← Home

connected-react-router

21
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

supasate

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file-transition:umd/ConnectedReactRouter.js AI (source-diff): Webpack UMD build artifact, not obfuscation; minified dist is expected for this file. ai
semgrep semgrep:new-function-constructor AI (semgrep): The new Function() usage is in a webpack-generated UMD bundle wrapper — standard UMD boilerplate, not dynamic code execution of user input. Stable false positive for this package. ai
dependencies unvetted-dep:lodash.isequalwith AI (dependencies): lodash.isequalwith is a well-known lodash modular package; its use here for deep equality comparison is legitimate and expected. ai
dependencies unvetted-dep:redux-seamless-immutable AI (dependencies): redux-seamless-immutable is an intentional runtime dependency supporting optional immutable state integration; its inclusion is consistent with the library's documented feature set across all versions. ai
phantom-deps phantom-dep:redux-seamless-immutable AI (phantom-deps): Declared but not directly imported because it's an optional integration dependency; this pattern is stable for this package across versions. ai
provenance no-provenance AI (provenance): Package predates Sigstore provenance; no provenance is expected for this established project and is not a security concern. ai

Versions (showing 21 of 21)

Version Deps Published
6.9.3 4 / 38
6.9.2 4 / 38
6.9.1 4 / 38
6.9.0 3 / 39
6.8.0 1 / 38
6.7.0 1 / 38
6.6.1 3 / 35
6.6.0 3 / 35
6.5.2 3 / 35
6.5.1 3 / 35
6.5.0 3 / 35
6.4.0 3 / 35
6.3.2 2 / 36
6.3.1 2 / 35
6.3.0 2 / 35
6.2.2 2 / 34
6.2.1 2 / 33
6.2.0 2 / 33
6.1.0 2 / 33
6.0.0 2 / 33
4.5.0 3 / 33

v6.9.2

2 findings
HIGH Modified file became obfuscated: umd/ConnectedReactRouter.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.1

2 findings
HIGH Modified file became obfuscated: umd/ConnectedReactRouter.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.9.0

2 findings
HIGH Modified file became obfuscated: umd/ConnectedReactRouter.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.8.0

2 findings
HIGH Modified file became obfuscated: umd/ConnectedReactRouter.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.7.0

2 findings
HIGH Modified file became obfuscated: umd/ConnectedReactRouter.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.1

2 findings
HIGH Modified file became obfuscated: umd/ConnectedReactRouter.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.6.0

2 findings
HIGH Modified file became obfuscated: umd/ConnectedReactRouter.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v6.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.