← Home

@wix/auto_sdk_ecom_order-transactions

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

yoavwix-cishahatawixnpmwix-ambassadorwix-ci-publisherwix-bi-publishergalil-teamusability-sessionsyurynixydanivmayacoamitde007haimbrum-wixyoungshinobiethanpshlomitc-wixarielhwix-org-headlessfalconcinadavlacroir-wixdorchaouat

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:build/internal/es/ecom-v1-order-transactions-order-transactions.universal-aENRFMbJ.d.mts AI (source-diff): Long-line .d.mts files are tsup-generated TypeScript declaration re-exports; stable pattern for this Wix SDK package. ai
source-diff obfuscated-file:build/cjs/ecom-v1-order-transactions-order-transactions.universal-DRvhf2o2.d.ts AI (source-diff): CJS variant of the same tsup-generated declaration file; not obfuscation. ai
source-diff obfuscated-file:build/internal/cjs/ecom-v1-order-transactions-order-transactions.universal-aENRFMbJ.d.ts AI (source-diff): CJS variant of the same tsup-generated declaration file; not obfuscation. ai
source-diff obfuscated-file:build/es/ecom-v1-order-transactions-order-transactions.universal-DRvhf2o2.d.mts AI (source-diff): Same tsup-generated declaration file pattern; not obfuscation. ai
source-diff obfuscated-file:build/internal/ecom-v1-order-transactions-order-transactions.universal-aENRFMbJ.d.ts AI (source-diff): Long-line TypeScript declaration file; standard Wix SDK build artifact, not obfuscated code. ai
source-diff obfuscated-file:build/internal/ecom-v1-order-transactions-order-transactions.universal-aENRFMbJ.d.mts AI (source-diff): Long-line TypeScript declaration file; standard Wix SDK build artifact, not obfuscated code. ai
source-diff obfuscated-file:build/ecom-v1-order-transactions-order-transactions.universal-DRvhf2o2.d.mts AI (source-diff): Long-line TypeScript declaration file; standard Wix SDK build artifact, not obfuscated code. ai
source-diff obfuscated-file:build/ecom-v1-order-transactions-order-transactions.universal-DRvhf2o2.d.ts AI (source-diff): Long-line TypeScript declaration file; standard Wix SDK build artifact, not obfuscated code. ai
source-diff obfuscated-file:build/internal/ecom-v1-order-transactions-order-transactions.universal-CQewkK3E.d.mts AI (source-diff): Long-line .d.mts files are bundled TypeScript declaration re-exports, standard for Wix SDK packages. ai
source-diff obfuscated-file:build/ecom-v1-order-transactions-order-transactions.universal-DgIVKgiJ.d.mts AI (source-diff): Same pattern: bundled TS declaration re-exports, not obfuscation. ai
source-diff obfuscated-file:build/index.d.mts AI (source-diff): Bundled TS declaration re-exports; stable pattern for this package family. ai
source-diff obfuscated-file:build/internal/index.d.mts AI (source-diff): Bundled TS declaration re-exports; stable pattern for this package family. ai
source-diff obfuscated-file:build/internal/index.d.ts AI (source-diff): Bundled TS declaration re-exports; stable pattern for this package family. ai
source-diff obfuscated-file:build/index.d.ts AI (source-diff): Bundled TS declaration re-exports; stable pattern for this package family. ai
source-diff obfuscated-file:build/ecom-v1-order-transactions-order-transactions.universal-DgIVKgiJ.d.ts AI (source-diff): Bundled TS declaration re-exports; stable pattern for this package family. ai
source-diff obfuscated-file:build/internal/ecom-v1-order-transactions-order-transactions.universal-CQewkK3E.d.ts AI (source-diff): Bundled TS declaration re-exports; stable pattern for this package family. ai
source-diff obfuscated-file:build/es/meta.d.mts AI (source-diff): TypeScript declaration file with long export lines; standard tsup output for large Wix SDK packages. ai
maintainer-change maintainer-added AI (maintainer-change): Routine Wix internal maintainer rotation consistent with CI-managed SDK packages. ai
maintainer-change maintainer-removed AI (maintainer-change): Routine Wix internal maintainer rotation consistent with CI-managed SDK packages. ai
source-diff obfuscated-file:build/es/index.d.mts AI (source-diff): TypeScript declaration file with long export lines; standard tsup output for large Wix SDK packages. ai
source-diff obfuscated-file:build/internal/es/index.d.mts AI (source-diff): TypeScript declaration file with long export lines; standard tsup output for large Wix SDK packages. ai
source-diff obfuscated-file:build/es/index.typings.d.mts AI (source-diff): TypeScript declaration file with long export lines; standard tsup output for large Wix SDK packages. ai
source-diff obfuscated-file:build/internal/es/index.typings.d.mts AI (source-diff): TypeScript declaration file with long export lines; standard tsup output for large Wix SDK packages. ai
source-diff obfuscated-file:build/internal/es/meta.d.mts AI (source-diff): TypeScript declaration file with long export lines; standard tsup output for large Wix SDK packages. ai
provenance publisher-changed AI (provenance): Transition to wix-ci-publisher is Wix's standard CI account with 1032 approved packages; stable pattern across Wix SDK packages. ai
npm-metadata no-description AI (npm-metadata): Wix SDK auto-generated packages consistently omit descriptions; not a malice signal here. ai
bogus-package bogus-package AI (bogus-package): Wix auto-generated SDK packages are intentionally templated with no description/repo; pattern is stable across this publisher's packages. ai
provenance no-provenance AI (provenance): Wix CI pipeline does not attach Sigstore provenance; consistent across all their SDK packages. ai

Versions (showing 51 of 83)

View all versions
Version Deps Published
1.0.89 3 / 2
1.0.88 3 / 2
1.0.87 3 / 2
1.0.86 3 / 2
1.0.85 3 / 2
1.0.84 3 / 2
1.0.83 3 / 2
1.0.82 3 / 2
1.0.81 3 / 2
1.0.80 2 / 2
1.0.79 2 / 2
1.0.78 2 / 2
1.0.77 2 / 2
1.0.76 2 / 2
1.0.75 2 / 2
1.0.74 2 / 2
1.0.73 2 / 2
1.0.72 2 / 2
1.0.71 2 / 2
1.0.70 2 / 2
1.0.69 2 / 2
1.0.68 2 / 2
1.0.67 2 / 2
1.0.66 2 / 2
1.0.65 2 / 2
1.0.64 2 / 2
1.0.63 2 / 2
1.0.62 2 / 2
1.0.61 2 / 2
1.0.60 2 / 2
1.0.59 2 / 2
1.0.58 2 / 2
1.0.57 2 / 2
1.0.56 2 / 2
1.0.55 2 / 2
1.0.54 2 / 2
1.0.53 2 / 2
1.0.52 2 / 2
1.0.51 2 / 2
1.0.50 2 / 2
1.0.49 2 / 2
1.0.48 2 / 2
1.0.47 2 / 2
1.0.46 2 / 2
1.0.45 2 / 2
1.0.44 2 / 2
1.0.43 2 / 2
1.0.42 2 / 2
1.0.41 2 / 2
1.0.40 2 / 2
1.0.39 2 / 2

v1.0.89

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.88

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.87

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.86

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.85

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.84

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.83

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.82

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.81

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.80

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.79

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.78

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.77

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.76

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.75

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.74

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.73

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.72

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.71

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.70

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.69

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.68

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.67

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.66

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.65

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.64

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.63

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.62

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.60

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.51

8 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-09-29) provenance

This version was published by a different npm account than previous versions on 2025-09-29. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.50

8 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-09-22) provenance

This version was published by a different npm account than previous versions on 2025-09-22. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.49

8 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-09-22) provenance

This version was published by a different npm account than previous versions on 2025-09-22. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.48

8 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-09-19) provenance

This version was published by a different npm account than previous versions on 2025-09-19. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.47

8 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-09-14) provenance

This version was published by a different npm account than previous versions on 2025-09-14. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.46

8 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-09-14) provenance

This version was published by a different npm account than previous versions on 2025-09-14. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/meta.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.45

6 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-09-10) provenance

This version was published by a different npm account than previous versions on 2025-09-10. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.44

6 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-08-28) provenance

This version was published by a different npm account than previous versions on 2025-08-28. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.43

6 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-08-28) provenance

This version was published by a different npm account than previous versions on 2025-08-28. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.42

6 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-08-27) provenance

This version was published by a different npm account than previous versions on 2025-08-27. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.41

6 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-08-20) provenance

This version was published by a different npm account than previous versions on 2025-08-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.40

6 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-08-20) provenance

This version was published by a different npm account than previous versions on 2025-08-20. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.39

6 findings
HIGH Publisher changed: roir-wix → wix-ci-publisher (on 2025-08-12) provenance

This version was published by a different npm account than previous versions on 2025-08-12. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: build/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: build/internal/es/index.typings.d.mts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.