← Home

@workflow/web

Workflow Observability UI

13
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matt.strakavercel-release-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:build/server/assets/server-build-CAufQfpc.js AI (source-diff): Bundled vite/react-router server build, not true obfuscation. ai
source-diff net-exec-file:build/server/assets/server-build-CAufQfpc.js AI (source-diff): SSR server bundle naturally contains network + dynamic code patterns; no exfil behavior found. ai
source-diff net-exec-file:build/server/assets/server-build-HnD5F5wE.js AI (source-diff): Server bundle (express/react-router); no unrelated exfil destination. ai
source-diff obfuscated-file:build/server/assets/server-build-HnD5F5wE.js AI (source-diff): Minified Vite SSR bundle with bundler banner; benign build output. ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-Bp6ZST9_.js AI (source-diff): Standard bundled framework code; no hostile net/exec target. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-Bp6ZST9_.js AI (source-diff): Minified Vite client bundle, not obfuscation; regenerated per release. ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-B6kYjVMX.js AI (source-diff): Fetch+dynamic import are normal React SSR bundle patterns, no hostile target. ai
source-diff net-exec-file:build/server/assets/server-build-X-sv9tml.js AI (source-diff): SSR server bundle; network+exec inherent to React Router server build. ai
source-diff obfuscated-file:build/server/assets/server-build-X-sv9tml.js AI (source-diff): esbuild server bundle, minified build output not obfuscation. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-B6kYjVMX.js AI (source-diff): Vite bundle (mapDeps banner), minified not obfuscated; regenerated each build. ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-CWOyQBTZ.js AI (source-diff): Client-side bundle with fetch + dynamic import is normal for Vite code-split output. ai
source-diff net-exec-file:build/server/assets/server-build-dI1gM6-m.js AI (source-diff): Server bundle naturally uses network + dynamic code; standard SSR pattern. ai
source-diff obfuscated-file:build/server/assets/server-build-dI1gM6-m.js AI (source-diff): Vite-bundled server entry; standard minified React Router SSR output. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-CWOyQBTZ.js AI (source-diff): Vite-bundled mermaid chart library; standard minified output for this web UI package. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-ZIVWJOga.js AI (source-diff): Vite-bundled client asset containing mermaid library; minification is expected. ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-ZIVWJOga.js AI (source-diff): Client-side React bundle with fetch/dynamic import — normal for Vite output. ai
source-diff obfuscated-file:build/server/assets/server-build-DUwThcMX.js AI (source-diff): Vite SSR server bundle; long lines from bundling, not obfuscation. ai
source-diff net-exec-file:build/server/assets/server-build-DUwThcMX.js AI (source-diff): Server-side React Router bundle with HTTP handling — expected pattern. ai
source-diff net-exec-file:build/server/assets/server-build-BBm5-YMr.js AI (source-diff): SSR server bundle with network + dynamic code; expected for React Router server build. ai
source-diff obfuscated-file:build/server/assets/server-build-BBm5-YMr.js AI (source-diff): Vite SSR server bundle; standard minified build output for this web UI package. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-CjHrXABH.js AI (source-diff): Vite-bundled mermaid chart library; minified build output, not obfuscation. ai
source-diff net-exec-file:build/server/assets/server-build-JwomDvSn.js AI (source-diff): Server-side React Router bundle; network + dynamic code is expected. ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-CjHrXABH.js AI (source-diff): Client-side React bundle with fetch + dynamic import; normal for SPA. ai
source-diff obfuscated-file:build/server/assets/server-build-JwomDvSn.js AI (source-diff): Vite/React Router server build bundle; minified output is expected. ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-Cr7OQX4b.js AI (source-diff): Client-side React bundle with dynamic imports; not malicious network+exec. ai
source-diff net-exec-file:build/server/assets/server-build-DBNmVwSJ.js AI (source-diff): SSR server bundle with HTTP handling; expected for a web app server build. ai
source-diff obfuscated-file:build/server/assets/server-build-DBNmVwSJ.js AI (source-diff): Vite SSR server bundle; standard minified build output. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-Cr7OQX4b.js AI (source-diff): Vite-bundled mermaid chart library; standard minified build output. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-BE1h5qUK.js AI (source-diff): Standard Vite-minified client bundle; mermaid is a declared devDep, content is recognizable React/Mermaid code. ai
source-diff net-exec-file:build/server/assets/server-build-DiegzHGY.js AI (source-diff): Network+exec pattern in SSR bundle is expected for a React Router server; no malicious indicators in samples. ai
source-diff obfuscated-file:build/server/assets/server-build-DiegzHGY.js AI (source-diff): Standard Vite/React Router SSR server bundle; content matches declared deps (minimatch, react-router, etc.). ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-BE1h5qUK.js AI (source-diff): Network+exec pattern in a browser UI bundle is expected; no actual dropper behavior in samples. ai
source-diff obfuscated-file:build/client/assets/mermaid-3ZIDBTTL-B_qZU5zW.js AI (source-diff): Standard Vite-minified client bundle; mermaid + Radix UI code visible in sample, not malicious obfuscation. ai
source-diff net-exec-file:build/client/assets/mermaid-3ZIDBTTL-B_qZU5zW.js AI (source-diff): Network + eval pattern in a browser-side mermaid/React bundle is expected; no dropper behavior in sample. ai
source-diff obfuscated-file:build/server/assets/server-build-UvQ8ujzE.js AI (source-diff): Standard Vite SSR server bundle; React Router, minimatch, and React imports visible in sample. ai
source-diff net-exec-file:build/server/assets/server-build-UvQ8ujzE.js AI (source-diff): Server-side SSR bundle with network calls is expected for a React Router express server package. ai

Versions (showing 13 of 13)

Version Deps Published
4.1.14 1 / 47
4.1.13 1 / 47
4.1.12 1 / 47
4.1.11 1 / 47
4.1.10 1 / 47
4.1.9 1 / 47
4.1.8 1 / 47
4.1.7 1 / 47
4.1.6 1 / 47
4.1.5 1 / 47
4.1.4 1 / 47
4.1.1 1 / 47
4.1.0 1 / 47

v4.1.14

3 findings
HIGH New obfuscated file: build/server/assets/server-build-CAufQfpc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/server/assets/server-build-CAufQfpc.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.13

5 findings
HIGH New obfuscated file: build/client/assets/mermaid-3ZIDBTTL-Bp6ZST9_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/assets/mermaid-3ZIDBTTL-Bp6ZST9_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/server/assets/server-build-HnD5F5wE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/server/assets/server-build-HnD5F5wE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.12

5 findings
HIGH New obfuscated file: build/client/assets/mermaid-3ZIDBTTL-B6kYjVMX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/client/assets/mermaid-3ZIDBTTL-B6kYjVMX.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/server/assets/server-build-X-sv9tml.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/server/assets/server-build-X-sv9tml.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.