@abi-software/mapintegratedvuer
This project aims to provide an application to visually navigate anatomical entities to discover functional and physiological datasets from organ-specific neural circuitry.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/index-CMkLXnxB.js | AI (source-diff): Bundled vue/pinia app code, no evidence of dropper/loader behavior. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-mlgJKWSV.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CMkLXnxB.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-raNlNgsS.js | AI (source-diff): Bundled app code with normal fetch/dynamic-import, no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/index-raNlNgsS.js | AI (source-diff): Vite/Rollup bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-R9Bw7Ou4.js | AI (source-diff): Vite/Rollup bundled build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-Djmb_gqk.js | AI (source-diff): Vite bundle output, long minified lines flagged as obfuscation false positive. | ai | |
| source-diff | net-exec-file:dist/index-CwfUgFL1.js | AI (source-diff): Bundled Vue/pinia app code, not a dropper; standard build artifact. | ai | |
| source-diff | obfuscated-file:dist/index-CwfUgFL1.js | AI (source-diff): Vite bundle output, long minified lines flagged as obfuscation false positive. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-C3-OeGQ0.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CGSECPAp.js | AI (source-diff): Bundled Vue app code, no actual dropper/loader behavior present. | ai | |
| source-diff | obfuscated-file:dist/index-CGSECPAp.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-RE4Jc7WG.js | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation; matches Vue component library build pattern. | ai | |
| source-diff | obfuscated-file:dist/index-E1q0fbBZ.js | AI (source-diff): Bundled Vite/Rollup output, not true obfuscation; matches Vue component library build pattern. | ai | |
| source-diff | net-exec-file:dist/index-E1q0fbBZ.js | AI (source-diff): Bundled Vue/Pinia app code; no fetched-binary or credential-exfil behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/index-C753e18_.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-DiDiS2Ct.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-C753e18_.js | AI (source-diff): Bundled vendor code (vue/pinia); no concrete malicious network+exec behavior found. | ai | |
| phantom-deps | phantom-dep:@esbuild/darwin-arm64 | AI (phantom-deps): Platform-specific optional binary for esbuild, expected phantom dep. | ai | |
| source-diff | net-exec-file:dist/index-CsTb2Qef.js | AI (source-diff): Bundled Vue/Pinia app code triggers heuristic; no fetched-binary or exfil behavior present. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-B-51garm.js | AI (source-diff): Minified Vite bundle chunk, not true obfuscation; standard build output for this package. | ai | |
| source-diff | obfuscated-file:dist/index-CsTb2Qef.js | AI (source-diff): Minified Vite bundle chunk, not true obfuscation; standard build output for this package. | ai | |
| source-diff | net-exec-file:dist/index-DfylWmCz.js | AI (source-diff): Standard Vue app bundle; network+eval patterns are framework code, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/index-DfylWmCz.js | AI (source-diff): Vite/rollup bundled output, not true obfuscation; long lines are minification. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-CNjL9TTP.js | AI (source-diff): Vite/rollup bundled output, not true obfuscation; long lines are minification. | ai | |
| source-diff | obfuscated-file:dist/index-DOdcCNMv.js | AI (source-diff): Bundled Vite output, not true obfuscation; source is readable Vue/Pinia code. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-Ce5ybiWA.js | AI (source-diff): Bundled Vite output, not true obfuscation; source is readable Vue/Pinia code. | ai | |
| source-diff | net-exec-file:dist/index-DOdcCNMv.js | AI (source-diff): Bundle contains generic app code, not dropper/loader behavior aimed at unrelated destination. | ai | |
| source-diff | obfuscated-file:dist/index-8DUKRP2u.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-D8QXfBlf.js | AI (source-diff): Vite/Rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-8DUKRP2u.js | AI (source-diff): Bundled vue/pinia app code, no actual dropper behavior found. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-DdcqAvf4.js | AI (source-diff): Bundled vite/rollup build output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Dop9gDcW.js | AI (source-diff): Bundled Vue/Pinia app code; no evidence of dropper/loader behavior. | ai | |
| source-diff | obfuscated-file:dist/index-Dop9gDcW.js | AI (source-diff): Bundled vite/rollup build output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-CcgzsE03.js | AI (source-diff): Vite/rollup bundled output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-CAQ1PsC2.js | AI (source-diff): Vite/rollup bundled output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-CcgzsE03.js | AI (source-diff): Bundled Vue app code, no dropper/loader behavior present. | ai | |
| source-diff | net-exec-file:dist/index-o_HxI1zc.js | AI (source-diff): Network calls and dynamic code in a Vue UI library bundle are expected; no dropper/loader patterns visible in samples. | ai | |
| source-diff | obfuscated-file:dist/ContentMixin-CLr2YdhY.js | AI (source-diff): Standard Vite build output for this Vue component library; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-o_HxI1zc.js | AI (source-diff): Standard Vite bundle; samples show normal Vue/Pinia imports with no malicious patterns. | ai | |
| phantom-deps | phantom-dep:xss | AI (phantom-deps): Likely used in bundled Vue SFCs; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:marked | AI (phantom-deps): Likely used in bundled Vue SFCs; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@abi-software/sparc-annotation | AI (phantom-deps): Same-org dep used in bundled components; stable FP. | ai | |
| phantom-deps | phantom-dep:@abi-software/map-side-bar | AI (phantom-deps): Same-org dep used in bundled components; stable FP. | ai | |
| phantom-deps | phantom-dep:@abi-software/svg-sprite | AI (phantom-deps): Same-org dep used in bundled components; stable FP. | ai | |
| phantom-deps | phantom-dep:css-element-queries | AI (phantom-deps): Likely used in bundled Vue SFCs; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:splitpanes | AI (phantom-deps): Likely used in bundled Vue SFCs; stable false positive for this package. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 1.19.0 | 19 / 31 | |
| 1.18.4 | 19 / 31 | |
| 1.18.3 | 19 / 31 | |
| 1.18.2 | 19 / 31 | |
| 1.18.1 | 19 / 31 | |
| 1.18.0 | 19 / 31 | |
| 1.17.4 | 19 / 31 | |
| 1.17.3 | 19 / 31 | |
| 1.17.2 | 19 / 31 | |
| 1.17.1 | 19 / 31 | |
| 1.17.0 | 19 / 31 | |
| 1.16.3 | 20 / 31 | |
| 1.16.2 | 20 / 31 | |
| 1.16.1 | 20 / 31 | |
| 1.15.1 | 20 / 31 | |
| 1.15.0 | 20 / 31 | |
| 1.14.1 | 19 / 31 | |
| 1.14.0 | 19 / 31 |
v1.19.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.15.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.