← Home

powerlines

The "framework framework" that simplifies modern dev tool usage, generates virtual (or actual) code modules, and improves DX across the board.

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-bot

Keywords

powerlinesstorm-softwareunplugintypescriptdotenvbabelesbuildunbuildnuxtviterolluprspackwebpackastro

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:bin/prompts-Cb5cSsjg.mjs AI (source-diff): Bundled CLI output (esbuild-style), not true obfuscation; no malicious behavior in sample. ai
source-diff obfuscated-file:bin/prompts-BLU5Njeg.mjs AI (source-diff): Minified bundled CLI output, not true obfuscation; no malicious behavior found. ai
source-diff obfuscated-file:bin/prompts-D2lN84PY.mjs AI (source-diff): Bundled tsup/esbuild CLI output, not true obfuscation. ai
source-diff obfuscated-file:bin/prompts-rJ8Zkvkh.mjs AI (source-diff): Bundled CLI output, not true obfuscation; consistent with package's build tooling. ai
source-diff obfuscated-file:bin/prompts-D_Rv-lNz.mjs AI (source-diff): Bundled chunk, minified build output not true obfuscation. ai
source-diff obfuscated-file:bin/bin.mjs AI (source-diff): Bundled CLI entry, minified build output not true obfuscation. ai
phantom-deps phantom-dep:typedoc-plugin-frontmatter AI (phantom-deps): Config-referenced plugin, not a code-import; benign for this doc-tooling package. ai
source-diff large-new-source-files AI (source-diff): Bin directory restructure/bundling, no malicious behavior observed. ai
source-diff obfuscated-file:bin/prompts-DEjU8qNL.mjs AI (source-diff): Bundled esbuild output for CLI, not true obfuscation. ai
source-diff source-size-tripled AI (source-diff): Result of bundling more CLI subcommands into bin/, not injected payload. ai
install-scripts install-script:postinstall AI (install-scripts): Patches TS compiler for deepkit type transformer; documented build-tool behavior, no exfil/fetch. ai
install-scripts install-script:install AI (install-scripts): Removes bundled typescript dep, known deepkit/type-compiler workaround pattern. ai
phantom-deps phantom-dep:@powerlines/plugin-unbuild AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:compatx AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:undici AI (phantom-deps): Known implicit runtime dependency; stable for this package. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@donedeal0/superdiff AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/unique-id AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:bundle-require AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/capnp AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/http AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:@stryke/hash AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:oxc-parser AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:flat-cache AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
phantom-deps phantom-dep:ts-morph AI (phantom-deps): Config-referenced tool; stable pattern for this framework package. ai
dependencies unvetted-dep:@power-plant/schema AI (dependencies): Sibling first-party scoped package in same monorepo ecosystem, low risk. ai
phantom-deps phantom-dep:@jridgewell/sourcemap-codec AI (phantom-deps): Config-referenced dep; stable FP for this package. ai
phantom-deps phantom-dep:locate-character AI (phantom-deps): Config-referenced dep; stable FP for this package. ai
phantom-deps phantom-dep:@stryke/env AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): First-party @storm-software scoped dep; stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. ai
phantom-deps phantom-dep:unplugin AI (phantom-deps): Declared dep; used indirectly via @powerlines/unplugin integration layer. ai
phantom-deps phantom-dep:defu AI (phantom-deps): Declared in package.json deps; likely re-exported or used indirectly via sub-packages in this monorepo. ai
phantom-deps phantom-dep:@stryke/convert AI (phantom-deps): First-party @stryke scoped dep; stable false positive for this package. ai
source-diff obfuscated-file:dist/plugin-utils.d.cts AI (source-diff): File is a TypeScript declaration file with long bundled import lines, not obfuscated executable code. ai
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation; legitimate CI/CD migration for this org. ai
phantom-deps phantom-dep:@babel/plugin-transform-export-namespace-from AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-jsx AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/preset-typescript AI (phantom-deps): Framework-scoped Babel preset; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/helper-simple-access AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/helper-module-imports AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/helper-module-transforms AI (phantom-deps): Framework-scoped Babel helper; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-typescript AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-proposal-decorators AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-transform-react-jsx AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-transform-typescript AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-class-properties AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@babel/plugin-syntax-import-assertions AI (phantom-deps): Framework-scoped Babel plugin; loaded by convention in build tools. ai
phantom-deps phantom-dep:@storm-software/esbuild AI (phantom-deps): Config-referenced tool; stable pattern for this build-tool framework. ai
phantom-deps phantom-dep:@babel/parser AI (phantom-deps): powerlines is a build framework that loads Babel plugins by convention; phantom Babel deps are expected and stable across versions. ai
dependencies unvetted-dep:babel-plugin-parameter-decorator AI (dependencies): Well-known Babel plugin for TypeScript decorator support; no security concerns for this build framework. ai
dependencies unvetted-dep:@storm-software/esbuild AI (dependencies): First-party Storm Software package from the same publisher org with 233 approved packages; stable for this package. ai
dependencies unvetted-dep:@storm-software/tsup AI (dependencies): First-party Storm Software package from the same publisher org with 233 approved packages; stable for this package. ai
phantom-deps phantom-dep:@alloy-js/babel-plugin-jsx-dom-expressions AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:babel-dead-code-elimination AI (phantom-deps): Config-referenced Babel plugin for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:babel-plugin-parameter-decorator AI (phantom-deps): Config-referenced Babel plugin for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:github-slugger AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:nanotar AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@typescript-eslint/utils AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@microsoft/api-extractor AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@microsoft/tsdoc-config AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@alloy-js/babel-preset AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@alloy-js/babel-plugin AI (phantom-deps): Config-referenced package for this build framework; phantom dep pattern is stable. ai
phantom-deps phantom-dep:@babel/generator AI (phantom-deps): Framework-scoped Babel package loaded by convention; expected for this build framework. ai
phantom-deps phantom-dep:@babel/template AI (phantom-deps): Framework-scoped Babel package loaded by convention; expected for this build framework. ai
dependencies unvetted-dep:handlebars AI (dependencies): Handlebars is a well-known templating library used legitimately in this code-generation framework. Constraint ^4.7.8 starts at a patched version past known prototype pollution CVEs. ai
phantom-deps phantom-dep:oxc-resolver AI (phantom-deps): oxc-resolver is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. ai
phantom-deps phantom-dep:@cacheable/memory AI (phantom-deps): @cacheable/memory is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. ai
phantom-deps phantom-dep:unimport AI (phantom-deps): unimport is a runtime dep used via dynamic/config-driven loading in this plugin framework; not directly imported but legitimately declared. ai
dependencies unvetted-dep:@stryke/env AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. ai
phantom-deps phantom-dep:@storm-software/config AI (phantom-deps): Referenced in config files but not directly imported is expected behavior for a config package in a monorepo build tool context. ai
phantom-deps phantom-dep:@babel/types AI (phantom-deps): @babel/types is a well-known package loaded by convention in build tooling; phantom dep finding is expected for this type of framework package. ai
dependencies unvetted-dep:@storm-software/config-tools AI (dependencies): @storm-software/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern. ai
dependencies unvetted-dep:@storm-software/config AI (dependencies): @storm-software/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern. ai
dependencies unvetted-dep:@powerlines/engine AI (dependencies): @powerlines/* packages are first-party packages from the same Storm Software monorepo as powerlines itself. ai
dependencies unvetted-dep:@powerlines/core AI (dependencies): @powerlines/* packages are first-party packages from the same Storm Software monorepo as powerlines itself. ai
dependencies unvetted-dep:@stryke/convert AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. ai
dependencies unvetted-dep:@stryke/fs AI (dependencies): @stryke/* packages are first-party Storm Software org packages, consistent with monorepo publishing pattern for this package family. ai

Versions (showing 51 of 574)

View all versions
Version Deps Published
0.47.147 19 / 4
0.47.146 19 / 4
0.47.145 12 / 5
0.47.144 12 / 5
0.47.139 12 / 5
0.47.134 12 / 5
0.47.132 12 / 5
0.47.130 12 / 5
0.47.128 12 / 5
0.47.124 12 / 5
0.47.123 12 / 5
0.47.122 12 / 5
0.47.121 12 / 5
0.47.120 12 / 5
0.47.119 12 / 5
0.47.118 12 / 5
0.47.117 12 / 5
0.47.116 12 / 5
0.47.115 12 / 5
0.47.114 12 / 5
0.47.113 12 / 5
0.47.112 12 / 5
0.47.111 12 / 5
0.47.110 12 / 5
0.47.109 12 / 5
0.47.108 12 / 5
0.47.107 12 / 5
0.47.106 12 / 5
0.47.105 12 / 5
0.47.104 12 / 5
0.47.103 12 / 5
0.47.102 12 / 5
0.47.101 12 / 5
0.47.100 12 / 5
0.47.99 12 / 5
0.47.98 12 / 5
0.47.97 12 / 5
0.47.96 12 / 5
0.47.95 12 / 5
0.47.94 12 / 5
0.47.93 12 / 5
0.47.92 12 / 5
0.47.91 12 / 5
0.47.90 12 / 5
0.47.89 12 / 5
0.47.88 12 / 5
0.47.87 12 / 5
0.47.86 12 / 5
0.47.85 12 / 5
0.47.84 12 / 5
0.47.83 12 / 5

v0.47.147

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.146

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.145

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.144

28 findings
HIGH New obfuscated file: bin/bin.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/build-DjyA6GQp.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/changelog-B8i9yY3P.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/clean-B9CJqZ1x.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-BYBQBrQG.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-C1fmmSMf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-CK793fTW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-Zf66j-rA.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create-DqStfXER.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/deploy-DnH_cRzq.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/docs-HAdp8uaP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc-DPUIueyK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/help.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/lint-Ba5PLVn8.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/prepare-CGt61HvT.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/prompts-D_Rv-lNz.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-ad5QoVHh.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-Bd5rrPMc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-DG76mLcM.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-zD-5QlvH.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/types-CK9oFG7L.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-ChLxGxOi.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-ZLGSIorW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/zsh-HSOqkRfN.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.139

28 findings
HIGH New obfuscated file: bin/prompts-D2lN84PY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/zsh-D4vduhpt.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/bin.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/help.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-BCnYZE7Z.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc-BfrUs8t4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-CCtmurY_.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-CAFoODHg.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-BviB4q0i.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-D081RTl3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-DNspZ1fX.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-Dhmoxqaf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-eUDz8YBn.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-oBAkmWqR.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-DDWHXu_S.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/deploy-7qpJGrFI.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/types-Cos-hD27.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/docs-CMYq7TR4.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/prepare-CHpl-gcc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create-CchW-TwN.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/lint-D89vp8Cr.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/build-CAoyovYp.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/clean-DnU9yacU.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/changelog-CuRlydrC.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.134

28 findings
HIGH New obfuscated file: bin/prompts-rJ8Zkvkh.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/zsh-DRzKImAL.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/bin.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/help.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-CLUvmNXK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc-DPnR98G3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-mG0keekQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-DdK0gNQv.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-D2Y7UAVP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-Dyr9GPXb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-BshG3OVJ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-BFPw3cmT.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-D5l9lL9A.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-B-S4-NVJ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-CbfYNNnn.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/deploy-C0BxsnBu.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/types-B0EnYviY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/docs-D4htFHCe.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/prepare-CRiyDIvW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create-C6-64ZoZ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/lint-Cq4DaQZl.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/build-CfQN7D2i.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/clean-DkD7F12f.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/changelog-YvOlpRNW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.132

28 findings
HIGH New obfuscated file: bin/prompts-Cb5cSsjg.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/zsh-CZFzf8is.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/bin.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/help.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-iy5PGm0j.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc-RFrX7BLZ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-DvU6LBiI.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-BpliuWI0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-BzN8CLln.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-ncLLrE6q.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-BrQeQKKe.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-DVppJuhk.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-Df-O6gbQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-uIl-CRpQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-CV443TxW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/deploy-BuJ0UIE0.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/types-gPMswswq.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/docs-CFEYp9Sd.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/prepare-LPmDIDM_.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create-nPCRB9gH.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/lint-DfBt41tF.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/build-DfLqjlOR.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/clean-DHUpTVE3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/changelog-Ca8WSvPB.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.130

28 findings
HIGH New obfuscated file: bin/prompts-BLU5Njeg.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/zsh-CovvQbkK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/bin.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/help.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-DgBNLyO5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc-CMR2PoTk.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-BPhth5IY.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-u89xTYDL.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-CO5KKxC_.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-xJKi9Wf3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-tOpMiszf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-DN8bTLuk.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-O-B5wCwp.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-CFsIg7x3.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-B95Kf6xP.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/deploy-7KFyv2gK.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/types-Bqaibqfc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/docs-BYUT4EVd.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/prepare-CO8TSdQ2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create-D6RtqmWf.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/lint-DRX5nXyr.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/build-BOrKBwOU.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/clean-DLWZphBW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/changelog-BIewUxHU.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.128

28 findings
HIGH New obfuscated file: bin/prompts-DEjU8qNL.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/zsh-Bf6VX2tW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/bin.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/help.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-DcBNIEnv.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/gc-yhl6Wc1U.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-Dlyzcim5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-l5WTGeVn.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-8bmAaNQ2.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-RZsaJtzu.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/config-BYunqLZD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-Bx-gKDHc.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-CYWDQkcZ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/script-CXB3vetH.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update-275UZsT_.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/deploy-Dpv_gBUF.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/types-BnaNJFgJ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/docs-B3Vy9nmT.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/prepare-x9Bix5FR.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create-BoPKM4sQ.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/lint-C82qnP4x.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/build-BIaIu9Y5.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/clean-BiN7vXZE.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/changelog-E-js0BZb.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/update.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: bin/create.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.