← Home

homebridge-config-ui-x

22
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

oznunorthernmansuperegkhaostebaauwdustin.greifnfarinabwp91

Keywords

homebridge-pluginuiguiwebhomebridgehomebridge-config-ui-xui-xconfig-ui-xhomebridge-xhomebridge serverhomebridge uihomebridge-uihomebridge guihomebridge-guiweb interfaceconfig uimanagementconfig editorlinuxmacOSosxwindowsraspberry piaccessory controlsmart homehb-service

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:public/chunk-FS6FBYD6.js AI (source-diff): Bundled frontend build output (Angular/socket.io chunk), not injected loader code. ai
source-diff net-exec-file:public/chunk-NXTHTMCE.js AI (source-diff): engine.io-client bundle chunk; standard websocket library code, not malicious. ai
source-diff net-exec-file:public/chunk-GXCQWWJO.js AI (source-diff): engine.io/socket.io bundled client code; network+eval pattern is standard websocket polyfill, not a loader. ai
source-diff net-exec-file:public/chunk-JNYHRDBP.js AI (source-diff): engine.io/socket.io client bundle code, standard build output. ai
source-diff net-exec-file:public/chunk-47PBSPJW.js AI (source-diff): Bundled Angular/websocket UI chunk, not injected malware. ai
source-diff net-exec-file:public/chunk-PTQK2ZFT.js AI (source-diff): Bundled engine.io-client code, standard websocket transport, not malicious. ai
source-diff net-exec-file:public/chunk-GNDPG7KA.js AI (source-diff): Bundled frontend chunk (Angular/engine.io code), not a loader/dropper. ai
source-diff net-exec-file:public/chunk-SFNRCXRF.js AI (source-diff): Large bundled framework chunk from UI build, not obfuscated malware. ai
source-diff net-exec-file:public/chunk-24SUYQW4.js AI (source-diff): Bundled socket.io client code, not a dropper; standard UI build chunk. ai
source-diff net-exec-file:public/chunk-LRFO6QL5.js AI (source-diff): Bundled Angular/webpack frontend chunk, not injected loader malware. ai
source-diff net-exec-file:public/chunk-JN7O6C7T.js AI (source-diff): Bundled engine.io/socket.io client code, not a loader; standard UI build output. ai
source-diff net-exec-file:public/chunk-753BETXK.js AI (source-diff): Bundled engine.io-client code, not a loader/dropper; standard websocket transport. ai
source-diff net-exec-file:public/chunk-QHROK73U.js AI (source-diff): Angular/vendor bundle chunk from UI rebuild, not injected loader code. ai
source-diff net-exec-file:public/chunk-2GCZ3AMH.js AI (source-diff): Engine.io/socket client bundle code, not a dropper; standard UI rebuild artifact. ai
source-diff net-exec-file:public/chunk-F6CIEBBP.js AI (source-diff): Bundled engine.io-client transport code, not injected malware. ai
source-diff net-exec-file:public/chunk-Q5MJECPU.js AI (source-diff): Bundled Angular/socket.io UI chunk, standard build output. ai
source-diff net-exec-file:public/chunk-3SKLXSFI.js AI (source-diff): socket.io/engine.io client parser in minified Angular frontend bundle; websocket+base64, no obfuscation/exfil ai
source-diff large-new-source-files AI (source-diff): Routine UI build output with content-hashed chunk filenames. ai
source-diff net-exec-file:public/chunk-SYDJYMKC.js AI (source-diff): Bundled engine.io/socket client code, standard websocket transport. ai
source-diff net-exec-file:public/chunk-P74NOWY5.js AI (source-diff): Bundled Angular/vendor chunk, not obfuscated dropper code. ai
publish-pattern new-deps-added AI (publish-pattern): node-forge is a well-known crypto library used for cert generation. ai
source-diff net-exec-file:public/chunk-7FF5KR4E.js AI (source-diff): Bundled Angular/RxJS/socket.io frontend chunk, not a dropper; standard build output. ai
source-diff net-exec-file:public/chunk-MLPBQDF7.js AI (source-diff): engine.io/socket.io client bundle code, benign network+parsing logic. ai
source-diff net-exec-file:public/chunk-6RX3XE55.js AI (source-diff): Angular/ajv frontend bundle; network+exec pattern is standard UI framework code, not malware. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() in Angular framework bundle; standard Angular DI pattern, not obfuscation. ai
source-diff net-exec-file:public/chunk-GAHGBZ7U.js AI (source-diff): engine.io/Socket.IO client bundle; network+exec pattern is standard WebSocket client code, not malware. ai
phantom-deps phantom-dep:@fastify/static AI (phantom-deps): Fastify plugin registered via config, not direct import pattern. ai
phantom-deps phantom-dep:passport AI (phantom-deps): NestJS framework dependency used via decorators/config, not direct import. ai
semgrep semgrep:dynamic-require AI (semgrep): Used in build script to introspect plugin entry points; not runtime user-controlled input. ai
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside bundled Monaco editor (vs/loader.js); standard pattern in that well-known editor component. ai
phantom-deps phantom-dep:@nestjs/platform-socket.io AI (phantom-deps): NestJS platform adapter registered via config, not direct import. ai
phantom-deps phantom-dep:class-transformer AI (phantom-deps): NestJS serialization dependency used via decorators, not direct import. ai

Versions (showing 22 of 22)

Version Deps Published
5.27.0 40 / 26
5.25.0 40 / 26
5.24.0 40 / 25
5.23.0 41 / 26
5.22.0 41 / 26
5.21.0 41 / 26
5.20.0 41 / 26
5.19.0 41 / 26
5.18.0 41 / 26
5.17.0 41 / 26
5.16.0 41 / 23
5.15.2 41 / 23
5.15.1 41 / 23
5.15.0 41 / 23
5.14.0 40 / 22
5.13.1 40 / 22
5.13.0 40 / 22
5.12.0 40 / 22
5.11.2 40 / 22
5.11.1 40 / 22
5.11.0 40 / 22
5.10.0 40 / 22

v5.27.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.25.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.21.0

2 findings
HIGH New file with network + code execution: public/chunk-GXCQWWJO.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.20.0

4 findings
HIGH New file with network + code execution: public/chunk-FS6FBYD6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-NXTHTMCE.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-03-21, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-03-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.19.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-03-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.18.0

4 findings
HIGH New file with network + code execution: public/chunk-47PBSPJW.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-JNYHRDBP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-02-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-02-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.17.0

3 findings
HIGH New file with network + code execution: public/chunk-LRFO6QL5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-02-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-02-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.16.0

4 findings
HIGH New file with network + code execution: public/chunk-GNDPG7KA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-PTQK2ZFT.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-02-08, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-02-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.15.2

4 findings
HIGH New file with network + code execution: public/chunk-F6CIEBBP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-Q5MJECPU.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-01-31, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-31, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.15.1

4 findings
HIGH New file with network + code execution: public/chunk-24SUYQW4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-SFNRCXRF.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-01-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.15.0

4 findings
HIGH New file with network + code execution: public/chunk-7FF5KR4E.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-MLPBQDF7.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-01-17, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.14.0

3 findings
HIGH New file with network + code execution: public/chunk-753BETXK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2026-01-02, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.13.1

4 findings
HIGH New file with network + code execution: public/chunk-P74NOWY5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-SYDJYMKC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2025-12-28, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2025-12-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.13.0

3 findings
HIGH New file with network + code execution: public/chunk-JN7O6C7T.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2025-12-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2025-12-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.12.0

4 findings
HIGH New file with network + code execution: public/chunk-3SKLXSFI.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-7O4JAXGA.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: supereg → GitHub Actions (on 2025-12-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2025-12-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v5.11.2

3 findings
HIGH New file with network + code execution: public/chunk-2GCZ3AMH.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: public/chunk-QHROK73U.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.11.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.