@viz-js/viz
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:lib/viz-standalone.js | AI (source-diff): Emscripten-compiled WebAssembly bundle; long encoded strings are inherent to this package's build output. | ai | |
| source-diff | encoded-string-file:lib/viz-standalone.mjs | AI (source-diff): Same Emscripten bundle in ESM format; false positive for this package. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): @viz-js/viz is the canonical Graphviz WASM wrapper, not a typosquat of vite; Levenshtein match is coincidental. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 3.27.0 | 0 / 9 | |
| 3.26.0 | 0 / 9 | |
| 3.14.0 | 0 / 9 | |
| 3.13.0 | 0 / 9 |
v3.27.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.26.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.14.0
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.13.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.