pusher-js
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/cjs/pusher-with-encryption.js | AI (source-diff): Bundled websocket client code, not a dropper; network+eval pattern is inherent to the library. | ai | |
| source-diff | net-exec-file:dist/cjs/pusher.js | AI (source-diff): Same bundled output false positive as sibling file. | ai | |
| npm-metadata | url-dep:fetch-mock | AI (npm-metadata): Dev-only test dependency, not shipped to consumers. | ai | |
| npm-metadata | url-dep:karma-jasmine-web-worker | AI (npm-metadata): Dev-only test dependency, not shipped to consumers. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() is in the well-known json2.js polyfill (Crockford's JSON2), a legacy JSON parsing fallback. This pattern is stable and benign for this package. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 4007-day history; lack of Sigstore provenance is common and not a risk signal here. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode is in integration_tests_server/index.js, a test helper only. No malicious payload hiding; stable false positive for this package. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 8.6.0 | 1 / 32 | |
| 8.5.0 | 1 / 32 | |
| 8.4.3 | 1 / 32 | |
| 8.4.2 | 1 / 32 |
v8.6.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.