html-dom-parser
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/htmlparser2.js | AI (source-diff): Long encoded string is the htmlparser2 HTML entity decode trie (base64-packed lookup table), a stable legitimate pattern for this package. | ai | |
| source-diff | obfuscated-file:esm/node_modules/entities/dist/esm/generated/decode-data-html.mjs | AI (source-diff): Base64-encoded HTML entity decode table generated by entities package build scripts; not malicious. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase due to bundling htmlparser2 and entities deps into the package; expected for this build change. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are bundled dependency outputs (rollup build artifacts); not injected payloads. | ai | |
| source-diff | obfuscated-file:esm/node_modules/entities/dist/generated/decode-data-html.mjs | AI (source-diff): Known base64-encoded HTML decode trie from the entities package; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/htmlparser2.js | AI (source-diff): UMD bundle of htmlparser2 dep produced by rollup; long lines are minified but not malicious. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Base64 decode is part of htmlparser2 bundled utility for binary encoding; not a malicious payload pattern. | ai |
Versions (showing 9 of 9)
| Version | Deps | Published |
|---|---|---|
| 7.1.0 | 2 / 37 | |
| 7.0.1 | 2 / 37 | |
| 7.0.0 | 2 / 37 | |
| 6.0.0 | 2 / 37 | |
| 5.1.8 | 2 / 36 | |
| 5.1.7 | 2 / 42 | |
| 5.1.5 | 2 / 41 | |
| 5.1.4 | 2 / 41 | |
| 5.1.2 | 2 / 41 |
v7.1.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v7.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.0.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.7
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v5.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.