← Home

vod-js-sdk-v6

47
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

superjollytencent-playerallenxhu

Keywords

tencentcloudsdkvod

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:src/base.js AI (source-diff): Bundled dependency code, not obfuscation. ai
phantom-deps phantom-dep:cos-js-sdk-v5 AI (phantom-deps): Used via bundled dist, heuristic false positive. ai
maintainer-change maintainer-takeover AI (maintainer-change): 981 days live on npm without unpublish; consistent with legitimate transfer. ai
source-diff net-exec-file:src/cos-js-sdk-v5.js AI (source-diff): Official cos-js-sdk-v5 webpack bundle, expected content. ai
source-diff net-exec-file:src/base.js AI (source-diff): Bundled dependency code. ai
source-diff obfuscated-file:lib/src/base.js AI (source-diff): Bundled cos-js-sdk-v5 webpack UMD output, not injected obfuscation. ai
source-diff net-exec-file:lib/src/base.js AI (source-diff): Same vendored bundle; no concrete malicious network/exec behavior. ai
npm-metadata bundled-binaries AI (npm-metadata): fsevents native .node binary inside committed demo node_modules, standard macOS optional dep, not a backdoor. ai
vendored-integrity tampered-vendored-dep:docs/import-demo/node_modules/atob AI (vendored-integrity): Committed demo node_modules; sole diff is npm install-time package.json metadata (_resolved/_where), no code payload. ai
source-diff obfuscated-file:docs/import-demo/node_modules/vue/dist/vue.common.prod.js AI (source-diff): Stock minified Vue bundle in committed demo node_modules; not obfuscation. ai
source-diff net-exec-file:docs/import-demo/node_modules/vue/dist/vue.common.prod.js AI (source-diff): Stock minified Vue library in committed demo tree; no dropper behavior. ai
publish-pattern new-deps-added AI (publish-pattern): uuid and eventemitter3 are well-known established deps. ai
provenance publisher-changed-stale AI (provenance): Long-stable legitimate publisher change from 2020, unchanged since. ai
source-diff encoded-string-file:test/uploader.test.ts AI (source-diff): Base64 strings are mocked test fixtures for upload signatures, not hidden payloads. ai
source-diff net-exec-file:docs/import-demo/bundle.js AI (source-diff): Bundled webpack demo posting to Tencent's own demo upload endpoint, not a dropper. ai
semgrep semgrep:new-function-constructor AI (semgrep): Same bundled demo file; build artifact, not obfuscation. ai
semgrep semgrep:eval-usage AI (semgrep): Fires inside bundled third-party libs (sha1/Vue) within webpack demo bundle. ai

Versions (showing 47 of 47)

Version Deps Published
1.8.0 7 / 22
1.7.4 6 / 22
1.7.3 5 / 22
1.7.2 5 / 22
1.7.0 6 / 22
1.6.2 6 / 22
1.6.1 5 / 23
1.6.0 5 / 23
1.5.0 5 / 23
1.4.16 5 / 23
1.4.15 5 / 23
1.4.14 5 / 23
1.4.13 5 / 23
1.4.12 5 / 23
1.4.11 4 / 23
1.4.10 4 / 23
1.4.9 4 / 23
1.4.8 4 / 23
1.4.7 4 / 22
1.4.6 4 / 22
1.4.5 4 / 22
1.4.4 4 / 22
1.4.3 4 / 22
1.4.2 4 / 22
1.4.1 4 / 22
1.4.0 4 / 22
1.3.3 3 / 21
1.3.2 3 / 21
1.3.1 3 / 21
1.2.11 3 / 13
1.2.10 3 / 13
1.2.9 3 / 13
1.2.8 3 / 13
1.2.7 3 / 13
1.2.6 3 / 13
1.2.4 3 / 13
1.2.3 3 / 13
1.2.2 3 / 13
1.2.1 3 / 13
1.2.0 3 / 13
1.1.6 3 / 13
1.1.5 3 / 12
1.1.4 3 / 11
1.1.3 3 / 11
1.1.2 3 / 11
1.1.0 3 / 11
1.0.0 3 / 11

v1.7.0

8 findings
HIGH New obfuscated file: lib/src/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/src/base.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/base.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: src/cos-js-sdk-v5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → superjolly (on 2023-11-13, unremoved on npm for 981d) provenance

This version was published by a different npm account (superjolly) than the most recent previously approved version (alsotang) on 2023-11-13. It has since remained available on npm for 981 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.2

8 findings
HIGH New obfuscated file: lib/src/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: lib/src/base.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: src/base.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: src/base.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: src/cos-js-sdk-v5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2023-07-26, unremoved on npm for 1091d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2023-07-26. It has since remained available on npm for 1091 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.1

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2023-02-06, unremoved on npm for 1261d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2023-02-06. It has since remained available on npm for 1261 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.0

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2023-02-03, unremoved on npm for 1264d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2023-02-03. It has since remained available on npm for 1264 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2022-08-09, unremoved on npm for 1442d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-08-09. It has since remained available on npm for 1442 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.16

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2022-08-09, unremoved on npm for 1442d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-08-09. It has since remained available on npm for 1442 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.15

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2022-08-05, unremoved on npm for 1446d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-08-05. It has since remained available on npm for 1446 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.14

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2022-05-16, unremoved on npm for 1527d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-05-16. It has since remained available on npm for 1527 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.13

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → tencent-player (on 2022-04-08, unremoved on npm for 1565d) provenance

This version was published by a different npm account (tencent-player) than the most recent previously approved version (alsotang) on 2022-04-08. It has since remained available on npm for 1565 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.12

2 findings
MEDIUM Publisher changed: alsotang → _windmill (on 2021-05-27, unremoved on npm for 1881d) provenance

This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2021-05-27. It has since remained available on npm for 1881 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.11

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → _windmill (on 2020-10-16, unremoved on npm for 2104d) provenance

This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2020-10-16. It has since remained available on npm for 2104 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.10

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → _windmill (on 2020-08-07, unremoved on npm for 2174d) provenance

This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2020-08-07. It has since remained available on npm for 2174 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.9

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → _windmill (on 2020-08-03, unremoved on npm for 2178d) provenance

This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2020-08-03. It has since remained available on npm for 2178 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.8

3 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

MEDIUM Publisher changed: alsotang → _windmill (on 2019-12-18, unremoved on npm for 2407d) provenance

This version was published by a different npm account (_windmill) than the most recent previously approved version (alsotang) on 2019-12-18. It has since remained available on npm for 2407 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.7

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.6

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.5

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.4

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.3

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.1

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/b9b6ae4aa1ef9a0331d4b7c0b9dd6b38b6dc0bda/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.3

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/4062fb96f9534d15dda7213e977346fdecff5d64/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/ef3f8e6f80bd56132f9dd7cc90cfa5033a409710/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/37d93b9875ad412aace7e8c5b3d9645cc6670fd4/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.11

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d7f590d2855884e833fa2059ec4568b8e5f631a7/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.10

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d877209ceaff2bb99bfa53c1e7398fa952a0b7cd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.9

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/7d45870e4a91f3ac747cf80900ea16f819b51fc9/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.8

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/93bef43f4e2ea29808a3b88cd6bde4d3468059bd/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.7

11 findings
HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.6

83 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • docs/import-demo/node_modules/fsevents/lib/binding/Release/node-v67-darwin-x64/fse.node

HIGH New obfuscated file: docs/import-demo/node_modules/vod-js-sdk-v6/dist/vod-js-sdk-v6.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: docs/import-demo/node_modules/vod-js-sdk-v6/dist/vod-js-sdk-v6.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: docs/import-demo/node_modules/vue/dist/vue.common.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: docs/import-demo/node_modules/vue/dist/vue.common.prod.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/terser/dist/bundle.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: docs/import-demo/node_modules/source-map-support/node_modules/source-map/dist/source-map.debug.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/source-map/dist/source-map.debug.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: docs/import-demo/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/cos-js-sdk-v5/dist/cos-js-sdk-v5.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/ajv/dist/ajv.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/vue/dist/vue.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/vue/dist/vue.esm.browser.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/cos-js-sdk-v5/demo/common/vue.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: docs/import-demo/node_modules/vue/dist/vue.runtime.common.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/json5/dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/json5/lib/unicode.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/json5/lib/parse.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/@xtuc/long/dist/long.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: docs/import-demo/node_modules/terser/dist/bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: docs/import-demo/node_modules/json5/lib/stringify.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/acorn/dist/acorn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/acorn/dist/acorn.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: docs/import-demo/node_modules/browserify-rsa/test.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: docs/import-demo/node_modules/ajv/dist/ajv.bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/bluebird/js/browser/bluebird.core.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/bluebird/js/browser/bluebird.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/cos-js-sdk-v5/dist/cos-js-sdk-v5.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/vue/dist/vue.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/vue/dist/vue.common.dev.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/vue/dist/vue.esm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/cos-js-sdk-v5/lib/request.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/vue/dist/vue.esm.browser.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: docs/import-demo/node_modules/bluebird/js/release/promisify.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/ast (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/ast` byte-matched 33 of 34 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/ast/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/browserify-aes (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/browserify-aes` byte-matched 21 of 22 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/browserify-aes/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/crypto-browserify (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/crypto-browserify` byte-matched 20 of 21 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/crypto-browserify/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/fast-json-stable-stringify (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/fast-json-stable-stringify` byte-matched 15 of 16 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fast-json-stable-stringify/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/querystring (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/querystring` byte-matched 14 of 15 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/querystring/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/wast-parser (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/wast-parser` byte-matched 12 of 13 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wast-parser/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/utf8 (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/utf8` byte-matched 11 of 12 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/utf8/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/helper-wasm-section (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/helper-wasm-section` byte-matched 9 of 10 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-wasm-section/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/leb128 (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/leb128` byte-matched 9 of 10 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/leb128/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/browserify-zlib (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/browserify-zlib` byte-matched 9 of 10 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/browserify-zlib/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/wasm-parser (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-parser` byte-matched 8 of 9 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-parser/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/atob (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/atob` byte-matched 8 of 9 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/atob/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/json-schema-traverse (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/json-schema-traverse` byte-matched 8 of 9 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/json-schema-traverse/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/acorn-dynamic-import (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/acorn-dynamic-import` byte-matched 7 of 8 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/acorn-dynamic-import/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/xtend (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/xtend` byte-matched 7 of 8 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/xtend/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/wasm-edit (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-edit` byte-matched 6 of 7 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-edit/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/assert (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/assert` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/assert/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/concat-map (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/concat-map` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/concat-map/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/fsevents/node_modules/concat-map (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/fsevents/node_modules/concat-map` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/concat-map/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/fsevents/node_modules/isarray (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/fsevents/node_modules/isarray` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/isarray/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/isarray (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/isarray` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/isarray/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/isexe (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/isexe` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/isexe/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/pump (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/pump` byte-matched 6 of 7 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/pump/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/helper-buffer (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/helper-buffer` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-buffer/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/helper-module-context (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/helper-module-context` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-module-context/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/helper-wasm-bytecode (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/helper-wasm-bytecode` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/helper-wasm-bytecode/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/wasm-gen (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-gen` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-gen/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/wasm-opt (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/wasm-opt` byte-matched 5 of 6 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wasm-opt/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@xtuc/ieee754 (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@xtuc/ieee754` byte-matched 5 of 6 file(s) against @xtuc/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@xtuc/ieee754/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @xtuc/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/core-util-is (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/core-util-is` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/core-util-is/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/fsevents/node_modules/core-util-is (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/fsevents/node_modules/core-util-is` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/core-util-is/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/js-sha1 (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/js-sha1` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/js-sha1/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/stream-browserify (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/stream-browserify` byte-matched 5 of 6 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/stream-browserify/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/floating-point-hex-parser (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/floating-point-hex-parser` byte-matched 4 of 5 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/floating-point-hex-parser/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/ieee754 (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/ieee754` byte-matched 4 of 5 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/ieee754/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/@webassemblyjs/wast-printer (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/@webassemblyjs/wast-printer` byte-matched 4 of 5 file(s) against @webassemblyjs/[email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/@webassemblyjs/wast-printer/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against @webassemblyjs/[email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/fsevents/node_modules/string_decoder (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/fsevents/node_modules/string_decoder` byte-matched 4 of 5 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/fsevents/node_modules/string_decoder/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/is-buffer (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/is-buffer` byte-matched 4 of 5 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/is-buffer/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH Modified vendored dependency: docs/import-demo/node_modules/string_decoder (1 file(s)) vendored-integrity

The directory `docs/import-demo/node_modules/string_decoder` byte-matched 4 of 5 file(s) against [email protected] — a version that passed review and that we hold in storage — which identifies it as a vendored copy of that package. But 1 file(s) inside it differ from that package's bytes at the same path: docs/import-demo/node_modules/string_decoder/package.json. A vendored library that is a faithful copy except for a handful of altered files is a well-worn supply-chain shape — the surrounding real code lends the tree legitimacy while the altered files carry the payload. These files are NOT exempt from any authorship heuristic; diff them against [email protected] before greenflagging.

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH eval-usage: docs/import-demo/bundle.js:25 semgrep

eval() can execute arbitrary code — common in supply-chain attacks but also used by legitimate parsers and template engines. Verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:25 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L25 23 | * @license MIT 24 | */ > 25 | !function(){"use strict";var root="object"==typeof window?window:{},NODE_JS=!root.JS_SHA1_NO_NODE_JS&&"object"==typeof p 26 | /*! 27 | * Vue.js v2.6.10

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

HIGH new-function-constructor: docs/import-demo/bundle.js:30 semgrep

new Function() dynamically compiles and executes code, similar to eval(). Common in template engines and parsers — verify the input source. Source: https://github.com/tencentyun/vod-js-sdk-v6/blob/d3884f4192fae881a9538ce12459834a1952447b/docs/import-demo/bundle.js#L30 28 | * (c) 2014-2019 Evan You 29 | * Released under the MIT License. > 30 | */var r;r=function(){"use strict";var e=Object.freeze({});function r(e){return null==e}function o(e){return null!=e}fun 31 | //# sourceMappingURL=bundle.js.map

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.4

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.3

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.5

2 findings
HIGH Long encoded string in modified file: test/uploader.test.ts source-diff

Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.