← Home

snyk

15
Versions
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

snyk-admin

Keywords

securityvulnerabilitiesadvisoriesauditsnykscandockercontainerscanning

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:snyk-tree AI (phantom-deps): Legitimate first-party Snyk plugin dependency, likely used via dynamic require. ai
phantom-deps phantom-dep:wrap-ansi AI (phantom-deps): Common CLI dep, likely used via transitive/indirect require. ai
phantom-deps phantom-dep:validator AI (phantom-deps): Legacy dep, likely used transitively; not a malware indicator here. ai
phantom-deps phantom-dep:promise AI (phantom-deps): Legacy dep, likely used transitively; not a malware indicator here. ai
source-diff obfuscated-file:dist/cli/10.index.js AI (source-diff): Webpack bundle output; readable module map, not obfuscation. ai
source-diff net-exec-file:dist/cli/10.index.js AI (source-diff): Bundled CLI code; network+exec expected for a security scanner. ai
source-diff obfuscated-file:dist/cli/425.index.js AI (source-diff): Webpack bundle chunk with readable module structure, not obfuscation. ai
source-diff net-exec-file:dist/cli/425.index.js AI (source-diff): Bundled CLI chunk; net+exec are normal for a security scanner CLI. ai
source-diff net-exec-file:dist/cli/672.index.js AI (source-diff): Bundled CLI chunk; benign vendored modules. ai
source-diff encoded-string-file:dist/cli/778.index.js AI (source-diff): Brotli-compressed vendored data in webpack bundle. ai
source-diff encoded-string-file:dist/cli/917.index.js AI (source-diff): GopherJS-compiled runtime, expected long strings. ai
source-diff obfuscated-file:dist/cli/778.index.js AI (source-diff): Webpack bundle chunk with readable code; standard for this CLI package. ai
source-diff net-exec-file:dist/cli/778.index.js AI (source-diff): Bundled CLI chunk naturally contains net+exec; not malicious. ai
source-diff encoded-string-file:dist/cli/index.js AI (source-diff): Sentry ANR worker script base64-encoded; standard practice. ai
source-diff encoded-string-file:dist/cli/320.index.js AI (source-diff): Snyk CLI bundles brotli-compressed webpack assets; this pattern is stable and expected across all versions. ai
provenance no-provenance AI (provenance): Established Snyk package; lack of Sigstore provenance is low risk given publisher track record. ai
install-scripts install-script:postinstall AI (install-scripts): Snyk's documented bootstrap pattern; runs platform binary setup on install across all versions. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require loads platform binary deployment config; expected pattern for cross-platform CLI bootstrap. ai
semgrep semgrep:env-spread AI (semgrep): Env spreading is intentional to pass environment to child CLI process; stable pattern for this package. ai
npm-metadata bundled-binaries AI (npm-metadata): Snyk bundles platform-specific .node binaries as part of its CLI distribution; stable pattern across versions. ai
semgrep semgrep:child-process-import AI (semgrep): child_process is used to exec the Snyk CLI binary; core to the wrapper's documented functionality. ai

Versions (showing 15 of 15)

Version Deps Published
1.1306.2 2 / 4
1.1306.1 2 / 4
1.1306.0 2 / 4
1.1305.2 2 / 4
1.1305.1 2 / 4
1.1305.0 2 / 4
1.1304.3 2 / 4
1.1304.2 2 / 4
1.1304.1 2 / 4
1.1304.0 2 / 4
1.1303.2 2 / 4
1.1303.1 2 / 4
1.1303.0 2 / 4
1.1302.1 2 / 4
1.1302.0 2 / 4

v1.1306.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1306.1

3 findings
HIGH New obfuscated file: dist/cli/10.index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cli/10.index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1306.0

7 findings
HIGH Publisher changed: snyk-admin → CircleCI (on 2026-07-09) provenance

This version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.

HIGH New obfuscated file: dist/cli/425.index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/cli/425.index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/cli/672.index.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: dist/cli/778.index.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/cli/917.index.js source-diff

Modified file contains 69 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1305.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1305.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1304.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1304.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1304.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1304.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1303.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1303.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1303.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1302.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1302.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.