@aguspe/tiler-viewer
18
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
aguspe
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/client/viewer-DqTY1Mf2.js | AI (source-diff): Standard Vite minified bundle with accompanying source map; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/viewer-DqTY1Mf2.js | AI (source-diff): Network call is a Google Fonts CSS import; dynamic execution is normal browser JS bundle behavior. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-CgOEJB-o.js | AI (source-diff): Vite-bundled React client output; minification is expected for this package's build process. | ai | |
| source-diff | net-exec-file:dist/client/viewer-CgOEJB-o.js | AI (source-diff): Network+exec pattern in a React browser bundle is standard (fetch + dynamic imports); not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/client/viewer-338qH44f.js | AI (source-diff): Bundled React viewer; network+exec pattern is normal for client-side SPA code. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-338qH44f.js | AI (source-diff): Vite-bundled client JS with source map; minification is expected for this package. | ai | |
| source-diff | net-exec-file:dist/client/viewer-CaS_s40N.js | AI (source-diff): Network call is a Google Fonts CSS import in a browser bundle; no dynamic code execution of remote content. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-CaS_s40N.js | AI (source-diff): Standard Vite-minified client bundle for a React app; source map is included and content is benign CSS/UI code. | ai | |
| source-diff | net-exec-file:dist/client/viewer-BolslLtr.js | AI (source-diff): Network call is a Google Fonts CSS import from the bundler; no dynamic code execution present. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-BolslLtr.js | AI (source-diff): Standard Vite-minified client bundle with source map; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-BlW8xPdj.js | AI (source-diff): Vite-minified client bundle; content is CSS/UI code, not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/client/viewer-BlW8xPdj.js | AI (source-diff): Network reference is a Google Fonts stylesheet import in a browser bundle; no dynamic code execution pattern. | ai | |
| source-diff | net-exec-file:dist/client/viewer-CI7nZwbv.js | AI (source-diff): Network call is a Google Fonts CSS import; no dynamic code execution beyond normal React hydration. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-CI7nZwbv.js | AI (source-diff): Vite-minified client bundle for a React viewer; long lines are standard bundler output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/client/viewer-DXSIEC3U.js | AI (source-diff): Network call is Google Fonts CSS import; dynamic code is standard DOM/React hydration, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-DXSIEC3U.js | AI (source-diff): Vite-minified client bundle; long lines are CSS design tokens, not obfuscation. | ai | |
| phantom-deps | phantom-dep:@aguspe/tiler-widgets | AI (phantom-deps): Same-org dependency used transitively via bundled output; stable false positive for this package. | ai | |
| source-diff | net-exec-file:dist/client/viewer-oA3ShJCD.js | AI (source-diff): Network+exec pattern in React client bundle is expected for a browser-side viewer app; no dropper behavior present. | ai | |
| source-diff | obfuscated-file:dist/client/viewer-oA3ShJCD.js | AI (source-diff): Minified Vite/React production bundle; standard build artifact for this SSR viewer package. | ai |