← Home

evalite

12
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mpocock

Keywords

aievalstypescriptvitest

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/ui/assets/utils-DqEQv1lI.js AI (source-diff): Bundled React/lucide UI chunk; minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/eval._name-BWrvDpgS.js AI (source-diff): Bundled UI route chunk; minified build output. ai
source-diff net-exec-file:dist/ui/assets/eval._name-BWrvDpgS.js AI (source-diff): Bundled UI fetch/module preload, benign. ai
source-diff net-exec-file:dist/ui/assets/utils-DqEQv1lI.js AI (source-diff): Vite modulepreload fetch, not remote code exec. ai
source-diff obfuscated-file:dist/ui/assets/index-D5W1pzmu.js AI (source-diff): Vite-bundled UI entry; minified build output, stable across releases. ai
source-diff net-exec-file:dist/ui/assets/eval._name-DwRsoOTw.js AI (source-diff): Standard bundled React UI chunk; net/exec are framework patterns. ai
source-diff obfuscated-file:dist/ui/assets/eval._name.result._resultIndex-DjuqvgED.js AI (source-diff): Vite-bundled UI route chunk; minified React build output. ai
source-diff obfuscated-file:dist/ui/assets/index-Y_TtxmWn.js AI (source-diff): Vite-bundled UI asset; minified build output, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/utils-D6vB9JPq.js AI (source-diff): Vite-bundled UI vendor chunk (lucide-react); minified build output. ai
source-diff obfuscated-file:dist/ui/assets/eval._name-DwRsoOTw.js AI (source-diff): Vite-bundled UI route chunk; minified React build output. ai
source-diff net-exec-file:dist/ui/assets/utils-D6vB9JPq.js AI (source-diff): fetch is Vite modulepreload; no hostile destination in bundled UI. ai
source-diff net-exec-file:dist/ui/assets/eval._name-v7Ndn0cL.js AI (source-diff): Bundled UI code; network+dynamic-code are Vite bundle artifacts. ai
source-diff obfuscated-file:dist/ui/assets/utils-URiS0Xlg.js AI (source-diff): Minified lucide-react/UI bundle, benign build output. ai
source-diff obfuscated-file:dist/ui/assets/index-DQAgvSjE.js AI (source-diff): Vite bundler banner; minified React UI, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/eval._name-v7Ndn0cL.js AI (source-diff): Minified React route bundle, benign build output. ai
source-diff net-exec-file:dist/ui/assets/utils-URiS0Xlg.js AI (source-diff): Bundled UI fetch (modulepreload) + React internals, no hostile target. ai
source-diff obfuscated-file:dist/ui/assets/index-Cw8nIL9M.js AI (source-diff): Vite bundle banner; minified UI build output, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/utils-DxzOSt6Y.js AI (source-diff): Minified Vite UI chunk (lucide-react/tinycolor), benign build output. ai
source-diff obfuscated-file:dist/ui/assets/eval._name-BQ_Az1St.js AI (source-diff): Minified Vite UI route chunk, benign build output. ai
source-diff net-exec-file:dist/ui/assets/utils-DxzOSt6Y.js AI (source-diff): fetch is React modulepreload in bundled UI; no dynamic code exec on hostile target. ai
source-diff net-exec-file:dist/ui/assets/eval._name-BQ_Az1St.js AI (source-diff): Bundled UI chunk; network+exec is standard React runtime, not a loader. ai
source-diff net-exec-file:dist/ui/assets/utils-kPEOt9l4.js AI (source-diff): fetch()/exec patterns are Vite modulepreload shim in dashboard bundle. ai
source-diff obfuscated-file:dist/ui/assets/eval._name-BNHOoQ10.js AI (source-diff): Minified Vite UI route chunk, benign build output. ai
source-diff obfuscated-file:dist/ui/assets/utils-kPEOt9l4.js AI (source-diff): Minified Vite UI chunk (lucide-react etc.), benign build output. ai
source-diff obfuscated-file:dist/ui/assets/index-CnEhgUvU.js AI (source-diff): Vite bundle banner; minified UI build output, not obfuscation. ai
source-diff obfuscated-file:dist/ui/assets/eval._name.result._resultIndex-DXKLY6Ln.js AI (source-diff): Minified Vite UI route chunk, benign build output. ai
source-diff net-exec-file:dist/ui/assets/eval._name-BNHOoQ10.js AI (source-diff): fetch()/exec patterns are Vite modulepreload shim in dashboard bundle. ai
source-diff net-exec-file:dist/ui/assets/eval._name-rRue5V-D.js AI (source-diff): Bundled browser UI route chunk; benign fetch, no hostile destination. ai
source-diff obfuscated-file:dist/ui/assets/index-CqlBtfpc.js AI (source-diff): Vite bundler output for the UI; minified not obfuscated. ai
source-diff obfuscated-file:dist/ui/assets/utils-CNTWwrGU.js AI (source-diff): Bundled React/lucide UI asset; minified build output. ai
source-diff net-exec-file:dist/ui/assets/utils-CNTWwrGU.js AI (source-diff): fetch/modulepreload in bundled browser UI, no exfil target. ai
source-diff net-exec-file:dist/ui/assets/utils-DocBGlU8.js AI (source-diff): Bundled React UI with modulepreload fetch; no exfil destination. Build artifact. ai
source-diff obfuscated-file:dist/ui/assets/index-DOP9p3Bf.js AI (source-diff): Vite-bundled web UI output; minified not obfuscated. Stable for this package's dist assets. ai

Versions (showing 12 of 12)

Version Deps Published
0.19.0 13 / 5
0.15.0 11 / 5
0.14.6 11 / 5
0.14.4 11 / 5
0.14.3 11 / 5
0.14.2 11 / 5
0.14.1 11 / 5
0.14.0 11 / 5
0.12.0 11 / 5
0.11.6 10 / 5
0.11.5 10 / 5
0.11.0 10 / 5

v0.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.15.0

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-rRue5V-D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-rRue5V-D.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-TsnFgeUk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-CqlBtfpc.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-CNTWwrGU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-CNTWwrGU.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.6

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-v7Ndn0cL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-v7Ndn0cL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-BbjazH8g.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DQAgvSjE.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-URiS0Xlg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-URiS0Xlg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.4

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-BWrvDpgS.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-BWrvDpgS.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-FZbEOGph.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-D5W1pzmu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-DqEQv1lI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-DqEQv1lI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.3

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-BQ_Az1St.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-BQ_Az1St.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-Cp-bZzeo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-Cw8nIL9M.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-DxzOSt6Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-DxzOSt6Y.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.2

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-DwRsoOTw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-DwRsoOTw.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-DjuqvgED.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-Y_TtxmWn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-D6vB9JPq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-D6vB9JPq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.1

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-DwRsoOTw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-DwRsoOTw.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-DjuqvgED.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-Y_TtxmWn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-D6vB9JPq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-D6vB9JPq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.0

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-BNHOoQ10.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-BNHOoQ10.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-DXKLY6Ln.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-CnEhgUvU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-kPEOt9l4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-kPEOt9l4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.0

7 findings
HIGH New obfuscated file: dist/ui/assets/eval._name-CVu5ihPs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/eval._name-CVu5ihPs.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/ui/assets/eval._name.result._resultIndex-HVrAsq0D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ui/assets/index-DOP9p3Bf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (vite) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: dist/ui/assets/utils-DocBGlU8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ui/assets/utils-DocBGlU8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.11.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.