← Home

bippy

100
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

abai

Keywords

bippyfiberinternalsreactreact devtoolsreact fiberreact instrumentation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/source-DjV3BlJf.js AI (source-diff): Bundled runtime shim + stack-parser code, not net-exec; hashed dist filenames change per build. ai
source-diff net-exec-file:dist/source-CgGjiK9R.cjs AI (source-diff): Bundled runtime shim + stack-parser code, not net-exec; hashed dist filenames change per build. ai
source-diff net-exec-file:dist/source-AAPM9BO7.js AI (source-diff): Same bundled build artifact, ESM variant; benign for this package. ai
source-diff net-exec-file:dist/source-WLoJP0PF.cjs AI (source-diff): Bundled dist output with legit banner; stack/source-map parsing, no exfil destination. ai
source-diff net-exec-file:dist/source-Bu6NKhnI.cjs AI (source-diff): Rolldown-bundled source export; stack-parser/fiber code, no hostile destination. ai
source-diff net-exec-file:dist/source-DWOhEbf2.js AI (source-diff): Rolldown-bundled source export; stack-parser/fiber code, no hostile destination. ai
source-diff net-exec-file:dist/source-DNoVJul7.js AI (source-diff): Rolldown-bundled dist of source-map/stack parsing feature; benign build output. ai
source-diff net-exec-file:dist/source-CpnylWPF.cjs AI (source-diff): Rolldown-bundled dist of source-map/stack parsing feature; benign build output. ai
source-diff obfuscated-file:dist/core-SjGIw1cd.js AI (source-diff): Minified ESM bundle output; benign. ai
source-diff obfuscated-file:dist/rdt-hook-C62IwObP.cjs AI (source-diff): Minified RDT hook install code; core stated function. ai
source-diff obfuscated-file:dist/core-Du-sCECq.cjs AI (source-diff): Minified esbuild/tsdown output with license banner; benign for this build tool. ai
source-diff obfuscated-file:dist/src-BPHAAijb.cjs AI (source-diff): Minified build output with license banner; benign. ai
source-diff obfuscated-file:dist/index-Qs1rAFd9.d.ts AI (source-diff): Type-declaration bundle, long lines only; benign. ai
source-diff obfuscated-file:dist/src-C-CLm2l3.js AI (source-diff): Minified ESM build output; benign. ai
source-diff obfuscated-file:dist/index-lite-D5nI1ci5.cjs AI (source-diff): Minified esbuild bundle, not obfuscation; matches stated React-internals function. ai
source-diff net-exec-file:dist/source-A3voVUIp.cjs AI (source-diff): Rolldown-bundled dist; source-map/stack parsing, no real net-exec payload. ai
source-diff net-exec-file:dist/source-CvcvVqiB.js AI (source-diff): Rolldown-bundled dist; source-map/stack parsing, no real net-exec payload. ai
source-diff net-exec-file:dist/source-CSdAtQJ_.cjs AI (source-diff): Bundled rolldown output of the source-map module; no hostile destination, stable build artifact. ai
source-diff net-exec-file:dist/source-LNQQC0ZJ.js AI (source-diff): Bundled rolldown output of the source-map module; no hostile destination, stable build artifact. ai
source-diff net-exec-file:dist/source-Cq1_jzmd.cjs AI (source-diff): Bundled dist of the ./source export; error-stack/source-map code, no exfil destination. ai
source-diff net-exec-file:dist/source-C_40r4dr.js AI (source-diff): Bundled dist of the ./source export; error-stack/source-map code, no exfil destination. ai
source-diff net-exec-file:dist/source-BsqRDfoP.js AI (source-diff): ESM bundle of same source export; build artifact, not malware. ai
source-diff net-exec-file:dist/source-B7n25ucM.cjs AI (source-diff): Rolldown build output for the ./source export; benign stack-parsing/instrumentation code. ai
source-diff net-exec-file:dist/source-l0-0Utl0.js AI (source-diff): Same rolldown-bundled source-map parser; benign build output. ai
source-diff net-exec-file:dist/source-CpUl2rbU.cjs AI (source-diff): Stack/source-map parser bundle; net+exec heuristic is FP for this file. ai
source-diff net-exec-file:dist/source-DQCmZhBV.js AI (source-diff): Rolldown-bundled source-map/stack-parse code; benign build output for this lib. ai
source-diff net-exec-file:dist/source-ilDotInf.cjs AI (source-diff): Rolldown-bundled source-map/stack-parse code; benign build output for this lib. ai
source-diff net-exec-file:dist/source-DDEKmBrT.js AI (source-diff): Rolldown build output for source-map/fiber features; renamed bundle chunks recur every release. ai
source-diff net-exec-file:dist/source-B2Lz42Ab.cjs AI (source-diff): Rolldown build output for source-map/fiber features; renamed bundle chunks recur every release. ai
source-diff net-exec-file:dist/source-umpQJuDB.cjs AI (source-diff): Bundled dist output of source-map tooling; net+exec heuristic false positive for this build. ai
source-diff net-exec-file:dist/source-DjN4dTb0.js AI (source-diff): Bundled dist output; heuristic false positive, stable across releases. ai
source-diff net-exec-file:dist/source-CzshDdc9.js AI (source-diff): ESM sibling of same bundled source module; benign build artifact. ai
source-diff net-exec-file:dist/source-Bs3pHZxr.cjs AI (source-diff): Rolldown build output of source module; net/exec heuristic on bundled React-instrumentation code, no hostile target. ai
source-diff obfuscated-file:dist/core-DJZ0crEP.js AI (source-diff): Minified ESM bundle; benign build artifact. ai
source-diff obfuscated-file:dist/core-cPlOVfyn.cjs AI (source-diff): Minified tsdown bundle output with license banner; benign build artifact. ai
source-diff obfuscated-file:dist/rdt-hook-ByGa6hoK.cjs AI (source-diff): Minified RDT-hook instrumentation; benign build artifact. ai
source-diff net-exec-file:dist/source-BAPwFAwe.cjs AI (source-diff): Rolldown-bundled source-map parsing artifact; benign build output for this lib. ai
source-diff net-exec-file:dist/source-D2grjLFe.js AI (source-diff): Rolldown-bundled ESM equivalent; same benign build output. ai
source-diff net-exec-file:dist/source-D27ZXa0o.cjs AI (source-diff): Rolldown-bundled source-map/stack-parser dist output; benign build artifact. ai
source-diff net-exec-file:dist/source-7rH6oRiA.js AI (source-diff): Rolldown-bundled source-map/stack-parser dist output; benign build artifact. ai
source-diff net-exec-file:dist/source-BfkxIx1q.js AI (source-diff): Same bundled build output, ESM variant; benign for this package. ai
source-diff net-exec-file:dist/source-CD5HO-_u.cjs AI (source-diff): Rolldown-bundled dist of source-map/stack-parsing module; no hostile destination. ai
source-diff obfuscated-file:dist/core.d.ts AI (source-diff): Type declaration file, not obfuscated. ai
source-diff obfuscated-file:dist/core--XA5AwF7.d.ts AI (source-diff): Type declaration file, not obfuscated. ai
source-diff obfuscated-file:dist/core-DXbEy_Jg.js AI (source-diff): ESM minified build output; benign. ai
source-diff obfuscated-file:dist/rdt-hook-B9Wwh1TS.cjs AI (source-diff): Minified RDT hook bundle; core package function. ai
source-diff obfuscated-file:dist/core-DLqvN8F5.cjs AI (source-diff): Minified tsdown build output, not obfuscation; stable for this package. ai
source-diff obfuscated-file:dist/core-ClKFLt2T.cjs AI (source-diff): Minified tsdown build output with license banner; benign for this build tool. ai
source-diff large-new-source-files AI (source-diff): Dist bundle chunk churn from tsdown; expected. ai
source-diff obfuscated-file:dist/core.js AI (source-diff): Minified ESM re-export; benign build output. ai
source-diff obfuscated-file:dist/core-B0h3hqBg.js AI (source-diff): Minified ESM build output; benign. ai
source-diff obfuscated-file:dist/rdt-hook-CSGZ9466.cjs AI (source-diff): Minified React devtools hook logic; benign build output. ai
source-diff obfuscated-file:dist/core.cjs AI (source-diff): Minified re-export shim; benign build output. ai
source-diff obfuscated-file:dist/react-refresh.cjs AI (source-diff): Vite-bundled minified output; benign build artifact. ai
source-diff obfuscated-file:dist/react-refresh.js AI (source-diff): Vite-bundled minified output; benign build artifact. ai
source-diff obfuscated-file:dist/get-source.js AI (source-diff): Minified bundler output; build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/get-source.cjs AI (source-diff): Minified bundler output with license banner; build artifact, not obfuscation. ai
source-diff obfuscated-file:dist/src-B1XV7Ej_.js AI (source-diff): ESM counterpart of the same minified build output; no obfuscation. ai
source-diff obfuscated-file:dist/index-YNyYB6YK.d.ts AI (source-diff): Bundled TypeScript declaration file with long import lines; not obfuscated. ai
source-diff obfuscated-file:dist/src-CZc5lOwK.cjs AI (source-diff): Standard minified build output from tsdown; readable React DevTools instrumentation code. ai
source-diff net-exec-file:dist/source-CBCTB51B.js AI (source-diff): ESM bundle output with standard interop; not malicious network/exec activity. ai
source-diff net-exec-file:dist/source-VilPky0v.cjs AI (source-diff): Rolldown bundle output with CJS interop; not malicious network/exec activity. ai
source-diff net-exec-file:dist/source-CTbJ4jWB.cjs AI (source-diff): Rolldown bundler output containing error-stack-parser and React fiber code; not malicious. ai
source-diff net-exec-file:dist/source-DApL4zD4.js AI (source-diff): ESM counterpart of the same rolldown bundle; not malicious. ai
source-diff net-exec-file:dist/source-CAKKlkON.js AI (source-diff): ESM bundle with rolldown runtime helpers; not malicious. ai
source-diff net-exec-file:dist/source-C6Kcs2bv.cjs AI (source-diff): Bundled build output with CJS interop helpers; not malicious network/exec. ai
source-diff net-exec-file:dist/source-CbtKVSlW.js AI (source-diff): ESM counterpart of same bundled source file; same false positive. ai
source-diff net-exec-file:dist/source-ChLNXW9d.cjs AI (source-diff): Bundled build output with standard rolldown runtime helpers and error-stack-parser; not malicious. ai
source-diff net-exec-file:dist/source-BEL1nkP1.cjs AI (source-diff): Bundled CJS output from tsdown; CJS interop shims trigger net-exec heuristic falsely. ai
source-diff obfuscated-file:dist/core-CmL25iLV.d.ts AI (source-diff): Long TypeScript declaration lines, not obfuscation; standard .d.ts output. ai
source-diff net-exec-file:dist/source.iife.js AI (source-diff): IIFE bundle output; minified but not obfuscated, standard build artifact. ai
source-diff net-exec-file:dist/source-XJPX_wAG.js AI (source-diff): Bundled ESM output from tsdown; rolldown runtime shims trigger net-exec heuristic falsely. ai
source-diff obfuscated-file:dist/rdt-hook-aNC2TnWN.cjs AI (source-diff): Minified build artifact for React DevTools hook; content is readable instrumentation code with MIT license header. ai
source-diff obfuscated-file:dist/core-BmxLxXeu.js AI (source-diff): Minified build artifact with content-hash filename; standard tsdown/Vite output for this package. ai
source-diff obfuscated-file:dist/core-Bl5QDLCY.cjs AI (source-diff): Minified build artifact with content-hash filename; standard tsdown/Vite output for this package. ai
source-diff obfuscated-file:dist/rdt-hook-CqZoDOZQ.cjs AI (source-diff): Minified build artifact with content-hash filename; standard tsdown/Vite output for this package. ai
source-diff obfuscated-file:dist/rdt-hook.cjs AI (source-diff): Minified build artifact for a React DevTools hook library; content is readable and benign. ai
source-diff obfuscated-file:dist/core-DcvcGWE0.cjs AI (source-diff): Minified build artifact from tsdown bundler; content is React Fiber instrumentation, no malicious patterns. ai
source-diff obfuscated-file:dist/core-DrcMh8Kr.js AI (source-diff): Minified ESM build artifact; same React Fiber logic as CJS counterpart, no malicious patterns. ai
source-diff obfuscated-file:dist/rdt-hook-DnW_XqbK.cjs AI (source-diff): Minified build artifact; content is React DevTools hook injection, consistent with package purpose. ai
source-diff obfuscated-file:dist/core-CLXCJJKo.cjs AI (source-diff): Minified build artifact from tsdown/terser build pipeline; content matches React fiber instrumentation logic. ai
source-diff obfuscated-file:dist/rdt-hook-pgzgY3Sj.cjs AI (source-diff): Minified build artifact; content is React DevTools hook injection, consistent with package purpose. ai
source-diff obfuscated-file:dist/core-BYSK76G-.js AI (source-diff): Minified ESM build artifact; same React fiber instrumentation code as other dist files. ai
source-diff obfuscated-file:dist/core-Wlj_iSSM.cjs AI (source-diff): Standard bundler minification output for this React instrumentation library; not malicious obfuscation. ai
source-diff obfuscated-file:dist/rdt-hook-C6zmKmBn.cjs AI (source-diff): Standard bundler minification output; code is readable React DevTools hook logic. ai
source-diff obfuscated-file:dist/core-_xno6DOO.js AI (source-diff): Standard bundler minification output; same pattern as other dist files in this package. ai
source-diff obfuscated-file:dist/core-Baf5H9cC.cjs AI (source-diff): Minified build artifact; content is React Fiber traversal logic consistent with package purpose. ai
source-diff obfuscated-file:dist/rdt-hook-D8cI2Hik.cjs AI (source-diff): Minified build artifact; content is React DevTools hook injection consistent with package purpose. ai
source-diff obfuscated-file:dist/core-DmUyehIK.js AI (source-diff): Minified build artifact; ESM variant of core, consistent with package purpose. ai
source-diff obfuscated-file:dist/core-xjGqMMEY.cjs AI (source-diff): Standard bundler output (tsdown/esbuild) with license header; content is React fiber instrumentation, not obfuscated malware. ai
source-diff obfuscated-file:dist/core-DBBh-FTl.js AI (source-diff): Standard bundler output (ESM variant of core); readable React fiber code with correct license header. ai
source-diff obfuscated-file:dist/core-Cjoce0EW.d.ts AI (source-diff): TypeScript declaration file with long lines; not executable code, no obfuscation risk. ai
source-diff obfuscated-file:dist/rdt-hook-DnMMBqZs.cjs AI (source-diff): Standard bundler output; content is the RDT hook instrumentation matching the package's documented purpose. ai
source-diff obfuscated-file:dist/core-BDyaN6OC.cjs AI (source-diff): Standard minified build output from tsdown/terser; readable React fiber logic with license header. ai
source-diff obfuscated-file:dist/rdt-hook-DXiQ00mj.cjs AI (source-diff): Standard minified build output; contains React DevTools hook instrumentation logic, not malicious code. ai
source-diff obfuscated-file:dist/core-D1unqHCA.js AI (source-diff): Standard minified build output; ESM variant of the same React fiber instrumentation code. ai
source-diff obfuscated-file:dist/core-D8j-0_U5.cjs AI (source-diff): Standard bundler minification output; code is readable React fiber logic with license headers. ai
source-diff obfuscated-file:dist/rdt-hook-3SlCAu5p.cjs AI (source-diff): Standard bundler minification output; code is readable React DevTools hook logic with license headers. ai
source-diff obfuscated-file:dist/core-coQbWNwP.js AI (source-diff): Standard bundler minification output; ESM variant of the same React fiber logic. ai
source-diff obfuscated-file:dist/core-U1d648PH.js AI (source-diff): Standard minified build output for bippy; ESM variant of core, no malicious patterns. ai
source-diff obfuscated-file:dist/core-Ba_4EQvc.cjs AI (source-diff): Standard minified build output for bippy; content is React Fiber instrumentation, no malicious patterns. ai
source-diff obfuscated-file:dist/rdt-hook-D2m6uUhj.cjs AI (source-diff): Standard minified build output for bippy; content is React DevTools hook instrumentation, no malicious patterns. ai
source-diff obfuscated-file:dist/core-DjjS1PyL.cjs AI (source-diff): Minified bundler output for a React instrumentation library; content matches package purpose. ai
source-diff obfuscated-file:dist/core-CoV0JPOT.js AI (source-diff): Minified ESM build artifact; content matches package purpose. ai
source-diff obfuscated-file:dist/rdt-hook-DKowStdz.cjs AI (source-diff): Minified bundler output; React DevTools hook instrumentation consistent with package purpose. ai
source-diff obfuscated-file:dist/core-C5GY88Ut.js AI (source-diff): Minified build artifact with license header; bippy ships bundled dist files by design. ai
source-diff obfuscated-file:dist/core-Cd3r2ofN.cjs AI (source-diff): Minified build artifact with license header; bippy ships bundled dist files by design. ai
source-diff obfuscated-file:dist/rdt-hook-D8wHLzT1.cjs AI (source-diff): Minified build artifact with license header; bippy ships bundled dist files by design. ai
source-diff obfuscated-file:dist/core-CDFqpM4d.cjs AI (source-diff): Standard minified build artifact for bippy; content is React Fiber instrumentation code with license header. ai
source-diff obfuscated-file:dist/core-DHfgke6q.js AI (source-diff): Standard minified ESM build artifact for bippy core module. ai
source-diff obfuscated-file:dist/rdt-hook-DMr9w9M6.cjs AI (source-diff): Standard minified build artifact; content is React DevTools hook instrumentation, no malicious patterns. ai
source-diff obfuscated-file:dist/rdt-hook-CvGtf2Ko.cjs AI (source-diff): Minified build artifact; content is React DevTools hook injection, consistent with package purpose. ai
source-diff obfuscated-file:dist/core-okQGppJr.cjs AI (source-diff): Minified build artifact from tsdown bundler; content is legitimate React Fiber instrumentation code. ai
source-diff obfuscated-file:dist/core-BDWE7M7e.d.ts AI (source-diff): Long-line TypeScript declaration file, not executable code; false positive for obfuscation rule. ai
source-diff obfuscated-file:dist/core-vna6K12E.js AI (source-diff): Minified ESM build artifact; same legitimate React Fiber code as the CJS counterpart. ai
source-diff obfuscated-file:dist/rdt-hook-CC7xcriA.cjs AI (source-diff): Minified build artifact with license header; expected output for this React instrumentation package. ai
source-diff obfuscated-file:dist/core-BKZAzaFk.js AI (source-diff): Minified build artifact with license header; expected output for this React instrumentation package. ai
source-diff obfuscated-file:dist/core-BfMrtjuO.cjs AI (source-diff): Minified build artifact with license header; bippy ships bundled dist files by design across all versions. ai
source-diff obfuscated-file:dist/core-DA3qEQ-B.cjs AI (source-diff): Minified build artifact of React Fiber instrumentation code; consistent with bippy's documented purpose across versions. ai
source-diff obfuscated-file:dist/core-D7_ABaNC.js AI (source-diff): Minified ESM build artifact of the same React Fiber instrumentation code. ai
source-diff obfuscated-file:dist/rdt-hook-CUxWxwLu.cjs AI (source-diff): Minified build artifact; content is React DevTools hook instrumentation matching package purpose. ai
source-diff obfuscated-file:dist/rdt-hook-Bt7MAUjK.cjs AI (source-diff): Minified bundler output; content is React DevTools hook instrumentation consistent with package purpose. ai
source-diff obfuscated-file:dist/core-C9es-rtT.js AI (source-diff): Minified bundler output; ESM variant of the same React fiber instrumentation code. ai
source-diff obfuscated-file:dist/core-BQWcwPuH.cjs AI (source-diff): Minified bundler output (tsdown/esbuild); content matches React fiber instrumentation, not obfuscation. ai
source-diff obfuscated-file:dist/core-BS1Kq8uK.js AI (source-diff): Standard minified build output for bippy; content is React Fiber instrumentation code with license header. ai
source-diff obfuscated-file:dist/core-D94YBws4.cjs AI (source-diff): Standard minified build output for bippy; content is React Fiber instrumentation code with license header. ai
source-diff obfuscated-file:dist/rdt-hook-fnfpHC-R.cjs AI (source-diff): Standard minified build output for bippy; content is React DevTools hook instrumentation with license header. ai
source-diff obfuscated-file:dist/core-DUdJNG_v.cjs AI (source-diff): Minified build artifact with license header; bippy ships bundled dist files by design. ai
source-diff obfuscated-file:dist/rdt-hook-tX8aJ1Oc.cjs AI (source-diff): Minified build artifact with license header; bippy ships bundled dist files by design. ai
source-diff obfuscated-file:dist/core-CI0zcLQw.js AI (source-diff): Minified build artifact with license header; bippy ships bundled dist files by design. ai
source-diff obfuscated-file:dist/rdt-hook-BAGN3kfF.cjs AI (source-diff): Minified bundler output; content is React DevTools hook instrumentation, consistent with package purpose. ai
source-diff obfuscated-file:dist/core-BE71wdnw.js AI (source-diff): Minified bundler output; same React fiber logic as other dist files, no malicious patterns. ai
source-diff obfuscated-file:dist/core-DQUPoE6z.cjs AI (source-diff): Minified bundler output (tsdown/esbuild); content is React fiber instrumentation, not malicious. ai
source-diff obfuscated-file:dist/rdt-hook-D4Bzf_uM.cjs AI (source-diff): Standard minified build output; React DevTools hook injection is core functionality of bippy. ai
source-diff obfuscated-file:dist/core-mdTLRyEJ.js AI (source-diff): Standard minified build output for this React instrumentation library; content matches package purpose. ai
source-diff obfuscated-file:dist/core-bbMuuR0q.cjs AI (source-diff): Standard minified build output for this React instrumentation library; content matches package purpose. ai
source-diff obfuscated-file:dist/core-CS38tBgC.js AI (source-diff): Standard minified build output; same React Fiber logic as the .cjs counterpart. ai
source-diff obfuscated-file:dist/core-Jb49XNEH.cjs AI (source-diff): Standard minified build output for a React internals library; content is readable React Fiber logic with license header. ai
source-diff obfuscated-file:dist/rdt-hook-gE4odHs9.cjs AI (source-diff): Standard minified build output; content is React DevTools hook instrumentation, not malicious. ai
source-diff obfuscated-file:dist/core-BQc_XXkB.cjs AI (source-diff): Standard bundler minification output for a React instrumentation library; not obfuscation. ai
source-diff obfuscated-file:dist/core-DR6Lb084.js AI (source-diff): Standard bundler minification output; ESM variant of the same React fiber instrumentation code. ai
source-diff obfuscated-file:dist/rdt-hook-D7XiZP9p.cjs AI (source-diff): Standard bundler minification output; content is React DevTools hook logic, not malicious. ai
source-diff obfuscated-file:dist/rdt-hook-DjVWQ1ex.cjs AI (source-diff): Minified build artifact; content is React DevTools hook instrumentation, not malicious obfuscation. ai
source-diff obfuscated-file:dist/core-BGFTvyXC.cjs AI (source-diff): Minified build artifact of a React instrumentation library; content is readable React Fiber logic, not obfuscation. ai
source-diff obfuscated-file:dist/core-DeXBmn_W.js AI (source-diff): Minified build artifact; same React Fiber logic as the CJS counterpart, no malicious indicators. ai
source-diff obfuscated-file:dist/core-DDSDfsbb.js AI (source-diff): Standard minified build output; ESM variant of the same React Fiber instrumentation code. ai
source-diff obfuscated-file:dist/core-DVWLY4I2.cjs AI (source-diff): Standard minified build output from tsdown/terser; content is React Fiber instrumentation, no malicious patterns. ai
source-diff obfuscated-file:dist/rdt-hook-C7Zyojd_.cjs AI (source-diff): Standard minified build output; content is React DevTools hook instrumentation, no malicious patterns. ai
phantom-deps phantom-dep:@types/react-reconciler AI (phantom-deps): @types/react-reconciler is a type-only dep used at build time; not imported at runtime. ai
source-diff obfuscated-file:dist/rdt-hook-CIAyAMXM.cjs AI (source-diff): Minified bundler output; content is React DevTools hook instrumentation, consistent with package purpose. ai
source-diff obfuscated-file:dist/core-s90z2mSW.cjs AI (source-diff): Minified bundler output (tsdown/esbuild); content is React fiber instrumentation, not malicious. ai
source-diff obfuscated-file:dist/core-DOjBpCvr.js AI (source-diff): Minified bundler output; same React fiber logic as other dist chunks. ai

Versions (showing 100 of 131)

Version Deps Published
0.6.1 0 / 23
0.6.0 0 / 17
0.5.43 0 / 16
0.5.42 0 / 16
0.5.41 0 / 16
0.5.40 0 / 16
0.5.39 0 / 16
0.5.38 0 / 16
0.5.37 0 / 16
0.5.35 0 / 16
0.5.34 0 / 18
0.5.33 1 / 17
0.5.32 1 / 18
0.5.31 1 / 18
0.5.30 1 / 18
0.5.29 1 / 18
0.5.28 1 / 18
0.5.27 1 / 18
0.5.26 1 / 18
0.5.25 1 / 18
0.5.24 1 / 18
0.5.23 1 / 18
0.5.22 1 / 18
0.5.21 1 / 18
0.5.20 1 / 18
0.5.19 1 / 18
0.5.18 1 / 18
0.5.17 1 / 18
0.5.16 1 / 18
0.5.15 1 / 18
0.5.14 1 / 18
0.5.13 1 / 18
0.5.12 1 / 18
0.5.11 1 / 18
0.5.10 1 / 18
0.5.9 1 / 18
0.5.8 1 / 18
0.5.7 1 / 18
0.5.6 1 / 18
0.5.5 1 / 18
0.5.4 1 / 18
0.5.3 1 / 18
0.5.2 1 / 18
0.5.1 1 / 18
0.5.0 1 / 18
0.4.0 1 / 19
0.3.34 1 / 19
0.3.33 1 / 19
0.3.32 1 / 22
0.3.31 1 / 22
0.3.30 1 / 22
0.3.29 1 / 22
0.3.28 1 / 22
0.3.27 1 / 22
0.3.26 1 / 22
0.3.25 1 / 22
0.3.24 1 / 22
0.3.23 1 / 22
0.3.22 1 / 22
0.3.21 1 / 22
0.3.20 1 / 22
0.3.19 1 / 22
0.3.18 1 / 22
0.3.17 1 / 22
0.3.16 1 / 22
0.3.15 1 / 22
0.3.14 1 / 22
0.3.13 1 / 22
0.3.12 1 / 22
0.3.11 1 / 22
0.3.10 1 / 22
0.3.9 1 / 22
0.3.8 1 / 22
0.3.7 1 / 22
0.3.6 1 / 22
0.3.5 1 / 22
0.3.4 1 / 22
0.3.3 1 / 22
0.3.2 1 / 22
0.3.1 1 / 22
0.3.0 1 / 22
0.2.24 1 / 20
0.2.23 1 / 20
0.2.22 0 / 24
0.2.21 0 / 24
0.2.20 0 / 24
0.2.19 0 / 24
0.2.18 0 / 24
0.2.17 0 / 22
0.2.16 0 / 22
0.2.15 0 / 22
0.2.14 0 / 22
0.2.13 0 / 22
0.2.12 0 / 22
0.2.11 0 / 22
0.2.10 0 / 22
0.2.9 0 / 21
0.2.8 0 / 21
0.2.7 0 / 21
0.2.6 0 / 21
Showing 100 of 131 Next page →

v0.6.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: abai → GitHub Actions (on 2026-07-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (abai) on 2026-07-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.6.0

5 findings
HIGH New obfuscated file: dist/get-source.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react-refresh.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: dist/get-source.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/react-refresh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — minified bundler output, not obfuscation on its own.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.4

8 findings
HIGH New obfuscated file: dist/core-Du-sCECq.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/rdt-hook-C62IwObP.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core-SjGIw1cd.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core--XA5AwF7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.3

8 findings
HIGH New obfuscated file: dist/core-ClKFLt2T.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/rdt-hook-CSGZ9466.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core-B0h3hqBg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core--XA5AwF7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.2

8 findings
HIGH New obfuscated file: dist/core-DLqvN8F5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/rdt-hook-B9Wwh1TS.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core-DXbEy_Jg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core--XA5AwF7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.1

8 findings
HIGH New obfuscated file: dist/core-cPlOVfyn.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/rdt-hook-ByGa6hoK.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core-DJZ0crEP.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core--XA5AwF7.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/core.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

5 findings
HIGH New obfuscated file: dist/index-lite-D5nI1ci5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src-BPHAAijb.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src-C-CLm2l3.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-Qs1rAFd9.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.34

3 findings
HIGH New file with network + code execution: dist/source-BAPwFAwe.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-D2grjLFe.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.33

3 findings
HIGH New file with network + code execution: dist/source-ilDotInf.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-DQCmZhBV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.31

3 findings
HIGH New file with network + code execution: dist/source-Bu6NKhnI.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-DWOhEbf2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.30

3 findings
HIGH New file with network + code execution: dist/source-Cq1_jzmd.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-C_40r4dr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.29

3 findings
HIGH New file with network + code execution: dist/source-D27ZXa0o.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-7rH6oRiA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.28

3 findings
HIGH New file with network + code execution: dist/source-CD5HO-_u.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-BfkxIx1q.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.27

3 findings
HIGH New file with network + code execution: dist/source-B7n25ucM.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-BsqRDfoP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.25

3 findings
HIGH New file with network + code execution: dist/source-B2Lz42Ab.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-DDEKmBrT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.24

3 findings
HIGH New file with network + code execution: dist/source-CSdAtQJ_.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-LNQQC0ZJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.23

3 findings
HIGH New file with network + code execution: dist/source-CgGjiK9R.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-DjV3BlJf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.22

3 findings
HIGH New file with network + code execution: dist/source-CpnylWPF.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-DNoVJul7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.21

3 findings
HIGH New file with network + code execution: dist/source-A3voVUIp.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-CvcvVqiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.20

3 findings
HIGH New file with network + code execution: dist/source-WLoJP0PF.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-AAPM9BO7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.19

3 findings
HIGH New file with network + code execution: dist/source-umpQJuDB.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-DjN4dTb0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.18

3 findings
HIGH New file with network + code execution: dist/source-Bs3pHZxr.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-CzshDdc9.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.16

3 findings
HIGH New file with network + code execution: dist/source-CpUl2rbU.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/source-l0-0Utl0.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.