Panter cli tool for cloud CI/CD and DevOps
The project worktime CLI command downloads an unpinned response from a shortened URL and executes it as Bash. The remote destination can change the code run under the invoking user's permissions.
Package contains a possible secret pattern.
dist/packages/pipeline/src/backends/github/githubReleaseJobs.jsView on unpkg · L41Hardcoded password in dist/packages/pipeline/src/backends/github/githubReleaseJobs.js
dist/packages/pipeline/src/backends/github/githubReleaseJobs.jsView on unpkg · L247Package source references child process execution.
dist/packages/pipeline/src/pipeline/detectPackageManager.jsView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/bundles/catci/index.jsView on unpkg · L1Package source references dynamic code evaluation.
dist/bundles/catci/index.jsView on unpkg · L24A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundles/catci/index.jsView on unpkg · L1Package source references dynamic require/import behavior.
dist/packages/pipeline/src/pipeline/projectFiles.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
dist/apps/cli/src/completion.jsView on unpkg · L189Source downloads or fetches remote code and executes it.
src/commands/project/commandGetMyTotalWorktime.tsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/apps/cli/src/release/releaseEntry.jsView on unpkg · L15Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundles/catenv/index.jsView on unpkg · L19745Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/bundles/catenv/index.jsView on unpkg · L66Package source invokes a package manager install command at runtime.
dist/apps/cli/src/commands/project/commandOpenGit.jsView on unpkg · L11Package ships high-entropy non-source blobs.
dist/runner-images/kubernetes/helm-charts/the-panter-chart/charts/mailhog-5.0.1.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/runner-images/kubernetes/helm-charts/the-panter-chart/charts/mailhog-5.0.1.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/runner-images/kubernetes/helm-charts/the-panter-chart/charts/mailhog-5.0.1.tgzPackage contains source files above the normal full-analysis size ceiling.
dist/bundles/cli/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/apps/cli/src/release/changesetCheckJob.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/publish/npmPublishJob.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/release/releaseGit.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/apps/cli/commands/mongodb/utils/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/commands/project/commandGetMyTotalWorktime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/commands/project/k8s/commandDeleteProject.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/commands/project/k8s/commandPauseProject.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/git/gitProjectInformation.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/release/changesetCheckJob.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/utils/getEditor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/utils/portForwards.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/utils/shell.jsView on unpkgHardcoded password in dist/packages/pipeline/src/backends/github/createGithubJobs.js
dist/packages/pipeline/src/backends/github/createGithubJobs.jsView on unpkg · L345Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundles/catci/index.jsView on unpkg · L1Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundles/catenv/index.jsView on unpkgPackage contains a possible secret pattern.
dist/packages/pipeline/src/backends/github/githubReleaseJobs.jsView on unpkg · L41Hardcoded password in dist/packages/pipeline/src/backends/github/githubReleaseJobs.js
dist/packages/pipeline/src/backends/github/githubReleaseJobs.jsView on unpkg · L247Source downloads or fetches remote code and executes it.
src/commands/project/commandGetMyTotalWorktime.tsView on unpkg · L9Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
dist/apps/cli/src/release/releaseEntry.jsView on unpkg · L15Source contains an obfuscated payload loader that reconstructs and executes hidden code.
dist/bundles/catenv/index.jsView on unpkg · L19745Source spawns a local helper that also contains network and dynamic execution context; review data flow before blocking.
dist/bundles/catenv/index.jsView on unpkg · L66Package source invokes a package manager install command at runtime.
dist/apps/cli/src/commands/project/commandOpenGit.jsView on unpkg · L11Package ships high-entropy non-source blobs.
dist/runner-images/kubernetes/helm-charts/the-panter-chart/charts/mailhog-5.0.1.tgzView on unpkgPackage ships compressed or archive-like blobs.
dist/runner-images/kubernetes/helm-charts/the-panter-chart/charts/mailhog-5.0.1.tgzView on unpkgPackage ships a nested archive or MCP bundle that was inventoried but not recursively analyzed.
dist/runner-images/kubernetes/helm-charts/the-panter-chart/charts/mailhog-5.0.1.tgzPackage contains source files above the normal full-analysis size ceiling.
dist/bundles/cli/index.jsView on unpkgA bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
dist/apps/cli/src/release/changesetCheckJob.js#virtual:normalized:round1View on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/publish/npmPublishJob.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/release/releaseGit.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/apps/cli/commands/mongodb/utils/index.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/commands/project/commandGetMyTotalWorktime.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/commands/project/k8s/commandDeleteProject.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/commands/project/k8s/commandPauseProject.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/git/gitProjectInformation.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/release/changesetCheckJob.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/utils/getEditor.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/utils/portForwards.jsView on unpkgSource file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/apps/cli/src/utils/shell.jsView on unpkgHardcoded password in dist/packages/pipeline/src/backends/github/createGithubJobs.js
dist/packages/pipeline/src/backends/github/createGithubJobs.jsView on unpkg · L345Package source references child process execution.
dist/packages/pipeline/src/pipeline/detectPackageManager.jsView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/bundles/catci/index.jsView on unpkg · L1A single source file combines environment access, network access, and code or shell execution; review context before blocking.
dist/bundles/catci/index.jsView on unpkg · L1Source combines command execution, command-output handling, and outbound requests; review data flow before blocking.
dist/bundles/catci/index.jsView on unpkg · L1Package source references dynamic code evaluation.
dist/bundles/catci/index.jsView on unpkg · L24Package source references dynamic require/import behavior.
dist/packages/pipeline/src/pipeline/projectFiles.jsView on unpkg · L3Source writes installer persistence such as shell profile or service configuration.
dist/apps/cli/src/completion.jsView on unpkg · L189Source file is highly similar to a previously finalized malicious package; route for source-aware review.
dist/bundles/catenv/index.jsView on unpkg