlog-rotationlog4jlog4jslog4tsloggerloggingnodestreamprettynode-loggerpailpinopretty-errorpretty-logprintprogressredactrotating-logshow errortimeruniversalvisulimawarning-loggingwinston

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/packem_shared/index-DqKWykfa.js AI (source-diff): Standard packem bundler output; sample shows readable ANSI/emoji utilities, no malicious patterns. ai
source-diff obfuscated-file:dist/packem_shared/format-label-CpyyTBom.js AI (source-diff): Minified bundler output (packem); content is readable logging/formatting logic, not obfuscated malware. ai
source-diff obfuscated-file:dist/packem_shared/index-CysYvHXs.js AI (source-diff): Minified bundler output; content is ANSI/terminal handling utilities, no malicious patterns. ai
source-diff obfuscated-file:dist/progress-bar.js AI (source-diff): Minified bundler output; content is clearly a progress bar implementation. ai
source-diff obfuscated-file:dist/spinner.js AI (source-diff): Minified bundler output; content is spinner animation frames and logic. ai
dependencies unvetted-dep:@visulima/colorize AI (dependencies): Same-monorepo sibling package; stable false positive for this package family. ai

Versions (showing 8 of 8)

Version Deps Published
3.2.2 1 / 0
3.2.1 1 / 0
3.2.0 2 / 0
3.1.0 2 / 0
3.0.3 2 / 0
3.0.2 2 / 0
3.0.1 2 / 0
3.0.0 2 / 0

v3.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.1

2 findings
HIGH New obfuscated file: dist/packem_shared/index-DqKWykfa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

2 findings
HIGH New obfuscated file: dist/packem_shared/index-DqKWykfa.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

5 findings
HIGH New obfuscated file: dist/packem_shared/format-label-CpyyTBom.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/index-CysYvHXs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/progress-bar.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/spinner.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.