railway
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-DKbAXI_A.d.ts | AI (source-diff): Long-line TS type declarations, not executable obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-DKbAXI_A.d.cts | AI (source-diff): Long-line TS type declarations, not executable obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-ErNNPAek.d.cts | AI (source-diff): Generated .d.cts type file with long union lines, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-ErNNPAek.d.ts | AI (source-diff): Generated .d.ts type file with long union lines, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-qc8SqGnG.d.cts | AI (source-diff): Generated .d.cts type declarations with long lines, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-qc8SqGnG.d.ts | AI (source-diff): Generated .d.ts type declarations with long lines, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-B7HOzgdR.d.cts | AI (source-diff): TypeScript declaration file with long re-export lines; normal tsup/rollup output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/iac/index.d.cts | AI (source-diff): TypeScript declaration file with long re-export lines; normal tsup/rollup output, not obfuscation. | ai | |
| phantom-deps | phantom-dep:tsx | AI (phantom-deps): tsx is used in demo/script entries (demo:iac, package:check); not a phantom dep concern. | ai | |
| source-diff | obfuscated-file:dist/iac/index.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; normal tsup/rollup output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-B7HOzgdR.d.ts | AI (source-diff): TypeScript declaration file with long re-export lines; normal tsup/rollup output, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@graphql-typed-document-node/core | AI (phantom-deps): Peer/type dependency for GraphQL typed documents; stable false positive for this package. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 3.5.2 | 3 / 11 | |
| 3.5.1 | 3 / 11 | |
| 3.5.0 | 3 / 11 | |
| 3.4.2 | 3 / 11 | |
| 3.4.1 | 3 / 11 | |
| 3.4.0 | 3 / 11 | |
| 3.3.2 | 3 / 11 | |
| 3.3.1 | 3 / 11 | |
| 3.3.0 | 3 / 11 | |
| 3.2.0 | 3 / 11 | |
| 3.1.4 | 3 / 11 | |
| 3.1.3 | 3 / 11 | |
| 3.1.2 | 3 / 11 | |
| 3.1.1 | 3 / 11 | |
| 3.1.0 | 3 / 11 | |
| 3.0.3 | 2 / 12 | |
| 3.0.2 | 2 / 12 | |
| 3.0.1 | 2 / 12 | |
| 3.0.0 | 2 / 12 |
v3.5.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.5.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.4.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.4.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.