ruru
2
Versions
—
License
No
Install Scripts
Attested
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation (unverified)
npm registry signatures
gitHead linked
Maintainers
benjie
Keywords
graphilegraphqlgraphiqlgraphite
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:static/7367.js | AI (source-diff): Bundled webpack chunk (minified UI asset), not obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/bundleCode.js | AI (source-diff): Brotli-compressed static asset buffers, documented as bundled resources. | ai | |
| source-diff | encoded-string-file:dist/bundleMeta.js | AI (source-diff): Brotli-compressed static asset buffers, documented as bundled resources. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Long-lived package (68 versions, 50k weekly dl) with unchanged provenance; dormancy alone not concerning. | ai | |
| phantom-deps | phantom-dep:yargs | AI (phantom-deps): yargs used in CLI config; referenced in config files as expected for a CLI tool. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): graphql is a peer dependency referenced in config; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a known implicit runtime dependency; stable false positive for this package. | ai |
v2.0.1
4 findings
HIGH
Long encoded string in modified file: static/7367.js
source-diff
Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
HIGH
Long encoded string in modified file: dist/bundleCode.js
source-diff
Modified file contains 94 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
HIGH
Long encoded string in modified file: dist/bundleMeta.js
source-diff
Modified file contains 87 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.