← Home

@visulima/task-runner

OIDC trusted publishing setup package for @visulima/task-runner

3
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

prisis

Keywords

cachemonoreporunnertasktask-runnervisulimaworkspace

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/packem_shared/Cache-BLDC94-L.js AI (source-diff): Minified bundler output (packem), not obfuscated; readable imports and logic throughout. ai
source-diff obfuscated-file:dist/packem_shared/checkImportBoundaries-D1nft8FO.js AI (source-diff): Minified bundler output, no obfuscation indicators. ai
source-diff obfuscated-file:dist/packem_shared/createTaskGraph-CKZ0Wfh0.js AI (source-diff): Minified bundler output, no obfuscation indicators. ai
source-diff obfuscated-file:dist/packem_shared/FileAccessTracker-Bi6nS1k6.js AI (source-diff): Minified bundler output; native binding loader pattern for fspy-seccomp-helper is expected for this package. ai
source-diff obfuscated-file:dist/packem_shared/FingerprintManager-DkS09Rdb.js AI (source-diff): Minified bundler output, no obfuscation indicators. ai
source-diff obfuscated-file:dist/packem_shared/HttpRemoteCache-m_Uc5bbn.js AI (source-diff): Minified bundler output; HTTP remote cache implementation is core to stated package function. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): Minified bundler output, no obfuscation indicators. ai
source-diff obfuscated-file:dist/packem_chunks/index.js AI (source-diff): Minified bundler output; bundled node-pty and native binding code. ai
source-diff net-exec-file:dist/packem_chunks/index.js AI (source-diff): Network+exec pattern is NAPI native binding loader (ldd musl detection + NAPI_RS_NATIVE_LIBRARY_PATH), standard for native Node addons. ai
source-diff obfuscated-file:dist/packem_shared/InProcessTaskHasher-DV79X35e.js AI (source-diff): Minified bundler output, no obfuscation indicators. ai
source-diff obfuscated-file:dist/packem_shared/LockfileHasher-DsXesGSK.js AI (source-diff): Minified bundler output, no obfuscation indicators. ai
source-diff obfuscated-file:dist/packem_shared/ReapiRemoteCache-CQQ-9OVP.js AI (source-diff): Minified bundler output; REAPI remote cache implementation is core to stated package function. ai
semgrep semgrep:child-process-import AI (semgrep): ldd musl-detection pattern; standard for NAPI native binding packages. ai
semgrep semgrep:child-process-execsync AI (semgrep): execSync('ldd --version') for musl detection; benign, fixed command string. ai
semgrep semgrep:dynamic-require AI (semgrep): NAPI_RS_NATIVE_LIBRARY_PATH override for native binding path; standard NAPI-RS pattern. ai
phantom-deps phantom-dep:nanotar AI (phantom-deps): Used in bundled dist output; phantom-dep heuristic misses bundled imports. ai
phantom-deps phantom-dep:@visulima/path AI (phantom-deps): Same-org dep used in bundled dist; phantom-dep heuristic misses bundled imports. ai
phantom-deps phantom-dep:@lydell/node-pty AI (phantom-deps): Used in bundled dist; phantom-dep heuristic misses bundled imports. ai
phantom-deps phantom-dep:@visulima/humanizer AI (phantom-deps): Same-org dep used in bundled dist; phantom-dep heuristic misses bundled imports. ai

Versions (showing 3 of 3)

Version Deps Published
1.0.1 4 / 0
1.0.0 4 / 0
0.0.1 0 / 0

v1.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

14 findings
HIGH Publisher changed: prisis → GitHub Actions (on 2026-07-03) provenance

This version was published by a different npm account than previous versions on 2026-07-03. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/packem_shared/Cache-BLDC94-L.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/checkImportBoundaries-D1nft8FO.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/createTaskGraph-CKZ0Wfh0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/FileAccessTracker-Bi6nS1k6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/FingerprintManager-DkS09Rdb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/HttpRemoteCache-m_Uc5bbn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_chunks/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/packem_chunks/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/packem_shared/InProcessTaskHasher-DV79X35e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/LockfileHasher-DsXesGSK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/packem_shared/ReapiRemoteCache-CQQ-9OVP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.