eve
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file-transition:dist/src/harness/compaction.js | AI (source-diff): Build-tool minification of readable source; stable for this bundled package. | ai | |
| source-diff | obfuscated-file:dist/src/public/nuxt/vercel-services.js | AI (source-diff): Rolldown-minified build output with readable ESM identifiers; not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/node/dist-BweCayKF.js | AI (source-diff): Rolldown-bundled minified ESM, not obfuscation; expected build output. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/node/auth-BuQkq4Gr.js | AI (source-diff): Rolldown-bundled minified ESM, not obfuscation; expected build output for this package. | ai | |
| source-diff | obfuscated-file-transition:dist/src/cli/dev/tui/status-line.js | AI (source-diff): Readable minified rolldown build output, not obfuscation; stable for this bundled package. | ai | |
| vendored-integrity | unresolved-vendored-tree:dist/src/node_modules/.pnpm | AI (vendored-integrity): pnpm-bundled third-party deps matching devDeps; routine for this build layout. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/docker-cli.js | AI (source-diff): Rolldown-bundled minified dist, not obfuscation; stable build output for this package. | ai | |
| source-diff | bulk-net-exec-files:dist | AI (source-diff): OpenAI SDK network client bundled as dependency, not injected exfil code. | ai | |
| source-diff | bulk-obfuscated-files:dist | AI (source-diff): Bundled vendored deps under dist/, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/internal/nitro/host/extension-distribution.js | AI (source-diff): Minified rolldown build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/internal/nitro/host/extension-state-usage.js | AI (source-diff): Minified rolldown build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/internal/nitro/host/dev-workspace-extensions.js | AI (source-diff): Minified rolldown build output, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/dist-BYo8Gno2.js | AI (source-diff): Minified workflow SDK bundle; benign build output. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/dist-CSfKNxQW.js | AI (source-diff): Network+exec co-occurrence is bundled SDK runtime, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/run-BdvQmV5a.js | AI (source-diff): Minified workflow runtime bundle; benign build output. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/attribute-changes-DXbmITuI.js | AI (source-diff): Minified rolldown vendor chunk, not obfuscation; stable build artifact. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/dist-CSfKNxQW.js | AI (source-diff): Minified zod/vendor bundle; benign build output. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/env-runner/node-worker.js | AI (source-diff): Minified vendored worker build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/env-runner/index.js | AI (source-diff): Minified vendored env-runner build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/node/dist-CdH_Yoxt.js | AI (source-diff): Minified bundler output from rolldown build, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/dist-Blxnyb7-.js | AI (source-diff): Bundled workflow/zod runtime chunk in official Vercel framework; minified build output, no hostile target. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/dist-zLevmMyU.js | AI (source-diff): Bundled ai-sdk runtime chunk; minified build output, benign network+exec for agent runtime. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/dist-CQenixFf.js | AI (source-diff): node:crypto + runtime dispatch in agent-framework bundle; no hostile destination. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/dist-CQenixFf.js | AI (source-diff): Minified bundled zod/workflow SDK chunk; build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/run-CL3mguvM.js | AI (source-diff): Minified workflow runtime chunk; bundler output. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/attribute-changes-Dmf_myUv.js | AI (source-diff): Minified rolldown build chunk, not obfuscation; stable for this compiled dist. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/dist-DnBjuNAZ.js | AI (source-diff): Bundled zod/workflow runtime; fetch to first-party APIs, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/src/compiler/normalize-extension.js | AI (source-diff): Minified rolldown build output, not obfuscation; benign for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/src/discover/extensions.js | AI (source-diff): Minified rolldown build output, not obfuscation; benign for this build pipeline. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/attribute-changes-Bi5DLT8S.js | AI (source-diff): node:crypto/fetch in bundled framework code; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/core-CXJbIkCL.js | AI (source-diff): Bundled framework code, benign network+exec APIs. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/core-CXJbIkCL.js | AI (source-diff): Bundled zod/framework chunk, minified build output. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/attribute-changes-Bi5DLT8S.js | AI (source-diff): Minified rolldown bundle output, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/workflow/dist-DJU_7R9s.js | AI (source-diff): Bundled workflow-SDK chunk (zod/undici); minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/dist-DJU_7R9s.js | AI (source-diff): Bundled runtime chunk; net+exec APIs are framework functionality, no hostile target. | ai | |
| source-diff | net-exec-file:dist/src/compiled/@workflow/world-vercel/index.js | AI (source-diff): Vercel world adapter bundle; net+exec inherent to first-party runtime. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/@workflow/world-vercel/index.js | AI (source-diff): Bundled first-party world adapter; minified, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/attribute-changes-zAifvEhb.js | AI (source-diff): Bundled workflow runtime; net+exec are framework internals, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/@chat-adapter/slack/api.js | AI (source-diff): Rolldown-bundled adapter dist; minified not obfuscated, stable for this build pipeline. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/node/version-DD-FX9rK.js | AI (source-diff): Bundled Zod/runtime chunk; benign framework code. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/client/core-Bm8azZA6.js | AI (source-diff): Bundled framework chunk; net+exec are legit agent-runtime APIs, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/client/core-Bm8azZA6.js | AI (source-diff): Minified bundled zod/framework output, not obfuscation; stable for this build pipeline. | ai | |
| dependencies | unvetted-dep:nitro | AI (dependencies): Nitro is an established Vercel/UnJS build tool; beta pin expected. | ai | |
| source-diff | net-exec-file:dist/src/compiled/_chunks/workflow/dist-D7CzPkf8.js | AI (source-diff): Bundled @ai-sdk workflow chunk; benign net/exec capability. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/semver/index.js | AI (source-diff): Vendored/compiled semver library; matches known semver source patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/docker.js | AI (source-diff): Bundler-minified output; Docker sandbox backend code, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/development-prewarm.js | AI (source-diff): Bundler-minified output; sandbox prewarm logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/development-cleanup.js | AI (source-diff): Bundler-minified output; code is semantically clear sandbox lifecycle management. | ai | |
| source-diff | obfuscated-file:dist/src/compiled/_chunks/node/auth-DF_ft5ea.js | AI (source-diff): Bundler-minified output from rolldown build; readable semantics, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-runtime.js | AI (source-diff): Bundler-minified output; microsandbox runtime binding, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-platform.js | AI (source-diff): Bundler-minified output; microsandbox platform binding, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-network.js | AI (source-diff): Bundler-minified output; microsandbox network binding, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/microsandbox-lifecycle.js | AI (source-diff): Bundler-minified output; microsandbox lifecycle management, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/just-bash.js | AI (source-diff): Bundler-minified output; just-bash backend implementation, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/src/execution/sandbox/bindings/just-bash-runtime.js | AI (source-diff): Bundler-minified output; just-bash sandbox runtime, no malicious patterns. | ai | |
| phantom-deps | phantom-dep:oxc-parser | AI (phantom-deps): Used in build scripts/config, not directly imported in source; stable false positive. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): Legitimate transfer from original eve SVG library author to Vercel org; new maintainers are vercel-release-bot and known Vercel engineers. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): dmitrybaranovskiy was original eve SVG library author; package repurposed by Vercel. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): rauchg, vercel-release-bot, matt.straka are Vercel org members; legitimate ownership transfer. | ai | |
| source-diff | source-size-tripled | AI (source-diff): 797x size increase from 15KB to 11MB reflects bundling of compiled dependencies; expected for this major version. | ai | |
| source-diff | large-new-source-files | AI (source-diff): 1919 new files reflect bundled compiled deps (openai, zod, slack, etc.) in dist; expected for this framework. | ai | |
| source-diff | obfuscated-file:dist/src/harness/attachment-staging.js | AI (source-diff): Minified first-party harness code; consistent with compiled framework dist. | ai | |
| source-diff | obfuscated-file:dist/src/node_modules/.pnpm/[email protected][email protected][email protected]/node_modules/openai/lib/AssistantStream.js | AI (source-diff): Minified openai SDK bundled into dist; standard for compiled framework packages. | ai | |
| source-diff | obfuscated-file:dist/src/setup/ask.js | AI (source-diff): Minified first-party CLI prompt code; readable interactive question logic. | ai | |
| source-diff | obfuscated-file:dist/src/compiler/artifacts.js | AI (source-diff): Minified first-party compiler code; readable artifact management logic. | ai | |
| source-diff | obfuscated-file:dist/src/public/channels/teams/api.js | AI (source-diff): Minified first-party Teams channel API; readable MS Teams OAuth/API calls. | ai | |
| source-diff | obfuscated-file:dist/src/public/channels/slack/api.js | AI (source-diff): Minified first-party Slack channel API; readable Slack API calls. | ai | |
| source-diff | obfuscated-file:dist/src/public/channels/github/api.js | AI (source-diff): Minified first-party GitHub channel API; readable GitHub REST calls. | ai | |
| source-diff | obfuscated-file:dist/src/node_modules/.pnpm/[email protected]/node_modules/zod/v4/core/api.js | AI (source-diff): Minified zod v4 bundled into dist; standard dependency bundling. | ai | |
| source-diff | obfuscated-file:dist/src/setup/boxes/add-channels.js | AI (source-diff): Minified first-party setup code; readable logic for Slack/Vercel scaffolding. | ai | |
| source-diff | obfuscated-file:dist/src/node_modules/.pnpm/[email protected][email protected][email protected]/node_modules/openai/lib/AbstractChatCompletionRunner.js | AI (source-diff): Minified openai SDK bundled into dist; standard for compiled framework packages. | ai | |
| provenance | missing-githead | AI (provenance): GitHub Actions publish without gitHead is common; repo URL is vercel/eve. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to GitHub Actions under Vercel org; consistent with CI/CD publishing pipeline. | ai |
Versions (showing 40 of 40)
| Version | Deps | Published |
|---|---|---|
| 0.27.0 | 1 / 56 | |
| 0.26.2 | 1 / 56 | |
| 0.26.1 | 1 / 56 | |
| 0.26.0 | 1 / 55 | |
| 0.25.3 | 1 / 55 | |
| 0.25.2 | 1 / 55 | |
| 0.25.0 | 1 / 55 | |
| 0.24.5 | 1 / 55 | |
| 0.24.3 | 1 / 55 | |
| 0.24.2 | 1 / 54 | |
| 0.23.0 | 1 / 54 | |
| 0.22.6 | 1 / 54 | |
| 0.22.5 | 1 / 54 | |
| 0.22.3 | 1 / 54 | |
| 0.22.2 | 1 / 54 | |
| 0.22.0 | 1 / 52 | |
| 0.21.1 | 1 / 52 | |
| 0.21.0 | 1 / 52 | |
| 0.20.0 | 1 / 52 | |
| 0.18.2 | 1 / 51 | |
| 0.18.1 | 1 / 51 | |
| 0.17.1 | 1 / 51 | |
| 0.17.0 | 1 / 51 | |
| 0.16.1 | 1 / 51 | |
| 0.16.0 | 1 / 51 | |
| 0.15.5 | 1 / 51 | |
| 0.15.3 | 1 / 51 | |
| 0.15.1 | 1 / 51 | |
| 0.15.0 | 1 / 51 | |
| 0.13.3 | 1 / 48 | |
| 0.13.1 | 1 / 47 | |
| 0.11.5 | 1 / 47 | |
| 0.9.2 | 2 / 46 | |
| 0.9.1 | 3 / 45 | |
| 0.8.4 | 2 / 45 | |
| 0.8.3 | 2 / 44 | |
| 0.7.3 | 2 / 43 | |
| 0.7.2 | 2 / 43 | |
| 0.7.0 | 1 / 44 | |
| 0.5.4 | 0 / 4 |
v0.27.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.1
2 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.25.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.25.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.25.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.5
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.3
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.2
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.23.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.6
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.5
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.2
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.21.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.21.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.20.0
10 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.18.2
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v0.18.1
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v0.17.1
16 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v0.17.0
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.