varlock
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/chunk-XYBJ2DUJ.js | AI (source-diff): Bundled CLI tool legitimately uses child_process/https for secret management; provenance-attested build. | ai | |
| source-diff | net-exec-file:dist/chunk-CU6IMJWG.js | AI (source-diff): Bundled CLI for env/secrets management; network+exec imports are core functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-IC5TUG2F.js | AI (source-diff): Bundled CLI for secret management; network + exec imports are core functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-W3GUFLIV.js | AI (source-diff): CLI tool for secret management legitimately uses child_process, https, fs in its bundled dist. | ai | |
| source-diff | net-exec-file:dist/chunk-FOA6LP5C.js | AI (source-diff): CLI tool legitimately uses child_process/https for env management; bundled output. | ai | |
| dependencies | unvetted-dep:@env-spec/parser | AI (dependencies): Same dmno-dev org as varlock; first-party sibling dependency, not a third-party unknown. | ai | |
| source-diff | net-exec-file:dist/chunk-C4ITUXON.js | AI (source-diff): CLI tool bundle; child_process/https/fs imports are expected for env-management functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-2AGKN64R.js | AI (source-diff): Bundled CLI for secret management; network+exec is core functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-MXPBXRWY.js | AI (source-diff): Bundled CLI for env/secrets management; legitimate use of https+exec. SLSA provenance confirms source. | ai | |
| source-diff | net-exec-file:dist/chunk-J6FIWUFA.js | AI (source-diff): Bundled CLI for secret/env management; child_process+https+crypto are core to its function. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance present; gitHead absence is a non-issue with Sigstore attestation. | ai | |
| source-diff | net-exec-file:dist/chunk-PBWMMYWL.js | AI (source-diff): Bundled CLI tool legitimately uses child_process and https for its core functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-6CRDPEUT.js | AI (source-diff): Bundled CLI for secret management; network+exec is core functionality, not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-KG6Y2XNO.js | AI (source-diff): Bundled CLI chunk; child_process/https imports expected for a secrets-management CLI tool. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 109k weekly downloads; missing provenance is common and not a risk signal here. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package restructured its dist output; large file additions are expected for a CLI tool with bundled dependencies. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Large refactor with SLSA provenance; dormancy explained by development cycle, not account takeover indicators. | ai | |
| source-diff | net-exec-file:dist/chunk-5LNYCOEO.js | AI (source-diff): Legitimate bundled dist for a secrets/env CLI; network+exec imports are expected for this tool's functionality. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Binaries are the core local-encrypt feature of this secrets management CLI; SLSA provenance attestation validates their integrity. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 1.5.1 | 0 / 22 | |
| 1.5.0 | 0 / 22 | |
| 1.4.0 | 0 / 22 | |
| 1.2.0 | 0 / 21 | |
| 1.1.0 | 0 / 21 | |
| 0.9.1 | 0 / 21 | |
| 0.9.0 | 0 / 21 | |
| 0.8.2 | 0 / 21 | |
| 0.8.1 | 0 / 21 | |
| 0.8.0 | 0 / 21 | |
| 0.7.4 | 0 / 21 | |
| 0.7.3 | 0 / 21 | |
| 0.7.2 | 0 / 21 | |
| 0.7.1 | 0 / 21 | |
| 0.7.0 | 0 / 21 | |
| 0.6.4 | 0 / 20 | |
| 0.6.3 | 0 / 20 | |
| 0.6.1 | 0 / 20 | |
| 0.6.0 | 0 / 20 | |
| 0.5.0 | 0 / 20 | |
| 0.4.2 | 0 / 20 | |
| 0.4.1 | 0 / 20 | |
| 0.4.0 | 0 / 20 | |
| 0.3.0 | 0 / 20 | |
| 0.2.3 | 0 / 20 | |
| 0.2.2 | 5 / 20 | |
| 0.2.1 | 5 / 20 | |
| 0.2.0 | 5 / 20 | |
| 0.1.6 | 5 / 20 | |
| 0.1.4 | 5 / 20 | |
| 0.1.3 | 5 / 20 | |
| 0.1.2 | 5 / 20 | |
| 0.1.1 | 5 / 20 |
v1.5.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v1.5.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
2 findingsPackage contains compiled binaries that could be backdoors: • native-bins/linux-arm64/varlock-local-encrypt • native-bins/linux-x64/varlock-local-encrypt • native-bins/win32-x64/varlock-local-encrypt.exe
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.9.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.2
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.8.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.4
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.3
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.4
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.3
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.