@xwiki/cristal-electron-renderer
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/github-CTLFo_VH.js | AI (source-diff): Bundled app module output, standard Vite chunk naming. | ai | |
| source-diff | obfuscated-file:dist/floating-ui.dom-AjS1hz1P.js | AI (source-diff): Bundled third-party dependency (floating-ui), minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/c-edit-blocknote-BDXBHJ_D.js | AI (source-diff): Vite/Rollup bundled output with sourcemap; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/module-RjUF93sV.js | AI (source-diff): Bundled preact/vue compat shim, minified build output. | ai | |
| source-diff | obfuscated-file:dist/index-CCWBEKc7.js | AI (source-diff): Main bundled entry chunk with sourcemap shipped. | ai | |
| source-diff | net-exec-file:dist/index-CCWBEKc7.js | AI (source-diff): Vite modulepreload polyfill fetch + generic eval this-resolution, standard bundler boilerplate. | ai | |
| source-diff | obfuscated-file:dist/index-BYzEVDKE.js | AI (source-diff): Vite-bundled app entry, not true obfuscation; bundler banner present. | ai | |
| source-diff | net-exec-file:dist/index-BYzEVDKE.js | AI (source-diff): Standard vite modulepreload polyfill fetch, not a dropper pattern. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers are known xwiki.org team accounts, consistent with monorepo org. | ai | |
| source-diff | obfuscated-file:dist/floating-ui.dom-1S43Ew4Q.js | AI (source-diff): Bundled third-party UI positioning library. | ai | |
| source-diff | obfuscated-file:dist/hocuspocus-provider.esm-DpwNtHpL.js | AI (source-diff): Bundled collaboration provider lib, standard minified output. | ai | |
| source-diff | obfuscated-file:dist/offline-3x82kJQp.js | AI (source-diff): Bundled offline-mode module, consistent with other vite chunks. | ai | |
| source-diff | obfuscated-file:dist/NextcloudLoginMenu-BTVdL-FM.js | AI (source-diff): Bundled login form component, benign i18n strings visible. | ai | |
| source-diff | obfuscated-file:dist/nextcloud-B3M7otLC.js | AI (source-diff): Bundled Nextcloud auth UI module. | ai | |
| source-diff | net-exec-file:dist/index-B1WxkRNy.js | AI (source-diff): fetch+eval pattern is Vite's own modulepreload/Reflect polyfill code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-B1WxkRNy.js | AI (source-diff): Main Vite bundle entry with modulepreload polyfill, not malicious. | ai | |
| source-diff | obfuscated-file:dist/c-edit-blocknote-ByH5aYGe.js | AI (source-diff): Vite-bundled UI dependency (blocknote editor), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/github-CRi3Ye_z.js | AI (source-diff): Bundled login-menu module, vite banner confirms build output. | ai | |
| source-diff | net-exec-file:dist/index-BueVmDE0.js | AI (source-diff): fetch+eval fallback is standard Vite/Reflect polyfill code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-BueVmDE0.js | AI (source-diff): Vite bundle output for renderer UI, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/c-edit-blocknote-B9O11r92.js | AI (source-diff): Vite bundle output, not true obfuscation. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Internal monorepo subpackage, description omission is stylistic. | ai | |
| source-diff | obfuscated-file:dist/nextcloud-D7e5A3Dh.js | AI (source-diff): App feature module (Nextcloud login), Vite bundled. | ai | |
| source-diff | obfuscated-file:dist/hocuspocus-provider.esm-GdH-tehR.js | AI (source-diff): Known hocuspocus/yjs library bundled. | ai | |
| source-diff | obfuscated-file:dist/github-hmgjRgJ9.js | AI (source-diff): App feature module (GitHub login), Vite bundled. | ai | |
| source-diff | obfuscated-file:dist/floating-ui.dom-jUMXNG6O.js | AI (source-diff): Known floating-ui library bundled, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-BAvNOApG.js | AI (source-diff): Standard Vite modulepreload polyfill fetch, not malicious net-exec. | ai | |
| source-diff | obfuscated-file:dist/index-BAvNOApG.js | AI (source-diff): Vite bundle output, not true obfuscation. | ai | |
| phantom-deps | phantom-dep:inversify | AI (phantom-deps): inversify is a declared runtime dep; phantom-dep fires on DI config files, not direct imports. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): vue-router is a declared runtime dep used in router config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:vue | AI (phantom-deps): vue is a declared runtime dep used in Vite/Vue app config; phantom-dep heuristic fires on config-only references. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 1.5.0 | 18 / 4 | |
| 1.4.0 | 18 / 4 | |
| 1.3.0 | 18 / 4 | |
| 1.2.0 | 18 / 4 | |
| 1.1.0 | 17 / 4 | |
| 1.0.0 | 17 / 4 | |
| 0.25.0 | 17 / 4 | |
| 0.24.0 | 17 / 4 |
v1.5.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.0
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.0
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.24.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.