html2canvas
1
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
niklasvh
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:css-line-break | AI (dependencies): css-line-break is a legitimate utility authored by niklasvh (same author as html2canvas) for CSS text line-breaking logic; stable dependency across versions. | ai | |
| dependencies | unvetted-dep:text-segmentation | AI (dependencies): text-segmentation is a legitimate utility authored by niklasvh (same author as html2canvas) for Unicode text segmentation; stable dependency across versions. | ai | |
| provenance | no-provenance | AI (provenance): html2canvas is a long-established package (4115 days old); lack of Sigstore provenance is common and not a meaningful risk signal here. | ai |
Versions (showing 1 of 1)
| Version | Deps | Published |
|---|---|---|
| 1.4.1 | 2 / 72 |
v1.4.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.