@voiceflow/react-chat
voiceflow chat ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/styles.css-nDBT7a_Y.js | AI (source-diff): Vite/Rollup bundled JS output, not obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-BCg5K3-5.mjs | AI (source-diff): Bundled React runtime helpers, no actual net+exec dropper behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-nDBT7a_Y.js | AI (source-diff): Bundled React runtime helpers, no actual net+exec dropper behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-BCg5K3-5.mjs | AI (source-diff): Vite/Rollup bundled JS output, not obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-B1P_v4FN.mjs | AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-BY1XhlRN.js | AI (source-diff): Bundled Vite output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-BY1XhlRN.js | AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-B1P_v4FN.mjs | AI (source-diff): Bundled Vite output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-Oq9cMn3v.js | AI (source-diff): Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-DlMromWW.mjs | AI (source-diff): Minified React bundle; no real network+exec payload present. | ai | |
| source-diff | net-exec-file:build/styles.css-Oq9cMn3v.js | AI (source-diff): Minified React bundle; no real network+exec payload present. | ai | |
| source-diff | obfuscated-file:build/styles.css-DlMromWW.mjs | AI (source-diff): Vite/Rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-CNfN5ryp.mjs | AI (source-diff): False positive from generic bundled build artifact, no real network+exec malware. | ai | |
| source-diff | obfuscated-file:build/styles.css-CmtHTtma.js | AI (source-diff): Bundled Vite/Rollup output, not obfuscation; matches React boilerplate. | ai | |
| source-diff | obfuscated-file:build/styles.css-CNfN5ryp.mjs | AI (source-diff): Bundled Vite/Rollup output, not obfuscation; matches React boilerplate. | ai | |
| source-diff | net-exec-file:build/styles.css-CmtHTtma.js | AI (source-diff): False positive from generic bundled build artifact, no real network+exec malware. | ai | |
| source-diff | obfuscated-file:build/styles.css-D4MIRDWW.js | AI (source-diff): Vite/Rollup bundled output, not obfuscation; matches package build tooling. | ai | |
| source-diff | net-exec-file:build/styles.css-BrlkRZxa.mjs | AI (source-diff): Bundled React interop code, no malicious behavior found. | ai | |
| source-diff | obfuscated-file:build/styles.css-BrlkRZxa.mjs | AI (source-diff): Vite/Rollup bundled ESM output, not obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-D4MIRDWW.js | AI (source-diff): React bundle contains normal require/dynamic patterns, no malicious network+exec behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-DgqCY0Zc.js | AI (source-diff): Minified Vite bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-HUn8aCbR.mjs | AI (source-diff): Bundled React/JSX runtime code, no malicious network+exec behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-HUn8aCbR.mjs | AI (source-diff): Minified Vite bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-DgqCY0Zc.js | AI (source-diff): Bundled React/JSX runtime code, no malicious network+exec behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-DkkksYRr.js | AI (source-diff): Bundled React runtime code, no real dropper behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-BHd9n5BQ.mjs | AI (source-diff): Bundled React runtime code, no real dropper behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-BHd9n5BQ.mjs | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-DkkksYRr.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-DtXR_yLr.js | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-RZgqP4wo.mjs | AI (source-diff): Standard bundle wrapper code, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:build/styles.css-RZgqP4wo.mjs | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-DtXR_yLr.js | AI (source-diff): Standard bundle wrapper code, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:build/styles.css-Cff6oDf9.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-DS-hcqiP.mjs | AI (source-diff): Bundled React runtime; no real network+exec malware behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-DS-hcqiP.mjs | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-Cff6oDf9.js | AI (source-diff): Bundled React runtime; no real network+exec malware behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-DWQk1uxg.mjs | AI (source-diff): Bundled ESM build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-BpybOKZF.js | AI (source-diff): Vite/Rollup bundle output (react-jsx-runtime), not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-BpybOKZF.js | AI (source-diff): Bundled React runtime code; no real network+exec malware behavior found. | ai | |
| source-diff | net-exec-file:build/styles.css-DWQk1uxg.mjs | AI (source-diff): Bundled build artifact, not dropper/loader malware. | ai | |
| source-diff | obfuscated-file:build/styles.css-C3vCHTeI.mjs | AI (source-diff): Minified vite/rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-C3vCHTeI.mjs | AI (source-diff): Bundled React/UI code, no actual dropper behavior in sample. | ai | |
| source-diff | net-exec-file:build/styles.css-BcHMFahz.js | AI (source-diff): Bundled React/UI code, no actual dropper behavior in sample. | ai | |
| source-diff | obfuscated-file:build/styles.css-BcHMFahz.js | AI (source-diff): Minified vite/rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/ChatConfig.dto-dJlnmvuT.mjs | AI (source-diff): Pattern match on bundled React internals, no actual dropper behavior. | ai | |
| source-diff | obfuscated-file:build/ChatConfig.dto-DZZ2t8yY.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/ChatConfig.dto-dJlnmvuT.mjs | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/ChatConfig.dto-DZZ2t8yY.js | AI (source-diff): Pattern match on bundled React internals, no actual dropper behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-zU0V5IfP.mjs | AI (source-diff): Bundler interop helpers, no real network+exec dropper behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-qdIlT2BT.js | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-zU0V5IfP.mjs | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-qdIlT2BT.js | AI (source-diff): Bundler interop helpers, no real network+exec dropper behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-BQlrl673.js | AI (source-diff): Bundled build output; no real network+exec malware pattern. | ai | |
| source-diff | obfuscated-file:build/styles.css-yzfJtYUx.mjs | AI (source-diff): Bundled Vite/Rollup CSS chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:build/styles.css-yzfJtYUx.mjs | AI (source-diff): Bundled build output; no real network+exec malware pattern. | ai | |
| source-diff | obfuscated-file:build/styles.css-BQlrl673.js | AI (source-diff): Bundled Vite/Rollup CSS chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:build/styles.css-Rk7zZ4Ai.js | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-BQdXxRlj.mjs | AI (source-diff): Bundled React runtime code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-BQdXxRlj.mjs | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-Rk7zZ4Ai.js | AI (source-diff): Bundled React runtime code, no dropper behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-DpVXINrA.mjs | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-DpVXINrA.mjs | AI (source-diff): Bundled React/jsx-runtime code, no actual network+exec payload. | ai | |
| source-diff | net-exec-file:build/styles.css-CqdniYZ7.js | AI (source-diff): Bundled React/jsx-runtime code, no actual network+exec payload. | ai | |
| source-diff | obfuscated-file:build/styles.css-CqdniYZ7.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css--cF8_YgW.js | AI (source-diff): Bundled UI code; no fetched binary or hostile network target in sample. | ai | |
| source-diff | net-exec-file:build/styles.css-C5bacpFy.mjs | AI (source-diff): Bundled UI code; no malicious network/exec behavior evidenced. | ai | |
| source-diff | obfuscated-file:build/styles.css-C5bacpFy.mjs | AI (source-diff): Vite ESM bundle output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css--cF8_YgW.js | AI (source-diff): Vite/rollup bundle output (React license header, module helpers), not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-CIZfRzwF.mjs | AI (source-diff): Bundled/minified vite build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-CIZfRzwF.mjs | AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. | ai | |
| source-diff | net-exec-file:build/styles.css-CK9R2gP0.js | AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:build/styles.css-CK9R2gP0.js | AI (source-diff): Bundled/minified vite build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-DplmA48C.mjs | AI (source-diff): Standard bundled/minified build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-DplmA48C.mjs | AI (source-diff): False positive on bundled React/Vite build code, no real exfil behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-DCxa62kV.js | AI (source-diff): False positive on bundled React/Vite build code, no real exfil behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-DCxa62kV.js | AI (source-diff): Standard bundled/minified build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-BEfB8MOo.mjs | AI (source-diff): React bundle interop code, no real network+exec malware behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-DgHrBjvm.js | AI (source-diff): React bundle interop code, no real network+exec malware behavior. | ai | |
| source-diff | obfuscated-file:build/styles.css-BEfB8MOo.mjs | AI (source-diff): Bundled Vite/Rollup output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-DgHrBjvm.js | AI (source-diff): Bundled Vite/Rollup output, not obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-CNo5j7Ek.mjs | AI (source-diff): Vite/esbuild bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:build/styles.css-DysXeYfL.js | AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:build/styles.css-DysXeYfL.js | AI (source-diff): Vite/esbuild bundled output, not true obfuscation. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established monorepo package with sparse release cadence; trusted service-account publisher. | ai | |
| source-diff | net-exec-file:build/styles.css-CNo5j7Ek.mjs | AI (source-diff): Standard bundled React runtime code, no malicious network/exec behavior found. | ai | |
| source-diff | obfuscated-file:build/styles.css-CUk_oX4E.mjs | AI (source-diff): Minified Vite bundle output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:build/styles.css-BcudssFd.js | AI (source-diff): Minified Vite bundle output, not true obfuscation; contains standard React JSX runtime code. | ai | |
| source-diff | net-exec-file:build/styles.css-CUk_oX4E.mjs | AI (source-diff): Bundled React internals, no real network+eval dropper behavior. | ai | |
| source-diff | net-exec-file:build/styles.css-BcudssFd.js | AI (source-diff): Bundled React internals, no real network+eval dropper behavior. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ts-pattern | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:remark-gfm | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:rehype-raw | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:chroma-js | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): Bundled build artifact; declared deps not directly imported is expected for this package. | ai | |
| phantom-deps | phantom-dep:remeda | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:cuid | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:slate | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established Voiceflow org package; lack of provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:@voiceflow/slate-serializer | AI (phantom-deps): Same org scope; bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-syntax-highlighter | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-speech-recognition | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-textarea-autosize | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:rehype-external-links | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@paralleldrive/cuid2 | AI (phantom-deps): Same bundled build pattern; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:regenerator-runtime | AI (phantom-deps): Known implicit runtime dependency; stable false positive for this package. | ai |
Versions (showing 32 of 32)
| Version | Deps | Published |
|---|---|---|
| 2.62.4 | 26 / 34 | |
| 2.11.2 | 22 / 44 | |
| 2.11.1 | 22 / 44 | |
| 2.11.0 | 22 / 44 | |
| 2.10.0 | 22 / 44 | |
| 2.9.1 | 22 / 44 | |
| 2.9.0 | 22 / 44 | |
| 2.8.1 | 22 / 44 | |
| 2.8.0 | 22 / 44 | |
| 2.7.2 | 22 / 44 | |
| 2.7.1 | 22 / 44 | |
| 2.7.0 | 22 / 44 | |
| 2.6.4 | 22 / 44 | |
| 2.6.3 | 22 / 44 | |
| 2.6.2 | 22 / 44 | |
| 2.6.1 | 22 / 44 | |
| 2.6.0 | 22 / 44 | |
| 2.5.2 | 22 / 44 | |
| 2.5.1 | 22 / 44 | |
| 2.5.0 | 22 / 44 | |
| 2.4.1 | 22 / 44 | |
| 2.4.0 | 22 / 44 | |
| 2.3.1 | 22 / 44 | |
| 2.3.0 | 22 / 44 | |
| 2.2.5 | 22 / 44 | |
| 2.2.4 | 22 / 44 | |
| 2.2.3 | 22 / 44 | |
| 2.2.2 | 22 / 44 | |
| 2.2.1 | 22 / 44 | |
| 2.2.0 | 22 / 44 | |
| 2.1.1 | 22 / 44 | |
| 2.1.0 | 22 / 44 |
v2.11.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.4
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.5
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.4
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.2
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.