← Home

@powerlines/plugin-env

A package containing a Powerlines plugin for injecting static .env configuration values to the code so that they're accessible at runtime.

100
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

stormie-botsullivanpj

Keywords

dotenvpowerlinesstorm-softwarepowerlines-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Size increase fully explained by inlinedDependencies bundling pattern documented in package.json. ai
source-diff large-new-source-files AI (source-diff): New files are inlined dependency bundles explicitly declared in package.json inlinedDependencies. ai
source-diff obfuscated-file:dist/load-DPB0maqs.cjs AI (source-diff): Bundled dotenv and other known deps; readable structure, hashed chunk filename is normal vite output. ai
source-diff obfuscated-file:dist/json5-DEV_07Nb.cjs AI (source-diff): Bundled confbox/json5 dependency with long unicode regex lines; not obfuscated, just minified. ai
source-diff obfuscated-file:dist/dist-C_a6goTt.cjs AI (source-diff): Standard rollup/vite bundle chunk with hashed filename; code is readable and references known deps. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/json5.cjs AI (source-diff): Minified vendored dependency (confbox) bundled into dist/node_modules via pnpm; not malicious obfuscation. ai
phantom-deps phantom-dep:@alloy-js/markdown AI (phantom-deps): Config-referenced dep in monorepo plugin; stable false positive for this package. ai
provenance publisher-changed AI (provenance): stormie-bot is the org's established bot account with 2775 approved packages; transition from GH Actions to this account is expected org automation pattern. ai
phantom-deps phantom-dep:@powerlines/core AI (phantom-deps): Same org scope; likely loaded by convention or peer dependency pattern, stable false positive for this package. ai
source-diff obfuscated-file:dist/types/env.cjs AI (source-diff): Minified but fully readable build output for a new package export; no obfuscation or malicious patterns. ai
source-diff obfuscated-file:dist/types/env.mjs AI (source-diff): Same as .cjs counterpart — minified ESM build output, content is benign env variable metadata. ai
dependencies unvetted-dep:@powerlines/alloy AI (dependencies): @powerlines/alloy is a sibling package in the same org scope, published by the same Storm Software maintainer with 356 approved packages. Internal org dependency, not a third-party unknown. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs AI (source-diff): Minified bundle of the legitimate jiti package included via rolldown bundling of pnpm deps. SLSA provenance attestation confirms CI build integrity. No malicious patterns in sample. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs AI (source-diff): Minified bundle of json5 parser from confbox package. Long line is a Unicode regex for JSON5 parsing — entirely benign. SLSA provenance confirms build integrity. ai
source-diff obfuscated-file:dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs AI (source-diff): Minified bundle of node-fetch-native proxy module using standard Node.js built-ins. No suspicious network calls or exfiltration. SLSA provenance confirms build integrity. ai
phantom-deps phantom-dep:@storm-software/config-tools AI (phantom-deps): Config tooling from the same org ecosystem; loaded by convention/config, stable false positive. ai
phantom-deps phantom-dep:@stryke/fs AI (phantom-deps): Part of the @powerlines monorepo ecosystem; phantom deps are expected for plugin packages loaded by convention or config, not direct import. ai
phantom-deps phantom-dep:powerlines AI (phantom-deps): Core peer dependency of the @powerlines plugin ecosystem; loaded by convention, not direct import. ai
phantom-deps phantom-dep:@babel/core AI (phantom-deps): Framework-scoped package loaded by convention in Babel plugin ecosystems; stable false positive for this package. ai
phantom-deps phantom-dep:@stryke/env AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. ai
phantom-deps phantom-dep:@stryke/capnp AI (phantom-deps): Same monorepo org dependency loaded by config/convention; stable false positive for this plugin package. ai
phantom-deps phantom-dep:@stryke/types AI (phantom-deps): Type-only dependency from same org; not directly imported at runtime but declared for type resolution. ai
phantom-deps phantom-dep:@alloy-js/core AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. ai
phantom-deps phantom-dep:@powerlines/alloy AI (phantom-deps): Same-org package from the @powerlines monorepo; loaded by plugin convention, not direct import. ai
phantom-deps phantom-dep:@stryke/type-checks AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. ai
phantom-deps phantom-dep:@alloy-js/typescript AI (phantom-deps): Framework-scoped package used via config/convention in the alloy-js ecosystem; stable false positive. ai
phantom-deps phantom-dep:@stryke/string-format AI (phantom-deps): Same monorepo org utility package; loaded by config/convention, stable false positive. ai
phantom-deps phantom-dep:@powerlines/plugin-babel AI (phantom-deps): Same-org plugin package from the @powerlines monorepo; loaded by plugin convention, not direct import. ai
phantom-deps phantom-dep:@babel/types AI (phantom-deps): Framework-scoped package loaded by convention via @babel/core; stable pattern for Babel plugins. ai
phantom-deps phantom-dep:@powerlines/plugin-plugin AI (phantom-deps): Same-org scoped package loaded by convention in plugin ecosystem; stable for this package. ai
phantom-deps phantom-dep:@alloy-js/json AI (phantom-deps): Config-file referenced dependency; legitimate pattern in code generation frameworks. ai
phantom-deps phantom-dep:@stryke/json AI (phantom-deps): Config-file referenced dependency; legitimate pattern in config-driven tooling. ai

Versions (showing 100 of 554)

Version Deps Published
0.16.109 26 / 2
0.16.108 24 / 4
0.16.107 24 / 4
0.16.106 24 / 4
0.16.105 24 / 4
0.16.104 24 / 4
0.16.103 24 / 4
0.16.102 24 / 4
0.16.101 24 / 4
0.16.100 24 / 4
0.16.99 24 / 4
0.16.98 24 / 4
0.16.97 24 / 4
0.16.96 24 / 4
0.16.95 24 / 4
0.16.94 24 / 4
0.16.93 24 / 4
0.16.92 24 / 4
0.16.91 24 / 4
0.16.90 24 / 4
0.16.89 24 / 4
0.16.88 24 / 4
0.16.87 24 / 4
0.16.86 24 / 4
0.16.83 24 / 4
0.16.82 24 / 4
0.16.81 24 / 4
0.16.80 24 / 4
0.16.79 24 / 4
0.16.76 24 / 4
0.16.75 24 / 4
0.16.74 24 / 4
0.16.73 24 / 4
0.16.72 24 / 4
0.16.71 24 / 4
0.16.70 24 / 4
0.16.69 24 / 4
0.16.68 24 / 4
0.16.64 23 / 4
0.16.62 23 / 4
0.16.60 20 / 4
0.16.59 20 / 4
0.16.58 20 / 4
0.16.57 20 / 4
0.16.56 20 / 4
0.16.55 20 / 4
0.16.53 20 / 4
0.16.52 20 / 4
0.16.51 20 / 4
0.16.50 20 / 4
0.16.49 20 / 4
0.16.48 20 / 4
0.16.47 20 / 4
0.16.46 20 / 4
0.16.45 20 / 4
0.16.44 20 / 4
0.16.42 20 / 4
0.16.41 20 / 4
0.16.40 20 / 4
0.16.39 20 / 4
0.16.38 20 / 4
0.16.37 20 / 4
0.16.36 20 / 4
0.16.35 20 / 4
0.16.34 20 / 4
0.16.33 20 / 4
0.16.32 20 / 4
0.16.31 20 / 4
0.16.30 20 / 4
0.16.29 20 / 4
0.16.28 20 / 4
0.16.27 20 / 4
0.16.26 20 / 4
0.16.25 20 / 4
0.16.24 20 / 4
0.16.23 20 / 4
0.16.22 20 / 4
0.16.21 20 / 4
0.16.20 20 / 4
0.16.19 20 / 4
0.16.18 20 / 4
0.16.17 20 / 4
0.16.16 20 / 4
0.16.15 20 / 4
0.16.14 20 / 4
0.16.13 20 / 4
0.16.12 20 / 4
0.16.11 20 / 4
0.16.10 20 / 4
0.16.9 20 / 4
0.16.8 20 / 4
0.16.7 20 / 4
0.16.6 20 / 4
0.16.5 20 / 4
0.16.4 20 / 4
0.16.3 20 / 4
0.16.2 20 / 4
0.16.1 20 / 4
0.16.0 20 / 4
0.15.205 20 / 4
Showing 100 of 554 Next page →

v0.16.100

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.99

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.98

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.97

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.96

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.95

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.94

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.93

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.92

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.91

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.90

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.89

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.88

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.86

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.83

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.82

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.81

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.80

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.79

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.76

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.75

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.74

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.70

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.69

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.62

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.60

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.57

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.52

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.50

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.47

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.11

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.10

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.9

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.8

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.7

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.6

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.5

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.4

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.3

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.2

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.1

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.0

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.205

4 findings
HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/jiti/dist/jiti.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/confbox/dist/_chunks/libs/json5.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node_modules/.pnpm/[email protected]/node_modules/node-fetch-native/dist/proxy.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.