← Home

ruru

2
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

benjie

Keywords

graphilegraphqlgraphiqlgraphite

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:static/7367.js AI (source-diff): Bundled webpack chunk (minified UI asset), not obfuscated payload. ai
source-diff encoded-string-file:dist/bundleCode.js AI (source-diff): Brotli-compressed static asset buffers, documented as bundled resources. ai
source-diff encoded-string-file:dist/bundleMeta.js AI (source-diff): Brotli-compressed static asset buffers, documented as bundled resources. ai
publish-pattern dormant-publish AI (publish-pattern): Long-lived package (68 versions, 50k weekly dl) with unchanged provenance; dormancy alone not concerning. ai
phantom-deps phantom-dep:yargs AI (phantom-deps): yargs used in CLI config; referenced in config files as expected for a CLI tool. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): graphql is a peer dependency referenced in config; stable false positive for this package. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit runtime dependency; stable false positive for this package. ai

Versions (showing 2 of 2)

Version Deps Published
2.0.1 7 / 0
2.0.0 7 / 0

v2.0.1

4 findings
HIGH Long encoded string in modified file: static/7367.js source-diff

Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/bundleCode.js source-diff

Modified file contains 94 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/bundleMeta.js source-diff

Modified file contains 87 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.