← Home

eve

40
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

rauchgvercel-release-botmatt.straka

Keywords

agent-frameworkagentsai-agentsai-sdkevalsevemcpmodel-context-protocolnextjsobservabilityreactserverlesstoolsvercelworkflow

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file-transition:dist/src/harness/compaction.js AI (source-diff): Build-tool minification of readable source; stable for this bundled package. ai
source-diff obfuscated-file:dist/src/public/nuxt/vercel-services.js AI (source-diff): Rolldown-minified build output with readable ESM identifiers; not true obfuscation. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/node/dist-BweCayKF.js AI (source-diff): Rolldown-bundled minified ESM, not obfuscation; expected build output. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/node/auth-BuQkq4Gr.js AI (source-diff): Rolldown-bundled minified ESM, not obfuscation; expected build output for this package. ai
source-diff obfuscated-file-transition:dist/src/cli/dev/tui/status-line.js AI (source-diff): Readable minified rolldown build output, not obfuscation; stable for this bundled package. ai
vendored-integrity unresolved-vendored-tree:dist/src/node_modules/.pnpm AI (vendored-integrity): pnpm-bundled third-party deps matching devDeps; routine for this build layout. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/docker-cli.js AI (source-diff): Rolldown-bundled minified dist, not obfuscation; stable build output for this package. ai
source-diff bulk-net-exec-files:dist AI (source-diff): OpenAI SDK network client bundled as dependency, not injected exfil code. ai
source-diff bulk-obfuscated-files:dist AI (source-diff): Bundled vendored deps under dist/, not true obfuscation. ai
source-diff obfuscated-file:dist/src/internal/nitro/host/extension-distribution.js AI (source-diff): Minified rolldown build output, not obfuscation. ai
source-diff obfuscated-file:dist/src/internal/nitro/host/extension-state-usage.js AI (source-diff): Minified rolldown build output, not obfuscation. ai
source-diff obfuscated-file:dist/src/internal/nitro/host/dev-workspace-extensions.js AI (source-diff): Minified rolldown build output, not obfuscation; stable for this build pipeline. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/dist-BYo8Gno2.js AI (source-diff): Minified workflow SDK bundle; benign build output. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/dist-CSfKNxQW.js AI (source-diff): Network+exec co-occurrence is bundled SDK runtime, no hostile target. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/run-BdvQmV5a.js AI (source-diff): Minified workflow runtime bundle; benign build output. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/attribute-changes-DXbmITuI.js AI (source-diff): Minified rolldown vendor chunk, not obfuscation; stable build artifact. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/dist-CSfKNxQW.js AI (source-diff): Minified zod/vendor bundle; benign build output. ai
source-diff obfuscated-file:dist/src/compiled/env-runner/node-worker.js AI (source-diff): Minified vendored worker build output, not obfuscation. ai
source-diff obfuscated-file:dist/src/compiled/env-runner/index.js AI (source-diff): Minified vendored env-runner build output, not obfuscation. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/node/dist-CdH_Yoxt.js AI (source-diff): Minified bundler output from rolldown build, not obfuscation; stable for this build pipeline. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/dist-Blxnyb7-.js AI (source-diff): Bundled workflow/zod runtime chunk in official Vercel framework; minified build output, no hostile target. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/dist-zLevmMyU.js AI (source-diff): Bundled ai-sdk runtime chunk; minified build output, benign network+exec for agent runtime. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/dist-CQenixFf.js AI (source-diff): node:crypto + runtime dispatch in agent-framework bundle; no hostile destination. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/dist-CQenixFf.js AI (source-diff): Minified bundled zod/workflow SDK chunk; build output not obfuscation. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/run-CL3mguvM.js AI (source-diff): Minified workflow runtime chunk; bundler output. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/attribute-changes-Dmf_myUv.js AI (source-diff): Minified rolldown build chunk, not obfuscation; stable for this compiled dist. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/dist-DnBjuNAZ.js AI (source-diff): Bundled zod/workflow runtime; fetch to first-party APIs, no dropper behavior. ai
source-diff obfuscated-file:dist/src/compiler/normalize-extension.js AI (source-diff): Minified rolldown build output, not obfuscation; benign for this build pipeline. ai
source-diff obfuscated-file:dist/src/discover/extensions.js AI (source-diff): Minified rolldown build output, not obfuscation; benign for this build pipeline. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/attribute-changes-Bi5DLT8S.js AI (source-diff): node:crypto/fetch in bundled framework code; no hostile destination. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/core-CXJbIkCL.js AI (source-diff): Bundled framework code, benign network+exec APIs. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/core-CXJbIkCL.js AI (source-diff): Bundled zod/framework chunk, minified build output. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/attribute-changes-Bi5DLT8S.js AI (source-diff): Minified rolldown bundle output, not obfuscation; stable for this build pipeline. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/workflow/dist-DJU_7R9s.js AI (source-diff): Bundled workflow-SDK chunk (zod/undici); minified build output, not obfuscation. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/dist-DJU_7R9s.js AI (source-diff): Bundled runtime chunk; net+exec APIs are framework functionality, no hostile target. ai
source-diff net-exec-file:dist/src/compiled/@workflow/world-vercel/index.js AI (source-diff): Vercel world adapter bundle; net+exec inherent to first-party runtime. ai
source-diff obfuscated-file:dist/src/compiled/@workflow/world-vercel/index.js AI (source-diff): Bundled first-party world adapter; minified, not obfuscated. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js AI (source-diff): Bundled workflow runtime; net+exec are framework internals, no hostile target. ai
source-diff obfuscated-file:dist/src/compiled/@chat-adapter/slack/api.js AI (source-diff): Rolldown-bundled adapter dist; minified not obfuscated, stable for this build pipeline. ai
source-diff net-exec-file:dist/src/compiled/_chunks/node/version-DD-FX9rK.js AI (source-diff): Bundled Zod/runtime chunk; benign framework code. ai
source-diff net-exec-file:dist/src/compiled/_chunks/client/core-Bm8azZA6.js AI (source-diff): Bundled framework chunk; net+exec are legit agent-runtime APIs, no hostile target. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/client/core-Bm8azZA6.js AI (source-diff): Minified bundled zod/framework output, not obfuscation; stable for this build pipeline. ai
dependencies unvetted-dep:nitro AI (dependencies): Nitro is an established Vercel/UnJS build tool; beta pin expected. ai
source-diff net-exec-file:dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js AI (source-diff): Bundled @ai-sdk workflow chunk; benign net/exec capability. ai
source-diff obfuscated-file:dist/src/compiled/semver/index.js AI (source-diff): Vendored/compiled semver library; matches known semver source patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/docker.js AI (source-diff): Bundler-minified output; Docker sandbox backend code, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/development-prewarm.js AI (source-diff): Bundler-minified output; sandbox prewarm logic, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/development-cleanup.js AI (source-diff): Bundler-minified output; code is semantically clear sandbox lifecycle management. ai
source-diff obfuscated-file:dist/src/compiled/_chunks/node/auth-DF_ft5ea.js AI (source-diff): Bundler-minified output from rolldown build; readable semantics, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-runtime.js AI (source-diff): Bundler-minified output; microsandbox runtime binding, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-platform.js AI (source-diff): Bundler-minified output; microsandbox platform binding, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-network.js AI (source-diff): Bundler-minified output; microsandbox network binding, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-lifecycle.js AI (source-diff): Bundler-minified output; microsandbox lifecycle management, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/just-bash.js AI (source-diff): Bundler-minified output; just-bash backend implementation, no malicious patterns. ai
source-diff obfuscated-file:dist/src/execution/sandbox/bindings/just-bash-runtime.js AI (source-diff): Bundler-minified output; just-bash sandbox runtime, no malicious patterns. ai
phantom-deps phantom-dep:oxc-parser AI (phantom-deps): Used in build scripts/config, not directly imported in source; stable false positive. ai
maintainer-change maintainer-takeover AI (maintainer-change): Legitimate transfer from original eve SVG library author to Vercel org; new maintainers are vercel-release-bot and known Vercel engineers. ai
maintainer-change maintainer-removed AI (maintainer-change): dmitrybaranovskiy was original eve SVG library author; package repurposed by Vercel. ai
maintainer-change maintainer-added AI (maintainer-change): rauchg, vercel-release-bot, matt.straka are Vercel org members; legitimate ownership transfer. ai
source-diff source-size-tripled AI (source-diff): 797x size increase from 15KB to 11MB reflects bundling of compiled dependencies; expected for this major version. ai
source-diff large-new-source-files AI (source-diff): 1919 new files reflect bundled compiled deps (openai, zod, slack, etc.) in dist; expected for this framework. ai
source-diff obfuscated-file:dist/src/harness/attachment-staging.js AI (source-diff): Minified first-party harness code; consistent with compiled framework dist. ai
source-diff obfuscated-file:dist/src/node_modules/.pnpm/[email protected][email protected][email protected]/node_modules/openai/lib/AssistantStream.js AI (source-diff): Minified openai SDK bundled into dist; standard for compiled framework packages. ai
source-diff obfuscated-file:dist/src/setup/ask.js AI (source-diff): Minified first-party CLI prompt code; readable interactive question logic. ai
source-diff obfuscated-file:dist/src/compiler/artifacts.js AI (source-diff): Minified first-party compiler code; readable artifact management logic. ai
source-diff obfuscated-file:dist/src/public/channels/teams/api.js AI (source-diff): Minified first-party Teams channel API; readable MS Teams OAuth/API calls. ai
source-diff obfuscated-file:dist/src/public/channels/slack/api.js AI (source-diff): Minified first-party Slack channel API; readable Slack API calls. ai
source-diff obfuscated-file:dist/src/public/channels/github/api.js AI (source-diff): Minified first-party GitHub channel API; readable GitHub REST calls. ai
source-diff obfuscated-file:dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v4/core/api.js AI (source-diff): Minified zod v4 bundled into dist; standard dependency bundling. ai
source-diff obfuscated-file:dist/src/setup/boxes/add-channels.js AI (source-diff): Minified first-party setup code; readable logic for Slack/Vercel scaffolding. ai
source-diff obfuscated-file:dist/src/node_modules/.pnpm/[email protected][email protected][email protected]/node_modules/openai/lib/AbstractChatCompletionRunner.js AI (source-diff): Minified openai SDK bundled into dist; standard for compiled framework packages. ai
provenance missing-githead AI (provenance): GitHub Actions publish without gitHead is common; repo URL is vercel/eve. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions under Vercel org; consistent with CI/CD publishing pipeline. ai

Versions (showing 40 of 40)

Version Deps Published
0.27.0 1 / 56
0.26.2 1 / 56
0.26.1 1 / 56
0.26.0 1 / 55
0.25.3 1 / 55
0.25.2 1 / 55
0.25.0 1 / 55
0.24.5 1 / 55
0.24.3 1 / 55
0.24.2 1 / 54
0.23.0 1 / 54
0.22.6 1 / 54
0.22.5 1 / 54
0.22.3 1 / 54
0.22.2 1 / 54
0.22.0 1 / 52
0.21.1 1 / 52
0.21.0 1 / 52
0.20.0 1 / 52
0.18.2 1 / 51
0.18.1 1 / 51
0.17.1 1 / 51
0.17.0 1 / 51
0.16.1 1 / 51
0.16.0 1 / 51
0.15.5 1 / 51
0.15.3 1 / 51
0.15.1 1 / 51
0.15.0 1 / 51
0.13.3 1 / 48
0.13.1 1 / 47
0.11.5 1 / 47
0.9.2 2 / 46
0.9.1 3 / 45
0.8.4 2 / 45
0.8.3 2 / 44
0.7.3 2 / 43
0.7.2 2 / 43
0.7.0 1 / 44
0.5.4 0 / 4

v0.27.0

3 findings
HIGH New obfuscated file: dist/src/public/nuxt/vercel-services.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Modified file became obfuscated: dist/src/harness/compaction.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.26.2

3 findings
HIGH New obfuscated file: dist/src/compiled/_chunks/node/auth-BuQkq4Gr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/dist-BweCayKF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.26.1

2 findings
HIGH Modified file became obfuscated: dist/src/cli/dev/tui/status-line.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.26.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.25.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.25.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.25.0

4 findings
HIGH New obfuscated file: dist/src/internal/nitro/host/dev-workspace-extensions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/nitro/host/extension-distribution.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/nitro/host/extension-state-usage.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.5

6 findings
HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-DXbmITuI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-BYo8Gno2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-CSfKNxQW.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-CSfKNxQW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/run-BdvQmV5a.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.3

11 findings
HIGH New obfuscated file: dist/src/compiled/_chunks/node/auth-BuQkq4Gr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/nitro/host/dev-authored-rebuild-coordinator.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/workflow/development-world-client.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/workflow/development-world-server.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/dist-CdH_Yoxt.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/nitro/host/drained-nitro-dev-server.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/env-runner/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/env-runner/node-worker.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/retry-DngYleaI.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/token-util-BoSJPKrG.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.2

11 findings
HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-MGTOG_uX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/authored-package-boundary.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-Blxnyb7-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-Blxnyb7-.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-zLevmMyU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-zLevmMyU.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/internal/materialize-authored-external-dependencies.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/materialized-authored-modules.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/internal/application/output-publication-lock.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/run-D8hv1ptT.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.23.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.6

5 findings
HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-Dmf_myUv.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-CQenixFf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-CQenixFf.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/run-CL3mguvM.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.5

9 findings
HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-ubiPfqvY.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/public/models/openai/chatgpt/auth.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-DnBjuNAZ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-DnBjuNAZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/cli/commands/extension-init.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/functions-BCMO8vbf.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/run-B3N1kN9q.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/public/models/openai/chatgpt/transport.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.3

3 findings
HIGH New obfuscated file: dist/src/discover/extensions.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiler/normalize-extension.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.2

11 findings
HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-BnKD8Y3m.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-CttsoN4D.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-DJU_7R9s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-DJU_7R9s.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-DpDDcpTl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/@workflow/world-local/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/@workflow/world-vercel/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/@workflow/world-vercel/index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/run-BSANnUPR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/undici-fb54XL8i.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.21.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.21.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.0

10 findings
HIGH New obfuscated file: dist/src/compiled/@chat-adapter/slack/api.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/auth-CWHn3Yve.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/@chat-adapter/twilio/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/run-BJUPZ0Ni.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/setup/vercel-project-framework.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/version-DD-FX9rK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/node/version-DD-FX9rK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.2

18 findings
HIGH New obfuscated file: dist/src/client/agent-info-schema.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/@chat-adapter/slack/api.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/auth-CWHn3Yve.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/@chat-adapter/slack/blocks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-Dxrjttr2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-FLIfyJ4Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/dist-W8yle6rh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/locales/en.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/external.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/functions-CnVBREsg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v0.18.1

18 findings
HIGH New obfuscated file: dist/src/client/agent-info-schema.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/@chat-adapter/slack/api.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/auth-CWHn3Yve.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/@chat-adapter/slack/blocks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-Dxrjttr2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-FLIfyJ4Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/dist-W8yle6rh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/locales/en.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/external.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/functions-CnVBREsg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v0.17.1

16 findings
HIGH New obfuscated file: dist/src/client/agent-info-schema.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/@chat-adapter/slack/blocks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-Dxrjttr2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-FLIfyJ4Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/dist-W8yle6rh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/locales/en.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/external.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/functions-CnVBREsg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v0.17.0

17 findings
HIGH New obfuscated file: dist/src/client/agent-info-schema.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/attribute-changes-DUxG-Gic.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/attribute-changes-DUxG-Gic.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/@chat-adapter/slack/blocks.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/client/core-Bm8azZA6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-Dxrjttr2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/dist-FLIfyJ4Y.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/node/dist-W8yle6rh.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/locales/en.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v3/external.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/compiled/_chunks/workflow/functions-CnVBREsg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/src/cli/commands/init-repl.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.