@wisemen/wise-crm-web
CRM frontend package with Vue 3 components, composables and types
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/Error-B4TwHEhb.js | AI (source-diff): Vite-bundled chunk with readable imports, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Error-5vt6UD4m.js | AI (source-diff): Vite-bundled chunk with readable imports, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Error-DIPflT5m.js | AI (source-diff): Bundled Vite/Rollup output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-CH-IIWac.js | AI (source-diff): Minified Vite bundle output with readable imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-KPxLN29p.js | AI (source-diff): Bundled Vite/Rollup output with readable imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-CR9n3e4F.js | AI (source-diff): Bundled Vite output, not obfuscation; readable imports and lib code. | ai | |
| source-diff | obfuscated-file:dist/AppSkeletonLoader-KuQjOJv3.js | AI (source-diff): Bundled Vite output, not obfuscation; readable imports and lib code. | ai | |
| source-diff | obfuscated-file:dist/SettingsIcon-B4Fw0byV.js | AI (source-diff): Bundled Vite build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-B2zuc7Bn.js | AI (source-diff): Bundled Vite build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/SettingsIcon-VHiybIvl.js | AI (source-diff): Bundled icon component output, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-CZMLaXXG.js | AI (source-diff): Bundled Vite/Rollup output for Vue components, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Error-iBGGWZtH.js | AI (source-diff): Vite-bundled dist output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/SettingsIcon-DzP-IQS5.js | AI (source-diff): Minified SVG icon component, bundler output. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Well-known libs (googlemaps, dompurify, tiptap) matching CRM feature additions. | ai | |
| source-diff | obfuscated-file:dist/Error-BPxDpKcI.js | AI (source-diff): Vite bundle chunk, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/AppSkeletonLoader-CfQNes_H.js | AI (source-diff): Bundled Vite/Rollup output, not obfuscation; clear library imports visible. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-ClBmhjLm.js | AI (source-diff): Bundled Vite/Rollup output, not obfuscation; clear library imports visible. | ai | |
| source-diff | obfuscated-file:dist/SettingsIcon-C0qTAv0w.js | AI (source-diff): Minified SVG icon component render function, standard bundler output. | ai | |
| source-diff | obfuscated-file:dist/Error-BArv9rNb.js | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/AppSkeletonLoader-jncaFZrp.js | AI (source-diff): Vite/rollup bundled Vue output, not obfuscation. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected growth from bundled chunk splitting in a component library build. | ai | |
| source-diff | obfuscated-file:dist/AppSkeletonLoader-BHzY5Tb-.js | AI (source-diff): Vite/rollup bundled Vue output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/AppSkeletonLoader-DVZ-oKgW.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Vue component library; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-BhE9TeRa.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Vue component library; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Error-za-wClcU.js | AI (source-diff): Minified Vite bundle output; long lines are standard bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/CrmDetailHeaderCard-BkA0Z-Cu.js | AI (source-diff): Vite-bundled Vue component; network calls are API client imports, dynamic execution is Vue's resolveDynamicComponent — not malware. | ai | |
| source-diff | obfuscated-file:dist/CrmDetailContainer-gk5K7eQn.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Vue component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/AppSkeletonLoader-BMX-bVc3.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Vue component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Error-CX6APxDX.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable imports confirm legitimate build artifact. | ai | |
| provenance | no-provenance | AI (provenance): Internal org package; provenance not configured in their publish pipeline, stable false positive. | ai | |
| source-diff | obfuscated-file:dist/SettingsIcon-CWFwJelS.js | AI (source-diff): Minified SVG icon component bundle; content is clearly a settings gear icon, not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/Error-D6dRLq_g.js | AI (source-diff): Minified Vite bundle output; long lines are normal for bundled Vue/TS libraries, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/CrmDetailHeaderCard-CacrRk2b.js | AI (source-diff): Standard Vite-bundled Vue component; imports are from known deps (vue, zod, vue-router), no actual dropper pattern. | ai | |
| phantom-deps | phantom-dep:@tiptap/vue-3 | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tiptap/starter-kit | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@vueuse/router | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@vueuse/core | AI (phantom-deps): Config-referenced dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:motion-v | AI (phantom-deps): Same pattern — config-referenced dep in a Vue component library. | ai | |
| phantom-deps | phantom-dep:reka-ui | AI (phantom-deps): Vue component library re-exports deps via config; not a real phantom-dep issue. | ai | |
| phantom-deps | phantom-dep:blurhash | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-text-style | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@googlemaps/js-api-loader | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@tiptap/extension-color | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:libphonenumber-js | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:vue3-google-map | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@number-flow/vue | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:@tiptap/pm | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai | |
| phantom-deps | phantom-dep:dompurify | AI (phantom-deps): Component library dependency referenced in config; not a direct import by design. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 1.3.1 | 15 / 22 | |
| 1.3.0 | 15 / 22 | |
| 1.2.0 | 15 / 22 | |
| 1.1.0 | 15 / 22 | |
| 1.0.0 | 15 / 22 | |
| 0.2.5 | 15 / 22 | |
| 0.2.4 | 15 / 22 | |
| 0.2.3 | 15 / 22 | |
| 0.2.2 | 15 / 22 | |
| 0.2.1 | 14 / 22 | |
| 0.2.0 | 14 / 22 | |
| 0.1.4 | 14 / 22 | |
| 0.1.3 | 14 / 22 | |
| 0.1.2 | 13 / 22 | |
| 0.1.1 | 14 / 22 | |
| 0.1.0 | 21 / 14 | |
| 0.0.12 | 20 / 14 | |
| 0.0.11 | 20 / 14 | |
| 0.0.10 | 20 / 14 | |
| 0.0.9 | 18 / 14 | |
| 0.0.8 | 18 / 14 | |
| 0.0.7 | 18 / 14 | |
| 0.0.6 | 18 / 14 | |
| 0.0.5 | 18 / 14 | |
| 0.0.4 | 18 / 14 | |
| 0.0.3 | 18 / 14 | |
| 0.0.2 | 18 / 14 | |
| 0.0.1 | 18 / 14 |
v0.0.10
16 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.