← Home

@workflow/builders

14
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matt.strakavercel-release-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/fast-discovery.test.js AI (source-diff): Plain vitest test file; long-line heuristic false positive. ai
source-diff obfuscated-file:dist/step-source-registration.test.js AI (source-diff): Plain vitest test file; long-line heuristic false positive. ai
source-diff obfuscated-file:dist/workflows-extractor.test.js AI (source-diff): Plain vitest test file; long-line heuristic false positive. ai
source-diff obfuscated-file:dist/fast-discovery.js AI (source-diff): Readable ESM discovery source with long regex/data lines; not obfuscation. ai
source-diff obfuscated-file:dist/base-builder-logging.test.js AI (source-diff): Plain vitest test file; long-line heuristic false positive. ai
source-diff obfuscated-file:dist/constants.test.js AI (source-diff): Long line is a base64 sourceMappingURL from tsc output, not obfuscation. ai
phantom-deps phantom-dep:@workflow/core AI (phantom-deps): Same-org monorepo dependency; declared in package.json as a runtime dep, phantom detection is a false positive here. ai

Versions (showing 14 of 14)

Version Deps Published
4.1.3 12 / 2
4.1.2 12 / 2
4.1.1 12 / 2
4.1.0 12 / 2
4.0.10 12 / 2
4.0.9 12 / 2
4.0.8 12 / 2
4.0.7 12 / 2
4.0.6 12 / 2
4.0.5 12 / 2
4.0.4 12 / 2
4.0.3 12 / 2
4.0.2 12 / 2
4.0.1 12 / 2

v4.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.1

6 findings
HIGH New obfuscated file: dist/base-builder-logging.test.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/fast-discovery.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/fast-discovery.test.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/step-source-registration.test.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/workflows-extractor.test.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.