drizzle-kit
Drizzle Kit is a CLI migrator tool for Drizzle ORM. It is probably the one and only tool that lets you completely automatically generate SQL migrations and covers ~95% of the common cases like deletions and renames by prompting user input. <https://github
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:drizzle-orm | AI (phantom-deps): Optional peer used by the ORM tooling; stable FP. | ai | |
| install-scripts | install-script:preinstall | AI (install-scripts): Preinstall is only-allow pnpm guard; no code fetch/exec. | ai | |
| phantom-deps | phantom-dep:ink | AI (phantom-deps): UI framework dependency for CLI; referenced in config files as documented. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): React peer dependency for ink-based UI; stable pattern for this package. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard SASL/SCRAM auth decoding in bundled pg driver, not payload hiding. | ai | |
| phantom-deps | phantom-dep:use-immer | AI (phantom-deps): Used via config/CLI wiring, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:immer | AI (phantom-deps): Used via config/CLI wiring, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:uuid | AI (phantom-deps): Used via config/CLI wiring, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ink-router | AI (phantom-deps): Used via config/CLI wiring, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ink-text-input | AI (phantom-deps): Used via config/CLI wiring, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:immer-reducer | AI (phantom-deps): Used via config/CLI wiring, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ink-divider | AI (phantom-deps): Used via config/CLI wiring, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/uuid | AI (phantom-deps): Type package, expected pattern. | ai | |
| phantom-deps | phantom-dep:pg | AI (phantom-deps): Driver loaded dynamically by config, longstanding pattern. | ai | |
| semgrep | semgrep:env-bulk-read | AI (semgrep): Debug library env filtering, not credential exfil. | ai | |
| phantom-deps | phantom-dep:xstate | AI (phantom-deps): CLI tool with dynamic config-based dependency loading; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:enquirer | AI (phantom-deps): Interactive CLI dependency; expected for this package. | ai | |
| phantom-deps | phantom-dep:js-yaml | AI (phantom-deps): Config parsing dependency; expected for CLI tool. | ai | |
| phantom-deps | phantom-dep:source-map-support | AI (phantom-deps): Build tool dependency; expected for this package. | ai | |
| phantom-deps | phantom-dep:pretty-error | AI (phantom-deps): Error formatting utility; expected for this package. | ai | |
| phantom-deps | phantom-dep:loading-cli | AI (phantom-deps): CLI progress indicator; expected for this package. | ai | |
| phantom-deps | phantom-dep:cli-table | AI (phantom-deps): CLI output formatting; expected for this package. | ai | |
| phantom-deps | phantom-dep:npm | AI (phantom-deps): Long-standing declared dep used via CLI tooling, stable false positive. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() executes locally-compiled esbuild output within the build pipeline, not remote/untrusted input. | ai | |
| semgrep | semgrep:child-process-spawn | AI (semgrep): Part of bundled commander CLI arg-parsing, standard pattern. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): Bundled commander library code, not package's own logic. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): jsonc-comment-stripping parser utility, not exec of untrusted input. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Used via config/schema validation, standard phantom-dep FP. | ai | |
| phantom-deps | phantom-dep:hanji | AI (phantom-deps): CLI rendering helper referenced indirectly; known FP pattern. | ai | |
| phantom-deps | phantom-dep:json-diff | AI (phantom-deps): Used for diffing, phantom-dep FP. | ai | |
| dependencies | unvetted-dep:immer-reducer | AI (dependencies): Legitimate immer helper lib, long-standing dependency. | ai | |
| dependencies | unvetted-dep:@lambda-team/ltdl | AI (dependencies): Publisher's own org package, consistent with repo ownership. | ai | |
| phantom-deps | phantom-dep:toml | AI (phantom-deps): Config-loaded dep, expected false positive for CLI tool. | ai | |
| dependencies | unvetted-dep:ink-router | AI (dependencies): Legitimate ink TUI routing lib used by drizzle-kit's CLI. | ai | |
| dependencies | unvetted-dep:hanji | AI (dependencies): hanji is drizzle-team's own small CLI prompt lib, long-standing dependency. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads user schema files, core to drizzle-kit's introspection functionality. | ai | |
| source-diff | obfuscated-file:api.mjs | AI (source-diff): esbuild ESM bundle output, minified not obfuscated | ai | |
| source-diff | net-exec-file:api.js | AI (source-diff): esbuild-bundled CLI; net+exec are normal build-tool primitives | ai | |
| source-diff | obfuscated-file:api.js | AI (source-diff): esbuild bundle output for new ./api export, not obfuscation | ai | |
| provenance | missing-githead | AI (provenance): explained by move to CI/CD SLSA-attested publish | ai | |
| source-diff | net-exec-file:api.mjs | AI (source-diff): esbuild-bundled CLI; dual-use build primitives | ai | |
| phantom-deps | phantom-dep:hono | AI (phantom-deps): Used internally by CLI bundle, not directly imported at top level. | ai | |
| phantom-deps | phantom-dep:@hono/zod-validator | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:@hono/node-server | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:superjson | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:minimatch | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:env-paths | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:camelcase | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:chalk | AI (phantom-deps): Bundled CLI dep, false positive pattern. | ai | |
| phantom-deps | phantom-dep:@esbuild-kit/esm-loader | AI (phantom-deps): @esbuild-kit/esm-loader is a legitimate build/loader dependency; phantom-dep is expected for build infrastructure. | ai | |
| phantom-deps | phantom-dep:@drizzle-team/brocli | AI (phantom-deps): @drizzle-team/brocli is a legitimate CLI utility dependency; phantom-dep is expected for CLI tools. | ai | |
| phantom-deps | phantom-dep:esbuild-register | AI (phantom-deps): esbuild-register is a legitimate build/config dependency; phantom-dep is expected for build infrastructure. | ai | |
| phantom-deps | phantom-dep:esbuild | AI (phantom-deps): esbuild is a legitimate build dependency used in the build process; phantom-dep is expected for build tools. | ai | |
| dependencies | unvetted-dep:@esbuild-kit/esm-loader | AI (dependencies): Well-known ESM loader utility; standard tooling dependency for drizzle-kit's build/runtime pipeline. | ai | |
| dependencies | unvetted-dep:@drizzle-team/brocli | AI (dependencies): First-party dependency from the drizzle-team namespace; stable CLI utility used across drizzle-kit versions. | ai |
Versions (showing 51 of 174)
| Version | Deps | Published |
|---|---|---|
| 0.31.10 | 4 / 65 | |
| 0.31.9 | 4 / 66 | |
| 0.31.8 | 4 / 66 | |
| 0.31.7 | 4 / 66 | |
| 0.31.6 | 4 / 66 | |
| 0.31.5 | 4 / 66 | |
| 0.31.4 | 4 / 66 | |
| 0.31.3 | 4 / 66 | |
| 0.31.2 | 4 / 66 | |
| 0.31.1 | 4 / 67 | |
| 0.31.0 | 4 / 67 | |
| 0.30.6 | 5 / 66 | |
| 0.30.5 | 5 / 66 | |
| 0.30.4 | 4 / 66 | |
| 0.30.3 | 4 / 66 | |
| 0.30.2 | 4 / 66 | |
| 0.30.1 | 4 / 66 | |
| 0.30.0 | 4 / 66 | |
| 0.29.1 | 4 / 66 | |
| 0.29.0 | 4 / 66 | |
| 0.28.1 | 4 / 66 | |
| 0.28.0 | 4 / 66 | |
| 0.27.2 | 4 / 63 | |
| 0.27.1 | 4 / 63 | |
| 0.27.0 | 4 / 63 | |
| 0.26.2 | 4 / 63 | |
| 0.26.1 | 4 / 63 | |
| 0.26.0 | 4 / 63 | |
| 0.25.0 | 4 / 63 | |
| 0.24.2 | 4 / 62 | |
| 0.24.1 | 4 / 62 | |
| 0.24.0 | 4 / 62 | |
| 0.23.2 | 4 / 62 | |
| 0.23.1 | 4 / 62 | |
| 0.23.0 | 3 / 62 | |
| 0.22.8 | 3 / 62 | |
| 0.22.7 | 3 / 62 | |
| 0.22.6 | 3 / 62 | |
| 0.22.5 | 3 / 62 | |
| 0.22.4 | 3 / 62 | |
| 0.22.3 | 3 / 62 | |
| 0.22.2 | 3 / 62 | |
| 0.22.1 | 3 / 62 | |
| 0.22.0 | 3 / 62 | |
| 0.21.4 | 9 / 56 | |
| 0.21.3 | 9 / 56 | |
| 0.21.2 | 9 / 55 | |
| 0.21.1 | 9 / 55 | |
| 0.21.0 | 9 / 55 | |
| 0.20.18 | 17 / 31 | |
| 0.20.17 | 17 / 31 |
v0.31.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.6
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.5
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.4
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.3
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.2
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.1
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.29.1
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.29.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.28.1
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.28.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.2
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.1
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.27.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.2
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.1
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.25.0
4 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.2
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.1
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.2
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: dankochetov.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.21.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.21.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.21.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.21.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.