varlock
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | bulk-net-exec-files:dist | AI (source-diff): Bundled build output using standard node builtins for CLI functionality, not injected exec code. | ai | |
| source-diff | net-exec-file:dist/chunk-3RZQ5CCT.js | AI (source-diff): Bundled CLI output; child_process+https are core to a secrets/env manager, no hostile destination. | ai | |
| source-diff | net-exec-file:dist/chunk-VQKJGQUB.js | AI (source-diff): Bundled tsup output; child_process/https are core to a CLI secret manager, no hostile destination. | ai | |
| source-diff | net-exec-file:dist/chunk-IBFUIBQD.js | AI (source-diff): Bundled tsup output; child_process/https use is core to a secrets-manager CLI. Hash-suffixed chunk name varies per build. | ai | |
| source-diff | net-exec-file:dist/chunk-A2CLCDH2.js | AI (source-diff): Bundled CLI output; child_process+https are core to varlock's secret-management function. | ai | |
| source-diff | net-exec-file:dist/chunk-GKN3UJNE.js | AI (source-diff): Bundled tsup CLI output; net+exec capability is inherent to a secrets CLI, no exfil destination. | ai | |
| source-diff | net-exec-file:dist/chunk-SX4IDFJO.js | AI (source-diff): Bundled tsup output; network+exec are core CLI/secrets-tool functionality, no hostile target. | ai | |
| source-diff | net-exec-file:dist/chunk-LTYLEVHC.js | AI (source-diff): Bundled tsup chunk; child_process/https are core to CLI secret resolution, no exfil target. | ai | |
| source-diff | net-exec-file:dist/chunk-CBO5NXPJ.js | AI (source-diff): Bundled tsup CLI output; child_process/https are core to this secrets CLI, no hostile target. | ai | |
| source-diff | net-exec-file:dist/chunk-ZEFEE3DD.js | AI (source-diff): Bundled tsup build output; network+exec are core to a secrets CLI, no hostile destination. | ai | |
| source-diff | net-exec-file:dist/chunk-OU4DP3EV.js | AI (source-diff): Bundled CLI tool importing standard Node builtins (child_process, https, crypto); expected for secrets-management package. | ai | |
| source-diff | net-exec-file:dist/chunk-XYBJ2DUJ.js | AI (source-diff): Bundled CLI tool legitimately uses child_process/https for secret management; provenance-attested build. | ai | |
| source-diff | net-exec-file:dist/chunk-CU6IMJWG.js | AI (source-diff): Bundled CLI for env/secrets management; network+exec imports are core functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-IC5TUG2F.js | AI (source-diff): Bundled CLI for secret management; network + exec imports are core functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-W3GUFLIV.js | AI (source-diff): CLI tool for secret management legitimately uses child_process, https, fs in its bundled dist. | ai | |
| source-diff | net-exec-file:dist/chunk-FOA6LP5C.js | AI (source-diff): CLI tool legitimately uses child_process/https for env management; bundled output. | ai | |
| dependencies | unvetted-dep:@env-spec/parser | AI (dependencies): Same dmno-dev org as varlock; first-party sibling dependency, not a third-party unknown. | ai | |
| source-diff | net-exec-file:dist/chunk-C4ITUXON.js | AI (source-diff): CLI tool bundle; child_process/https/fs imports are expected for env-management functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-2AGKN64R.js | AI (source-diff): Bundled CLI for secret management; network+exec is core functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-MXPBXRWY.js | AI (source-diff): Bundled CLI for env/secrets management; legitimate use of https+exec. SLSA provenance confirms source. | ai | |
| source-diff | net-exec-file:dist/chunk-J6FIWUFA.js | AI (source-diff): Bundled CLI for secret/env management; child_process+https+crypto are core to its function. | ai | |
| source-diff | net-exec-file:dist/chunk-PBWMMYWL.js | AI (source-diff): Bundled CLI tool legitimately uses child_process and https for its core functionality. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance present; gitHead absence is a non-issue with Sigstore attestation. | ai | |
| source-diff | net-exec-file:dist/chunk-6CRDPEUT.js | AI (source-diff): Bundled CLI for secret management; network+exec is core functionality, not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-KG6Y2XNO.js | AI (source-diff): Bundled CLI chunk; child_process/https imports expected for a secrets-management CLI tool. | ai | |
| provenance | no-provenance | AI (provenance): Established package with 109k weekly downloads; missing provenance is common and not a risk signal here. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package restructured its dist output; large file additions are expected for a CLI tool with bundled dependencies. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Large refactor with SLSA provenance; dormancy explained by development cycle, not account takeover indicators. | ai | |
| source-diff | net-exec-file:dist/chunk-5LNYCOEO.js | AI (source-diff): Legitimate bundled dist for a secrets/env CLI; network+exec imports are expected for this tool's functionality. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): Binaries are the core local-encrypt feature of this secrets management CLI; SLSA provenance attestation validates their integrity. | ai |
Versions (showing 45 of 45)
| Version | Deps | Published |
|---|---|---|
| 1.11.0 | 0 / 24 | |
| 1.10.0 | 0 / 24 | |
| 1.9.0 | 0 / 24 | |
| 1.8.0 | 0 / 24 | |
| 1.7.2 | 0 / 23 | |
| 1.7.1 | 0 / 23 | |
| 1.7.0 | 0 / 23 | |
| 1.6.1 | 0 / 23 | |
| 1.6.0 | 0 / 23 | |
| 1.5.1 | 0 / 22 | |
| 1.5.0 | 0 / 22 | |
| 1.4.0 | 0 / 22 | |
| 1.3.0 | 0 / 21 | |
| 1.2.0 | 0 / 21 | |
| 1.1.0 | 0 / 21 | |
| 0.9.1 | 0 / 21 | |
| 0.9.0 | 0 / 21 | |
| 0.8.2 | 0 / 21 | |
| 0.8.1 | 0 / 21 | |
| 0.8.0 | 0 / 21 | |
| 0.7.4 | 0 / 21 | |
| 0.7.3 | 0 / 21 | |
| 0.7.2 | 0 / 21 | |
| 0.7.1 | 0 / 21 | |
| 0.7.0 | 0 / 21 | |
| 0.6.4 | 0 / 20 | |
| 0.6.3 | 0 / 20 | |
| 0.6.2 | 0 / 20 | |
| 0.6.1 | 0 / 20 | |
| 0.6.0 | 0 / 20 | |
| 0.5.0 | 0 / 20 | |
| 0.4.2 | 0 / 20 | |
| 0.4.1 | 0 / 20 | |
| 0.4.0 | 0 / 20 | |
| 0.3.0 | 0 / 20 | |
| 0.2.3 | 0 / 20 | |
| 0.2.2 | 5 / 20 | |
| 0.2.1 | 5 / 20 | |
| 0.2.0 | 5 / 20 | |
| 0.1.6 | 5 / 20 | |
| 0.1.5 | 5 / 20 | |
| 0.1.4 | 5 / 20 | |
| 0.1.3 | 5 / 20 | |
| 0.1.2 | 5 / 20 | |
| 0.1.1 | 5 / 20 |
v1.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.6.2
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.