homebridge-config-ui-x
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:public/chunk-FS6FBYD6.js | AI (source-diff): Bundled frontend build output (Angular/socket.io chunk), not injected loader code. | ai | |
| source-diff | net-exec-file:public/chunk-NXTHTMCE.js | AI (source-diff): engine.io-client bundle chunk; standard websocket library code, not malicious. | ai | |
| source-diff | net-exec-file:public/chunk-GXCQWWJO.js | AI (source-diff): engine.io/socket.io bundled client code; network+eval pattern is standard websocket polyfill, not a loader. | ai | |
| source-diff | net-exec-file:public/chunk-JNYHRDBP.js | AI (source-diff): engine.io/socket.io client bundle code, standard build output. | ai | |
| source-diff | net-exec-file:public/chunk-47PBSPJW.js | AI (source-diff): Bundled Angular/websocket UI chunk, not injected malware. | ai | |
| source-diff | net-exec-file:public/chunk-PTQK2ZFT.js | AI (source-diff): Bundled engine.io-client code, standard websocket transport, not malicious. | ai | |
| source-diff | net-exec-file:public/chunk-GNDPG7KA.js | AI (source-diff): Bundled frontend chunk (Angular/engine.io code), not a loader/dropper. | ai | |
| source-diff | net-exec-file:public/chunk-SFNRCXRF.js | AI (source-diff): Large bundled framework chunk from UI build, not obfuscated malware. | ai | |
| source-diff | net-exec-file:public/chunk-24SUYQW4.js | AI (source-diff): Bundled socket.io client code, not a dropper; standard UI build chunk. | ai | |
| source-diff | net-exec-file:public/chunk-LRFO6QL5.js | AI (source-diff): Bundled Angular/webpack frontend chunk, not injected loader malware. | ai | |
| source-diff | net-exec-file:public/chunk-JN7O6C7T.js | AI (source-diff): Bundled engine.io/socket.io client code, not a loader; standard UI build output. | ai | |
| source-diff | net-exec-file:public/chunk-753BETXK.js | AI (source-diff): Bundled engine.io-client code, not a loader/dropper; standard websocket transport. | ai | |
| source-diff | net-exec-file:public/chunk-QHROK73U.js | AI (source-diff): Angular/vendor bundle chunk from UI rebuild, not injected loader code. | ai | |
| source-diff | net-exec-file:public/chunk-2GCZ3AMH.js | AI (source-diff): Engine.io/socket client bundle code, not a dropper; standard UI rebuild artifact. | ai | |
| source-diff | net-exec-file:public/chunk-F6CIEBBP.js | AI (source-diff): Bundled engine.io-client transport code, not injected malware. | ai | |
| source-diff | net-exec-file:public/chunk-Q5MJECPU.js | AI (source-diff): Bundled Angular/socket.io UI chunk, standard build output. | ai | |
| source-diff | net-exec-file:public/chunk-3SKLXSFI.js | AI (source-diff): socket.io/engine.io client parser in minified Angular frontend bundle; websocket+base64, no obfuscation/exfil | ai | |
| source-diff | large-new-source-files | AI (source-diff): Routine UI build output with content-hashed chunk filenames. | ai | |
| source-diff | net-exec-file:public/chunk-SYDJYMKC.js | AI (source-diff): Bundled engine.io/socket client code, standard websocket transport. | ai | |
| source-diff | net-exec-file:public/chunk-P74NOWY5.js | AI (source-diff): Bundled Angular/vendor chunk, not obfuscated dropper code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): node-forge is a well-known crypto library used for cert generation. | ai | |
| source-diff | net-exec-file:public/chunk-7FF5KR4E.js | AI (source-diff): Bundled Angular/RxJS/socket.io frontend chunk, not a dropper; standard build output. | ai | |
| source-diff | net-exec-file:public/chunk-MLPBQDF7.js | AI (source-diff): engine.io/socket.io client bundle code, benign network+parsing logic. | ai | |
| source-diff | net-exec-file:public/chunk-6RX3XE55.js | AI (source-diff): Angular/ajv frontend bundle; network+exec pattern is standard UI framework code, not malware. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() in Angular framework bundle; standard Angular DI pattern, not obfuscation. | ai | |
| source-diff | net-exec-file:public/chunk-GAHGBZ7U.js | AI (source-diff): engine.io/Socket.IO client bundle; network+exec pattern is standard WebSocket client code, not malware. | ai | |
| phantom-deps | phantom-dep:@fastify/static | AI (phantom-deps): Fastify plugin registered via config, not direct import pattern. | ai | |
| phantom-deps | phantom-dep:passport | AI (phantom-deps): NestJS framework dependency used via decorators/config, not direct import. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Used in build script to introspect plugin entry points; not runtime user-controlled input. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside bundled Monaco editor (vs/loader.js); standard pattern in that well-known editor component. | ai | |
| phantom-deps | phantom-dep:@nestjs/platform-socket.io | AI (phantom-deps): NestJS platform adapter registered via config, not direct import. | ai | |
| phantom-deps | phantom-dep:class-transformer | AI (phantom-deps): NestJS serialization dependency used via decorators, not direct import. | ai |
Versions (showing 22 of 22)
| Version | Deps | Published |
|---|---|---|
| 5.27.0 | 40 / 26 | |
| 5.25.0 | 40 / 26 | |
| 5.24.0 | 40 / 25 | |
| 5.23.0 | 41 / 26 | |
| 5.22.0 | 41 / 26 | |
| 5.21.0 | 41 / 26 | |
| 5.20.0 | 41 / 26 | |
| 5.19.0 | 41 / 26 | |
| 5.18.0 | 41 / 26 | |
| 5.17.0 | 41 / 26 | |
| 5.16.0 | 41 / 23 | |
| 5.15.2 | 41 / 23 | |
| 5.15.1 | 41 / 23 | |
| 5.15.0 | 41 / 23 | |
| 5.14.0 | 40 / 22 | |
| 5.13.1 | 40 / 22 | |
| 5.13.0 | 40 / 22 | |
| 5.12.0 | 40 / 22 | |
| 5.11.2 | 40 / 22 | |
| 5.11.1 | 40 / 22 | |
| 5.11.0 | 40 / 22 | |
| 5.10.0 | 40 / 22 |
v5.27.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.25.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.21.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.20.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-03-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.19.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-03-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.18.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-02-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.17.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-02-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.16.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-02-08, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.15.2
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-31, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.15.1
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.15.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-17, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.14.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2026-01-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.13.1
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2025-12-28, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.13.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2025-12-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.12.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (supereg) on 2025-12-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v5.11.2
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.11.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.10.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.