snyk
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:snyk-tree | AI (phantom-deps): Legitimate first-party Snyk plugin dependency, likely used via dynamic require. | ai | |
| phantom-deps | phantom-dep:wrap-ansi | AI (phantom-deps): Common CLI dep, likely used via transitive/indirect require. | ai | |
| phantom-deps | phantom-dep:validator | AI (phantom-deps): Legacy dep, likely used transitively; not a malware indicator here. | ai | |
| phantom-deps | phantom-dep:promise | AI (phantom-deps): Legacy dep, likely used transitively; not a malware indicator here. | ai | |
| source-diff | obfuscated-file:dist/cli/10.index.js | AI (source-diff): Webpack bundle output; readable module map, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/cli/10.index.js | AI (source-diff): Bundled CLI code; network+exec expected for a security scanner. | ai | |
| source-diff | obfuscated-file:dist/cli/425.index.js | AI (source-diff): Webpack bundle chunk with readable module structure, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/cli/425.index.js | AI (source-diff): Bundled CLI chunk; net+exec are normal for a security scanner CLI. | ai | |
| source-diff | net-exec-file:dist/cli/672.index.js | AI (source-diff): Bundled CLI chunk; benign vendored modules. | ai | |
| source-diff | encoded-string-file:dist/cli/778.index.js | AI (source-diff): Brotli-compressed vendored data in webpack bundle. | ai | |
| source-diff | encoded-string-file:dist/cli/917.index.js | AI (source-diff): GopherJS-compiled runtime, expected long strings. | ai | |
| source-diff | obfuscated-file:dist/cli/778.index.js | AI (source-diff): Webpack bundle chunk with readable code; standard for this CLI package. | ai | |
| source-diff | net-exec-file:dist/cli/778.index.js | AI (source-diff): Bundled CLI chunk naturally contains net+exec; not malicious. | ai | |
| source-diff | encoded-string-file:dist/cli/index.js | AI (source-diff): Sentry ANR worker script base64-encoded; standard practice. | ai | |
| source-diff | encoded-string-file:dist/cli/320.index.js | AI (source-diff): Snyk CLI bundles brotli-compressed webpack assets; this pattern is stable and expected across all versions. | ai | |
| provenance | no-provenance | AI (provenance): Established Snyk package; lack of Sigstore provenance is low risk given publisher track record. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Snyk's documented bootstrap pattern; runs platform binary setup on install across all versions. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Dynamic require loads platform binary deployment config; expected pattern for cross-platform CLI bootstrap. | ai | |
| semgrep | semgrep:env-spread | AI (semgrep): Env spreading is intentional to pass environment to child CLI process; stable pattern for this package. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Snyk bundles platform-specific .node binaries as part of its CLI distribution; stable pattern across versions. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): child_process is used to exec the Snyk CLI binary; core to the wrapper's documented functionality. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 1.1306.2 | 2 / 4 | |
| 1.1306.1 | 2 / 4 | |
| 1.1306.0 | 2 / 4 | |
| 1.1305.2 | 2 / 4 | |
| 1.1305.1 | 2 / 4 | |
| 1.1305.0 | 2 / 4 | |
| 1.1304.3 | 2 / 4 | |
| 1.1304.2 | 2 / 4 | |
| 1.1304.1 | 2 / 4 | |
| 1.1304.0 | 2 / 4 | |
| 1.1303.2 | 2 / 4 | |
| 1.1303.1 | 2 / 4 | |
| 1.1303.0 | 2 / 4 | |
| 1.1302.1 | 2 / 4 | |
| 1.1302.0 | 2 / 4 |
v1.1306.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1306.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1306.0
7 findingsThis version was published by a different npm account than previous versions on 2026-07-09. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 69 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1305.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1305.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1304.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1304.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1304.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1304.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1303.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1303.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1303.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1302.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1302.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.