@amodalai/runtime-app
26
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
amodaldev
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/assets/index-Ddep5KVX.js | AI (source-diff): Standard Vite/React production bundle; minification is expected for this UI asset package. | ai | |
| source-diff | obfuscated-file:dist/assets/index-Cmws_EDX.js | AI (source-diff): Standard Vite/React minified bundle; not obfuscated malware. Stable pattern for this frontend package. | ai | |
| source-diff | obfuscated-file:dist/assets/index-1Sq41APO.js | AI (source-diff): Standard Vite/React minified bundle; consistent with build tooling declared in package.json. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CFBCIBt8.js | AI (source-diff): Standard Vite/React minified build output; React license header visible in sample confirms legitimate bundled code. | ai | |
| source-diff | obfuscated-file:dist/assets/index-4-vNGOPa.js | AI (source-diff): Standard Vite/React production bundle; minified output is expected for this frontend app package. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BgLJGZT2.js | AI (source-diff): Standard Vite-minified React bundle; React license header visible in sample, no malicious indicators. | ai | |
| source-diff | obfuscated-file:dist/assets/index-DNjWcVGY.js | AI (source-diff): Standard Vite/React production bundle; minification is expected for this package type. | ai | |
| source-diff | obfuscated-file:dist/assets/index-r1gGOn-S.js | AI (source-diff): Standard Vite/React production bundle; minification is expected for this package's build output. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal monorepo package; missing metadata is expected, not malicious. | ai | |
| phantom-deps | phantom-dep:@amodalai/react | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:cron-parser | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:lucide-react | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/view | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/state | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/search | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/commands | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/language | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/lang-json | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/autocomplete | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:@codemirror/lang-markdown | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:clsx | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:cronstrue | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): React component library; dependencies declared and used in config/exports. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BoPrMuAN.js | AI (source-diff): Standard Vite/React production bundle; minification is expected for this frontend app package. | ai | |
| source-diff | obfuscated-file:dist/assets/index-CFMBq0OB.js | AI (source-diff): Standard Vite-minified React bundle; React license header visible in sample, consistent with build tooling in package.json. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BdV4gm0x.js | AI (source-diff): Standard Vite-minified React bundle; React license header visible in sample, consistent with package.json build config. | ai | |
| phantom-deps | phantom-dep:recharts | AI (phantom-deps): Directly imported in dependencies; UI library pattern. | ai | |
| phantom-deps | phantom-dep:codemirror | AI (phantom-deps): Directly imported in dependencies; UI library pattern. | ai | |
| source-diff | obfuscated-file:dist/assets/index-B1QggBTl.js | AI (source-diff): Standard Vite/React production bundle; minified output is expected for this frontend runtime app. | ai | |
| source-diff | obfuscated-file:dist/assets/index-BWcr9167.js | AI (source-diff): Standard Vite/React production bundle; minification is expected for this runtime app package. | ai | |
| source-diff | obfuscated-file:dist/assets/index-ZmB4k_QN.js | AI (source-diff): Standard Vite/React production bundle; minified not obfuscated. Stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:class-variance-authority | AI (phantom-deps): UI utility likely used in component files; stable false positive for this scoped package. | ai | |
| phantom-deps | phantom-dep:react-markdown | AI (phantom-deps): Likely used in JSX/TSX files not caught by import scanner; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:autoprefixer | AI (phantom-deps): CSS build tooling referenced in tailwind/postcss config; not directly imported — expected. | ai | |
| phantom-deps | phantom-dep:postcss | AI (phantom-deps): Build tooling dep referenced in config files; not directly imported in source — expected pattern. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): TypeScript is a build-time tool referenced in tsconfig; phantom-dep false positive for this package. | ai |
Versions (showing 26 of 126)
| Version | Deps | Published |
|---|---|---|
| 0.2.7 | 31 / 6 | |
| 0.2.6 | 31 / 6 | |
| 0.2.5 | 31 / 6 | |
| 0.2.4 | 31 / 6 | |
| 0.2.3 | 31 / 6 | |
| 0.2.2 | 31 / 6 | |
| 0.2.1 | 31 / 6 | |
| 0.2.0 | 30 / 6 | |
| 0.1.26 | 30 / 6 | |
| 0.1.25 | 30 / 6 | |
| 0.1.24 | 30 / 6 | |
| 0.1.23 | 30 / 6 | |
| 0.1.22 | 30 / 6 | |
| 0.1.21 | 30 / 6 | |
| 0.1.20 | 30 / 6 | |
| 0.1.19 | 30 / 6 | |
| 0.1.18 | 30 / 6 | |
| 0.1.17 | 25 / 9 | |
| 0.1.16 | 25 / 9 | |
| 0.1.15 | 25 / 9 | |
| 0.1.14 | 25 / 9 | |
| 0.1.13 | 25 / 9 | |
| 0.1.12 | 25 / 9 | |
| 0.1.11 | 25 / 9 | |
| 0.1.10 | 15 / 9 | |
| 0.1.9 | 13 / 9 |