@wix/auto_sdk_events_rsvp-v-2
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/cjs/events-v2-rsvp-rsvp-v-2.universal-DONDfd6H.d.ts | AI (source-diff): Generated TypeScript declaration file; long lines are type unions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/events-v2-rsvp-rsvp-v-2.universal-BzVZD9ih.d.ts | AI (source-diff): Generated TypeScript declaration file; long lines are type unions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/es/events-v2-rsvp-rsvp-v-2.universal-DONDfd6H.d.mts | AI (source-diff): Generated TypeScript declaration file; long lines are type unions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/events-v2-rsvp-rsvp-v-2.universal-BzVZD9ih.d.mts | AI (source-diff): Generated TypeScript declaration file; long lines are type unions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/events-v2-rsvp-rsvp-v-2.universal-DZlatNq1.d.mts | AI (source-diff): Long-line TypeScript declaration files from Wix SDK build pipeline; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/events-v2-rsvp-rsvp-v-2.universal-DZlatNq1.d.ts | AI (source-diff): Long-line TypeScript declaration files from Wix SDK build pipeline; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/es/events-v2-rsvp-rsvp-v-2.universal-DoS_qoxC.d.mts | AI (source-diff): Long-line TypeScript declaration files from Wix SDK build pipeline; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/cjs/events-v2-rsvp-rsvp-v-2.universal-DoS_qoxC.d.ts | AI (source-diff): Long-line TypeScript declaration files from Wix SDK build pipeline; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/events-v2-rsvp-rsvp-v-2.universal-kzb9lHo4.d.ts | AI (source-diff): Generated TypeScript declaration file with long lines from type definitions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/events-v2-rsvp-rsvp-v-2.universal-kzb9lHo4.d.mts | AI (source-diff): Generated TypeScript declaration file with long lines from type definitions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/es/events-v2-rsvp-rsvp-v-2.universal-P8IrmWgZ.d.mts | AI (source-diff): Generated TypeScript declaration file with long lines from type definitions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/cjs/events-v2-rsvp-rsvp-v-2.universal-P8IrmWgZ.d.ts | AI (source-diff): Generated TypeScript declaration file with long lines from type definitions, not obfuscation. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/events-v2-rsvp-rsvp-v-2.universal-DJqTgNEg.d.ts | AI (source-diff): Generated TypeScript declaration file with long JSDoc lines; not obfuscated code. Stable pattern for Wix SDK packages. | ai | |
| source-diff | obfuscated-file:build/internal/es/events-v2-rsvp-rsvp-v-2.universal-DJqTgNEg.d.mts | AI (source-diff): Generated TypeScript declaration file with long JSDoc lines; not obfuscated code. Stable pattern for Wix SDK packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Wix auto-generated SDK family; templated names, no description/repo are expected patterns across all versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Intentionally undescribed auto-generated SDK package; stable pattern for this package family. | ai | |
| source-diff | obfuscated-file:build/internal/es/events-v2-rsvp-rsvp-v-2.universal-DtCsSfgT.d.mts | AI (source-diff): Generated TypeScript declaration file with long type union lines; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/internal/cjs/events-v2-rsvp-rsvp-v-2.universal-DtCsSfgT.d.ts | AI (source-diff): Generated TypeScript declaration file with long type union lines; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/cjs/events-v2-rsvp-rsvp-v-2.universal-D8WtCCSm.d.ts | AI (source-diff): Generated TypeScript declaration file with long type union lines; not obfuscated code. | ai | |
| source-diff | obfuscated-file:build/es/events-v2-rsvp-rsvp-v-2.universal-D8WtCCSm.d.mts | AI (source-diff): Generated TypeScript declaration file with long type union lines; not obfuscated code. | ai |
Versions (showing 41 of 41)
| Version | Deps | Published |
|---|---|---|
| 1.0.97 | 3 / 2 | |
| 1.0.96 | 3 / 2 | |
| 1.0.95 | 3 / 2 | |
| 1.0.94 | 3 / 2 | |
| 1.0.93 | 3 / 2 | |
| 1.0.92 | 3 / 2 | |
| 1.0.91 | 3 / 2 | |
| 1.0.90 | 3 / 2 | |
| 1.0.47 | 2 / 2 | |
| 1.0.46 | 2 / 2 | |
| 1.0.45 | 2 / 2 | |
| 1.0.44 | 2 / 2 | |
| 1.0.43 | 2 / 2 | |
| 1.0.42 | 2 / 2 | |
| 1.0.41 | 2 / 2 | |
| 1.0.40 | 2 / 2 | |
| 1.0.39 | 2 / 2 | |
| 1.0.38 | 2 / 2 | |
| 1.0.37 | 2 / 2 | |
| 1.0.36 | 2 / 2 | |
| 1.0.35 | 2 / 2 | |
| 1.0.34 | 2 / 2 | |
| 1.0.33 | 2 / 2 | |
| 1.0.32 | 2 / 2 | |
| 1.0.31 | 2 / 2 | |
| 1.0.30 | 2 / 2 | |
| 1.0.29 | 2 / 2 | |
| 1.0.28 | 2 / 2 | |
| 1.0.27 | 2 / 2 | |
| 1.0.26 | 2 / 2 | |
| 1.0.25 | 2 / 2 | |
| 1.0.24 | 2 / 1 | |
| 1.0.23 | 2 / 1 | |
| 1.0.22 | 2 / 1 | |
| 1.0.21 | 2 / 1 | |
| 1.0.20 | 2 / 1 | |
| 1.0.19 | 2 / 1 | |
| 1.0.18 | 2 / 2 | |
| 1.0.17 | 2 / 2 | |
| 1.0.16 | 2 / 2 | |
| 1.0.15 | 2 / 1 |
v1.0.97
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.96
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.95
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.94
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.93
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.92
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.91
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.90
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.47
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.46
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.45
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.44
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.42
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.38
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.37
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.36
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.35
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.34
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.33
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.32
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.