← Home

sandbox

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

matheussmatt.strakavercel-release-botzeit-bot

Keywords

vercelsandboxcli

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Size growth from legitimate bundled dist output. ai
source-diff obfuscated-file:dist/string-width-D78SVDLD.mjs AI (source-diff): Bundled tsdown output of ansi-regex/strip-ansi, not obfuscation; stable for this build tool. ai
npm-metadata bundled-binaries AI (npm-metadata): pty-server-linux binary is documented PTY-tunnel component of the Vercel Sandbox CLI. ai

Versions (showing 51 of 57)

View all versions
Version Deps Published
3.5.2 5 / 18
3.5.1 5 / 18
3.5.0 5 / 18
3.4.3 5 / 18
3.4.2 5 / 18
3.4.1 5 / 18
3.4.0 5 / 18
3.3.1 5 / 18
3.3.0 5 / 18
3.2.2 5 / 18
3.2.1 5 / 18
3.2.0 5 / 18
3.1.2 4 / 19
3.1.1 4 / 19
3.1.0 4 / 19
3.0.2 4 / 19
3.0.1 4 / 19
3.0.0 4 / 19
2.5.12 3 / 18
2.5.11 3 / 18
2.5.10 3 / 18
2.5.9 3 / 18
2.5.8 3 / 18
2.5.7 3 / 18
2.5.6 3 / 18
2.5.5 3 / 18
2.5.4 3 / 18
2.5.3 3 / 18
2.5.2 3 / 18
2.5.1 3 / 18
2.5.0 3 / 18
2.4.0 3 / 18
2.3.0 3 / 18
2.2.0 3 / 18
2.1.0 3 / 18
2.0.4 3 / 18
2.0.3 3 / 18
2.0.2 3 / 18
2.0.1 3 / 18
2.0.0 3 / 18
1.0.19 2 / 0
1.0.18 2 / 0
1.0.17 2 / 0
1.0.16 2 / 0
1.0.15 2 / 0
1.0.14 2 / 0
1.0.13 2 / 0
1.0.12 2 / 0
1.0.11 2 / 0
1.0.10 2 / 0
1.0.9 2 / 0

v3.5.2

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-07-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-07-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.5.1

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-07-18, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-07-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.5.0

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-07-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-07-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.4.3

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-07-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-07-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.4.2

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-07-13, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-07-13, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.4.1

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-07-07, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-07-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.4.0

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-07-03, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-07-03, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.3.1

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.3.0

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.2.2

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.2.1

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-12, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-12, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.2.0

3 findings
HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-10, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.2

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-04, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-04, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.1

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-02, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-02, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.1.0

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-06-01, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-06-01, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.2

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-05-29, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-05-29, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.1

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-05-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-05-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.0.0

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-05-22, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-05-22, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.5.12

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-05-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-05-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.5.11

4 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: vercel-release-bot → GitHub Actions (on 2026-05-07, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (vercel-release-bot) on 2026-05-07, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.5.10

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.9

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.8

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.7

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.6

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.5

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.4

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.3

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.2

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.1

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

3 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/pty-server-linux-x86_64

HIGH New obfuscated file: dist/string-width-D78SVDLD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.