evalite
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/ui/assets/utils-DqEQv1lI.js | AI (source-diff): Bundled React/lucide UI chunk; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/eval._name-BWrvDpgS.js | AI (source-diff): Bundled UI route chunk; minified build output. | ai | |
| source-diff | net-exec-file:dist/ui/assets/eval._name-BWrvDpgS.js | AI (source-diff): Bundled UI fetch/module preload, benign. | ai | |
| source-diff | net-exec-file:dist/ui/assets/utils-DqEQv1lI.js | AI (source-diff): Vite modulepreload fetch, not remote code exec. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-D5W1pzmu.js | AI (source-diff): Vite-bundled UI entry; minified build output, stable across releases. | ai | |
| source-diff | net-exec-file:dist/ui/assets/eval._name-DwRsoOTw.js | AI (source-diff): Standard bundled React UI chunk; net/exec are framework patterns. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/eval._name.result._resultIndex-DjuqvgED.js | AI (source-diff): Vite-bundled UI route chunk; minified React build output. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-Y_TtxmWn.js | AI (source-diff): Vite-bundled UI asset; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/utils-D6vB9JPq.js | AI (source-diff): Vite-bundled UI vendor chunk (lucide-react); minified build output. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/eval._name-DwRsoOTw.js | AI (source-diff): Vite-bundled UI route chunk; minified React build output. | ai | |
| source-diff | net-exec-file:dist/ui/assets/utils-D6vB9JPq.js | AI (source-diff): fetch is Vite modulepreload; no hostile destination in bundled UI. | ai | |
| source-diff | net-exec-file:dist/ui/assets/eval._name-v7Ndn0cL.js | AI (source-diff): Bundled UI code; network+dynamic-code are Vite bundle artifacts. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/utils-URiS0Xlg.js | AI (source-diff): Minified lucide-react/UI bundle, benign build output. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-DQAgvSjE.js | AI (source-diff): Vite bundler banner; minified React UI, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/eval._name-v7Ndn0cL.js | AI (source-diff): Minified React route bundle, benign build output. | ai | |
| source-diff | net-exec-file:dist/ui/assets/utils-URiS0Xlg.js | AI (source-diff): Bundled UI fetch (modulepreload) + React internals, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-Cw8nIL9M.js | AI (source-diff): Vite bundle banner; minified UI build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/utils-DxzOSt6Y.js | AI (source-diff): Minified Vite UI chunk (lucide-react/tinycolor), benign build output. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/eval._name-BQ_Az1St.js | AI (source-diff): Minified Vite UI route chunk, benign build output. | ai | |
| source-diff | net-exec-file:dist/ui/assets/utils-DxzOSt6Y.js | AI (source-diff): fetch is React modulepreload in bundled UI; no dynamic code exec on hostile target. | ai | |
| source-diff | net-exec-file:dist/ui/assets/eval._name-BQ_Az1St.js | AI (source-diff): Bundled UI chunk; network+exec is standard React runtime, not a loader. | ai | |
| source-diff | net-exec-file:dist/ui/assets/utils-kPEOt9l4.js | AI (source-diff): fetch()/exec patterns are Vite modulepreload shim in dashboard bundle. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/eval._name-BNHOoQ10.js | AI (source-diff): Minified Vite UI route chunk, benign build output. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/utils-kPEOt9l4.js | AI (source-diff): Minified Vite UI chunk (lucide-react etc.), benign build output. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-CnEhgUvU.js | AI (source-diff): Vite bundle banner; minified UI build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/eval._name.result._resultIndex-DXKLY6Ln.js | AI (source-diff): Minified Vite UI route chunk, benign build output. | ai | |
| source-diff | net-exec-file:dist/ui/assets/eval._name-BNHOoQ10.js | AI (source-diff): fetch()/exec patterns are Vite modulepreload shim in dashboard bundle. | ai | |
| source-diff | net-exec-file:dist/ui/assets/eval._name-rRue5V-D.js | AI (source-diff): Bundled browser UI route chunk; benign fetch, no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-CqlBtfpc.js | AI (source-diff): Vite bundler output for the UI; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/utils-CNTWwrGU.js | AI (source-diff): Bundled React/lucide UI asset; minified build output. | ai | |
| source-diff | net-exec-file:dist/ui/assets/utils-CNTWwrGU.js | AI (source-diff): fetch/modulepreload in bundled browser UI, no exfil target. | ai | |
| source-diff | net-exec-file:dist/ui/assets/utils-DocBGlU8.js | AI (source-diff): Bundled React UI with modulepreload fetch; no exfil destination. Build artifact. | ai | |
| source-diff | obfuscated-file:dist/ui/assets/index-DOP9p3Bf.js | AI (source-diff): Vite-bundled web UI output; minified not obfuscated. Stable for this package's dist assets. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 0.19.0 | 13 / 5 | |
| 0.15.0 | 11 / 5 | |
| 0.14.6 | 11 / 5 | |
| 0.14.4 | 11 / 5 | |
| 0.14.3 | 11 / 5 | |
| 0.14.2 | 11 / 5 | |
| 0.14.1 | 11 / 5 | |
| 0.14.0 | 11 / 5 | |
| 0.12.0 | 11 / 5 | |
| 0.11.6 | 10 / 5 | |
| 0.11.5 | 10 / 5 | |
| 0.11.0 | 10 / 5 |
v0.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.15.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.6
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.4
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.2
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.1
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.