@fjall/deploy-core
Shared deployment engine for Fjall — used by CLI and webapp worker
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src/orchestration/organisationDeploy/cascadeExecution.js | AI (source-diff): Package intentionally minifies dist output via minify-dist.mjs build step; content is legitimate AWS orchestration code. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sqs | AI (phantom-deps): AWS SDK clients are loaded by convention in this deployment engine; phantom-dep is a stable false positive. | ai | |
| source-diff | obfuscated-file:dist/src/aws/targetReadiness.js | AI (source-diff): Same minified build output pattern; content is AWS target readiness probing logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/organisationDeploy/orgCascadeDeploy.js | AI (source-diff): Same minified build output pattern; content is org-level CDK deploy orchestration. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/stackCleanup/failedStack.js | AI (source-diff): Same minified build output pattern; content is CloudFormation/S3 stack cleanup logic. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/trailMigration/trailMigration.js | AI (source-diff): Package intentionally minifies dist output via minify-dist.mjs build step; content is readable CloudTrail/KMS logic, not obfuscated malware. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-secrets-manager | AI (phantom-deps): Framework-scoped AWS SDK dep loaded by convention, consistent with other accepted phantom deps in this package. | ai | |
| source-diff | obfuscated-file:dist/src/services/infrastructure/EcsService.js | AI (source-diff): Same intentional minification; content is legitimate AWS ECS service wrapper code. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-ecr | AI (phantom-deps): AWS SDK clients are loaded by convention/factory pattern; consistent with other accepted phantom AWS SDK deps in this package. | ai | |
| source-diff | obfuscated-file:dist/src/orchestration/codeOnlyDeploy.js | AI (source-diff): Package intentionally minifies dist output via minify-dist.mjs build step; content is legitimate ECS orchestration code. | ai | |
| provenance | no-provenance | AI (provenance): Consistent across all @fjall/deploy-core versions; no provenance is the norm for this package family. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-s3 | AI (phantom-deps): AWS SDK packages loaded by convention in deployment engine; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:@aws-sdk/client-sts | AI (phantom-deps): AWS SDK packages loaded by convention in deployment engine; not directly imported but legitimately declared. | ai | |
| phantom-deps | phantom-dep:@smithy/node-http-handler | AI (phantom-deps): Smithy HTTP handler used as AWS SDK transport; convention-loaded, not directly imported. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 2.15.0 | 20 / 2 | |
| 2.14.0 | 20 / 2 | |
| 2.13.0 | 18 / 2 | |
| 2.12.0 | 16 / 2 | |
| 2.11.1 | 16 / 2 | |
| 2.9.1 | 15 / 2 | |
| 2.9.0 | 15 / 2 | |
| 2.8.0 | 15 / 2 | |
| 2.7.1 | 15 / 2 | |
| 2.7.0 | 15 / 2 | |
| 2.6.0 | 15 / 2 | |
| 2.5.0 | 15 / 2 | |
| 2.4.8 | 14 / 2 | |
| 2.4.7 | 14 / 2 | |
| 2.4.5 | 14 / 2 | |
| 2.4.4 | 14 / 2 | |
| 2.4.3 | 14 / 2 | |
| 2.4.2 | 14 / 2 | |
| 2.4.1 | 14 / 2 | |
| 2.4.0 | 14 / 2 | |
| 2.3.0 | 14 / 2 | |
| 2.2.0 | 14 / 2 | |
| 2.1.1 | 14 / 2 | |
| 1.1.0 | 14 / 2 | |
| 0.102.0 | 14 / 2 | |
| 0.100.0 | 14 / 2 | |
| 0.99.4 | 14 / 2 | |
| 0.99.3 | 14 / 2 | |
| 0.99.1 | 14 / 2 | |
| 0.96.0 | 13 / 1 | |
| 0.95.0 | 13 / 1 | |
| 0.94.1 | 13 / 1 | |
| 0.94.0 | 13 / 1 | |
| 0.89.6 | 13 / 1 | |
| 0.89.5 | 11 / 1 | |
| 0.89.4 | 11 / 1 | |
| 0.89.2 | 11 / 1 |
v2.15.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.0
2 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.5
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.102.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.100.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.99.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.99.3
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.99.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.96.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.89.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.89.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.89.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.