slate
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:react-portal | AI (phantom-deps): Used React dep, import text hidden in bundled output. | ai | |
| source-diff | obfuscated-file:lib/slate.js | AI (source-diff): Rollup CJS bundle build output, not obfuscated; stable. | ai | |
| source-diff | obfuscated-file:lib/slate.es.js | AI (source-diff): Rollup ES bundle build output, readable with intact imports; stable across releases. | ai | |
| source-diff | net-exec-file-transition:dist/slate.js | AI (source-diff): Bundled editor code; no dropper/loader behavior, stale diff artifact. | ai | |
| phantom-deps | phantom-dep:tiny-warning | AI (phantom-deps): Bundled build hides imports; tiny-warning is genuinely used by slate. | ai | |
| source-diff | obfuscated-file-transition:dist/index.es.js | AI (source-diff): Readable Rollup/Babel bundle output, not obfuscation; long lines are minified dist. | ai | |
| source-diff | obfuscated-file-transition:dist/index.js | AI (source-diff): CommonJS bundle output with visible imports/helpers; benign build artifact. | ai | |
| source-diff | obfuscated-file-transition:dist/slate.js | AI (source-diff): UMD bundle output; readable factory wrapper, not obfuscated. | ai | |
| phantom-deps | phantom-dep:type-of | AI (phantom-deps): Bundled lib output has no scannable imports; dep is genuinely used. | ai | |
| provenance | missing-githead | AI (provenance): Publish-env change on established package; no behavioral risk. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): benchmark harness loads local benchmark dirs, dev-only | ai | |
| source-diff | net-exec-file:dist/slate.min.js | AI (source-diff): uglified browserify bundle, standard build output. | ai | |
| source-diff | obfuscated-file:dist/slate.js | AI (source-diff): browserify UMD bundle from documented dist scripts, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/slate.js | AI (source-diff): browserify require-shim in bundle, standard build output. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth is from bundled dist output, expected for this build process. | ai | |
| source-diff | bulk-obfuscated-files:dist | AI (source-diff): Minified bundle via uglifyjs, not hand-obfuscated malicious code. | ai | |
| source-diff | bulk-net-exec-files:dist | AI (source-diff): Browserify bundle output, matches dist:max/dist:min build scripts. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are the library's own build artifacts. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Small well-known utility packages consistent with feature diff. | ai | |
| phantom-deps | phantom-dep:mime | AI (phantom-deps): Legacy package, likely used indirectly; no malicious signal. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Legacy package, likely used indirectly; no malicious signal. | ai | |
| dependencies | unvetted-dep:xemplar | AI (dependencies): Old wildcard dep from 2011-era package, not a supply-chain risk indicator. | ai | |
| phantom-deps | phantom-dep:xemplar | AI (phantom-deps): Legacy package, likely used indirectly; no malicious signal. | ai |
Versions (showing 100 of 388)
| Version | Deps | Published |
|---|---|---|
| 0.47.5 | 8 / 2 | |
| 0.47.4 | 8 / 2 | |
| 0.47.3 | 8 / 2 | |
| 0.47.2 | 8 / 2 | |
| 0.47.1 | 8 / 2 | |
| 0.47.0 | 8 / 2 | |
| 0.46.1 | 8 / 2 | |
| 0.46.0 | 8 / 2 | |
| 0.45.1 | 8 / 2 | |
| 0.45.0 | 8 / 2 | |
| 0.44.13 | 8 / 2 | |
| 0.44.12 | 8 / 2 | |
| 0.44.11 | 8 / 2 | |
| 0.44.10 | 8 / 2 | |
| 0.44.9 | 8 / 2 | |
| 0.44.8 | 8 / 2 | |
| 0.44.7 | 8 / 2 | |
| 0.44.6 | 8 / 2 | |
| 0.44.5 | 8 / 2 | |
| 0.44.4 | 8 / 2 | |
| 0.44.3 | 8 / 2 | |
| 0.44.2 | 8 / 2 | |
| 0.44.1 | 8 / 2 | |
| 0.44.0 | 8 / 2 | |
| 0.43.7 | 8 / 2 | |
| 0.43.6 | 8 / 2 | |
| 0.43.5 | 8 / 2 | |
| 0.43.4 | 8 / 2 | |
| 0.43.3 | 8 / 2 | |
| 0.43.2 | 8 / 2 | |
| 0.43.1 | 8 / 2 | |
| 0.43.0 | 8 / 2 | |
| 0.42.6 | 8 / 2 | |
| 0.42.5 | 8 / 2 | |
| 0.42.4 | 8 / 2 | |
| 0.42.3 | 8 / 2 | |
| 0.42.2 | 8 / 2 | |
| 0.42.1 | 8 / 2 | |
| 0.42.0 | 8 / 2 | |
| 0.41.3 | 7 / 2 | |
| 0.41.2 | 7 / 2 | |
| 0.41.1 | 7 / 2 | |
| 0.41.0 | 7 / 2 | |
| 0.40.4 | 7 / 2 | |
| 0.40.3 | 7 / 2 | |
| 0.39.0 | 9 / 2 | |
| 0.38.2 | 9 / 2 | |
| 0.38.1 | 9 / 2 | |
| 0.38.0 | 9 / 2 | |
| 0.37.7 | 9 / 2 | |
| 0.37.6 | 9 / 2 | |
| 0.37.5 | 9 / 2 | |
| 0.37.4 | 9 / 2 | |
| 0.37.3 | 9 / 2 | |
| 0.37.2 | 9 / 2 | |
| 0.37.1 | 9 / 2 | |
| 0.37.0 | 9 / 2 | |
| 0.36.2 | 9 / 2 | |
| 0.36.1 | 9 / 1 | |
| 0.36.0 | 9 / 1 | |
| 0.35.0 | 9 / 1 | |
| 0.34.7 | 9 / 1 | |
| 0.34.6 | 9 / 1 | |
| 0.34.5 | 9 / 1 | |
| 0.34.4 | 9 / 1 | |
| 0.34.3 | 9 / 1 | |
| 0.34.2 | 9 / 1 | |
| 0.34.1 | 9 / 1 | |
| 0.34.0 | 9 / 1 | |
| 0.33.8 | 9 / 1 | |
| 0.33.7 | 9 / 1 | |
| 0.33.6 | 9 / 1 | |
| 0.33.5 | 9 / 1 | |
| 0.33.4 | 9 / 1 | |
| 0.33.3 | 9 / 1 | |
| 0.33.2 | 9 / 1 | |
| 0.33.1 | 9 / 1 | |
| 0.33.0 | 9 / 1 | |
| 0.32.5 | 9 / 1 | |
| 0.32.4 | 9 / 1 | |
| 0.32.3 | 9 / 1 | |
| 0.32.2 | 9 / 4 | |
| 0.32.1 | 8 / 4 | |
| 0.32.0 | 8 / 4 | |
| 0.31.8 | 8 / 4 | |
| 0.31.7 | 8 / 4 | |
| 0.31.6 | 8 / 4 | |
| 0.31.5 | 8 / 4 | |
| 0.31.4 | 8 / 4 | |
| 0.31.3 | 8 / 4 | |
| 0.31.2 | 8 / 4 | |
| 0.31.1 | 8 / 4 | |
| 0.31.0 | 8 / 4 | |
| 0.30.7 | 8 / 4 | |
| 0.30.6 | 8 / 4 | |
| 0.30.5 | 8 / 4 | |
| 0.30.4 | 8 / 4 | |
| 0.30.3 | 8 / 4 | |
| 0.25.3 | 9 / 4 | |
| 0.25.2 | 9 / 4 |
v0.47.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.47.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.46.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.45.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.13
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.12
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.11
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.10
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.9
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.44.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.43.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.42.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.41.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.40.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.39.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.38.2
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.38.1
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.38.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.7
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.6
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.5
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.4
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.3
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.2
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.1
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.37.0
5 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.36.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.35.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.34.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.33.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.32.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.8
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.7
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.6
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.5
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.4
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.25.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: ianstormtaylor.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.