← Home

@xwiki/cristal-electron-renderer

8
Versions
LGPL 2.1
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

xwikiorgnpmtmortagneesurlimanuelleducpierre.jeanjeanmarius.dumitru.floreavmassolmichael.hamann

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/github-CTLFo_VH.js AI (source-diff): Bundled app module output, standard Vite chunk naming. ai
source-diff obfuscated-file:dist/floating-ui.dom-AjS1hz1P.js AI (source-diff): Bundled third-party dependency (floating-ui), minified not obfuscated. ai
source-diff obfuscated-file:dist/c-edit-blocknote-BDXBHJ_D.js AI (source-diff): Vite/Rollup bundled output with sourcemap; not true obfuscation. ai
source-diff obfuscated-file:dist/module-RjUF93sV.js AI (source-diff): Bundled preact/vue compat shim, minified build output. ai
source-diff obfuscated-file:dist/index-CCWBEKc7.js AI (source-diff): Main bundled entry chunk with sourcemap shipped. ai
source-diff net-exec-file:dist/index-CCWBEKc7.js AI (source-diff): Vite modulepreload polyfill fetch + generic eval this-resolution, standard bundler boilerplate. ai
source-diff obfuscated-file:dist/index-BYzEVDKE.js AI (source-diff): Vite-bundled app entry, not true obfuscation; bundler banner present. ai
source-diff net-exec-file:dist/index-BYzEVDKE.js AI (source-diff): Standard vite modulepreload polyfill fetch, not a dropper pattern. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers are known xwiki.org team accounts, consistent with monorepo org. ai
source-diff obfuscated-file:dist/floating-ui.dom-1S43Ew4Q.js AI (source-diff): Bundled third-party UI positioning library. ai
source-diff obfuscated-file:dist/hocuspocus-provider.esm-DpwNtHpL.js AI (source-diff): Bundled collaboration provider lib, standard minified output. ai
source-diff obfuscated-file:dist/offline-3x82kJQp.js AI (source-diff): Bundled offline-mode module, consistent with other vite chunks. ai
source-diff obfuscated-file:dist/NextcloudLoginMenu-BTVdL-FM.js AI (source-diff): Bundled login form component, benign i18n strings visible. ai
source-diff obfuscated-file:dist/nextcloud-B3M7otLC.js AI (source-diff): Bundled Nextcloud auth UI module. ai
source-diff net-exec-file:dist/index-B1WxkRNy.js AI (source-diff): fetch+eval pattern is Vite's own modulepreload/Reflect polyfill code, not a dropper. ai
source-diff obfuscated-file:dist/index-B1WxkRNy.js AI (source-diff): Main Vite bundle entry with modulepreload polyfill, not malicious. ai
source-diff obfuscated-file:dist/c-edit-blocknote-ByH5aYGe.js AI (source-diff): Vite-bundled UI dependency (blocknote editor), not obfuscation. ai
source-diff obfuscated-file:dist/github-CRi3Ye_z.js AI (source-diff): Bundled login-menu module, vite banner confirms build output. ai
source-diff net-exec-file:dist/index-BueVmDE0.js AI (source-diff): fetch+eval fallback is standard Vite/Reflect polyfill code, not a dropper. ai
source-diff obfuscated-file:dist/index-BueVmDE0.js AI (source-diff): Vite bundle output for renderer UI, not true obfuscation. ai
source-diff obfuscated-file:dist/c-edit-blocknote-B9O11r92.js AI (source-diff): Vite bundle output, not true obfuscation. ai
npm-metadata no-description AI (npm-metadata): Internal monorepo subpackage, description omission is stylistic. ai
source-diff obfuscated-file:dist/nextcloud-D7e5A3Dh.js AI (source-diff): App feature module (Nextcloud login), Vite bundled. ai
source-diff obfuscated-file:dist/hocuspocus-provider.esm-GdH-tehR.js AI (source-diff): Known hocuspocus/yjs library bundled. ai
source-diff obfuscated-file:dist/github-hmgjRgJ9.js AI (source-diff): App feature module (GitHub login), Vite bundled. ai
source-diff obfuscated-file:dist/floating-ui.dom-jUMXNG6O.js AI (source-diff): Known floating-ui library bundled, not obfuscated malware. ai
source-diff net-exec-file:dist/index-BAvNOApG.js AI (source-diff): Standard Vite modulepreload polyfill fetch, not malicious net-exec. ai
source-diff obfuscated-file:dist/index-BAvNOApG.js AI (source-diff): Vite bundle output, not true obfuscation. ai
phantom-deps phantom-dep:inversify AI (phantom-deps): inversify is a declared runtime dep; phantom-dep fires on DI config files, not direct imports. ai
phantom-deps phantom-dep:vue-router AI (phantom-deps): vue-router is a declared runtime dep used in router config; stable false positive for this package. ai
phantom-deps phantom-dep:vue AI (phantom-deps): vue is a declared runtime dep used in Vite/Vue app config; phantom-dep heuristic fires on config-only references. ai

Versions (showing 8 of 8)

Version Deps Published
1.5.0 18 / 4
1.4.0 18 / 4
1.3.0 18 / 4
1.2.0 18 / 4
1.1.0 17 / 4
1.0.0 17 / 4
0.25.0 17 / 4
0.24.0 17 / 4

v1.5.0

7 findings
HIGH New obfuscated file: dist/c-edit-blocknote-BDXBHJ_D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.dom-AjS1hz1P.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/github-CTLFo_VH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CCWBEKc7.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CCWBEKc7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/module-RjUF93sV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

10 findings
HIGH New obfuscated file: dist/c-edit-blocknote-ByH5aYGe.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.dom-1S43Ew4Q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/github-CRi3Ye_z.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/hocuspocus-provider.esm-DpwNtHpL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-B1WxkRNy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/index-B1WxkRNy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/nextcloud-B3M7otLC.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/NextcloudLoginMenu-BTVdL-FM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/offline-3x82kJQp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

11 findings
HIGH New obfuscated file: dist/c-edit-blocknote-DumSgiT9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.dom-CAEmS8ps.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/github-D7zUI4at.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/hocuspocus-provider.esm-BpfHyEB8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BYzEVDKE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/index-BYzEVDKE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/nextcloud-CQE2ECP9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/nextcloud-internal-link-serializer-aQPALjjh-CC4jDDwx.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/NextcloudLoginMenu-KDDcub8n.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/offline-D7usGBRp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

11 findings
HIGH New obfuscated file: dist/c-edit-blocknote-B9O11r92.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.dom-jUMXNG6O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/github-hmgjRgJ9.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/hocuspocus-provider.esm-GdH-tehR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BAvNOApG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/index-BAvNOApG.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/nextcloud-D7e5A3Dh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/nextcloud-internal-link-serializer-aQPALjjh-BU4rmHkd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/NextcloudLoginMenu-D4rNYEoA.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/offline-BDCQW0NP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.25.0

12 findings
HIGH New obfuscated file: dist/c-edit-blocknote-QDrd5S5Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/floating-ui.dom-jUMXNG6O.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/github-BIEhyZwR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/hocuspocus-provider.esm-Gm89v0mM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-BueVmDE0.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: dist/index-BueVmDE0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/iterator-6Q8PBxGN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/nextcloud-DItVvF-I.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/nextcloud-internal-link-serializer-aQPALjjh-BEsoCl8_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/NextcloudLoginMenu-TTe74pvj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/offline-R9-n_mTj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.