@visulima/task-runner
OIDC trusted publishing setup package for @visulima/task-runner
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/packem_shared/Cache-BLDC94-L.js | AI (source-diff): Minified bundler output (packem), not obfuscated; readable imports and logic throughout. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/checkImportBoundaries-D1nft8FO.js | AI (source-diff): Minified bundler output, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/createTaskGraph-CKZ0Wfh0.js | AI (source-diff): Minified bundler output, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/FileAccessTracker-Bi6nS1k6.js | AI (source-diff): Minified bundler output; native binding loader pattern for fspy-seccomp-helper is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/FingerprintManager-DkS09Rdb.js | AI (source-diff): Minified bundler output, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/HttpRemoteCache-m_Uc5bbn.js | AI (source-diff): Minified bundler output; HTTP remote cache implementation is core to stated package function. | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): Minified bundler output, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/packem_chunks/index.js | AI (source-diff): Minified bundler output; bundled node-pty and native binding code. | ai | |
| source-diff | net-exec-file:dist/packem_chunks/index.js | AI (source-diff): Network+exec pattern is NAPI native binding loader (ldd musl detection + NAPI_RS_NATIVE_LIBRARY_PATH), standard for native Node addons. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/InProcessTaskHasher-DV79X35e.js | AI (source-diff): Minified bundler output, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/LockfileHasher-DsXesGSK.js | AI (source-diff): Minified bundler output, no obfuscation indicators. | ai | |
| source-diff | obfuscated-file:dist/packem_shared/ReapiRemoteCache-CQQ-9OVP.js | AI (source-diff): Minified bundler output; REAPI remote cache implementation is core to stated package function. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): ldd musl-detection pattern; standard for NAPI native binding packages. | ai | |
| semgrep | semgrep:child-process-execsync | AI (semgrep): execSync('ldd --version') for musl detection; benign, fixed command string. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): NAPI_RS_NATIVE_LIBRARY_PATH override for native binding path; standard NAPI-RS pattern. | ai | |
| phantom-deps | phantom-dep:nanotar | AI (phantom-deps): Used in bundled dist output; phantom-dep heuristic misses bundled imports. | ai | |
| phantom-deps | phantom-dep:@visulima/path | AI (phantom-deps): Same-org dep used in bundled dist; phantom-dep heuristic misses bundled imports. | ai | |
| phantom-deps | phantom-dep:@lydell/node-pty | AI (phantom-deps): Used in bundled dist; phantom-dep heuristic misses bundled imports. | ai | |
| phantom-deps | phantom-dep:@visulima/humanizer | AI (phantom-deps): Same-org dep used in bundled dist; phantom-dep heuristic misses bundled imports. | ai |
v1.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
14 findingsThis version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.