@wix/error-handler-core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:@wix/bi-logger-os-data/src/v2/index.ts | AI (source-diff): Auto-generated BI logger source with long import lines; not obfuscation. | ai | |
| source-diff | obfuscated-file:@wix/bi-logger-os-data/dist/types/index.d.ts | AI (source-diff): Auto-generated BI logger type declaration with long import lines; not obfuscation. | ai | |
| source-diff | obfuscated-file:@wix/bi-logger-os-data/dist/types/v2/index.d.ts | AI (source-diff): Auto-generated BI logger type declaration with long import lines; not obfuscation. | ai | |
| source-diff | obfuscated-file:@wix/bi-logger-os-data/src/index.ts | AI (source-diff): Auto-generated BI logger source with long import lines; not obfuscation. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal Wix monorepo package; sparse metadata is expected for org-internal scoped packages. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal scoped package; missing description is consistent across Wix monorepo packages. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-level transitive dep; stable false positive for this package. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is common; no other risk signals present for this internal package. | ai |
v1.20.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.