@ambita/infoland-component-library
Component library with models, views, and API services, for Vue and Riot.js (with Vue wrappers)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/ambita-map-FQmVi3_7.js | AI (source-diff): Map library bundle naturally contains network calls + dynamic code, no exfil target. | ai | |
| source-diff | obfuscated-file:dist/ambita-map-FQmVi3_7.js | AI (source-diff): Bundled third-party map SDK output, not true obfuscation. | ai | |
| dependencies | unvetted-dep:@ambita/design-system-icons | AI (dependencies): Same-org scoped dependency matching package's stated purpose. | ai | |
| source-diff | obfuscated-file:dist/ambita-map-BAnnvvRe.js | AI (source-diff): Minified bundler output, no true obfuscation signature. | ai | |
| dependencies | unvetted-dep:@ambita/ambita-map | AI (dependencies): Same-org scoped dependency matching package's stated Vue/Riot component scope. | ai | |
| source-diff | net-exec-file:dist/ambita-map-BAnnvvRe.js | AI (source-diff): Bundled Vite/Rollup output for a same-org map component, not a loader/dropper. | ai | |
| source-diff | obfuscated-file:dist/ambita-map-DoCXd_Zc.js | AI (source-diff): Standard vite/rollup minified bundle output; no obfuscation signatures present. | ai | |
| source-diff | obfuscated-file:dist/riot/infoland-riot.js | AI (source-diff): Standard vite/rollup minified bundle output for Riot.js build target. | ai | |
| source-diff | net-exec-file:dist/ambita-map-DoCXd_Zc.js | AI (source-diff): Network calls are map tile/API fetches; dynamic code execution is bundler async iterator polyfill pattern, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/ambita-map-B70VQZHK.js | AI (source-diff): Minified Vite bundle for map component; long lines are bundler output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/riot/infoland-riot.umd.cjs | AI (source-diff): Standard Vite UMD bundle for Riot.js target; network calls are component API calls, not dropper behavior. | ai | |
| source-diff | net-exec-file:dist/ambita-map-B70VQZHK.js | AI (source-diff): Same-org map component bundle; no hostile network destination or code injection pattern. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package added Riot.js build target and map component; large file count increase is expected. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase explained by new Riot build target and 1.8MB map bundle. | ai | |
| source-diff | net-exec-file:dist/ambita-map-CBW7-CQn.js | AI (source-diff): Map component bundles legitimately include fetch/XHR for tile/data loading and dynamic module patterns; no dropper indicators in sample. | ai | |
| source-diff | obfuscated-file:dist/ambita-map-CBW7-CQn.js | AI (source-diff): Standard Vite minified bundle for a map component; long lines are normal bundler output, not intentional obfuscation. | ai | |
| phantom-deps | phantom-dep:@vue/reactivity | AI (phantom-deps): Framework-scoped package loaded by convention in Vue 3 ecosystem; stable false positive. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): Referenced in config files as documented; stable false positive for this component library. | ai | |
| phantom-deps | phantom-dep:@ambita/design-system-icons | AI (phantom-deps): Same-org dependency; bundled into dist output rather than directly imported in source. | ai | |
| phantom-deps | phantom-dep:@ambita/ambita-map | AI (phantom-deps): Same-org dependency; bundled into dist output rather than directly imported in source. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 1.3.4 | 6 / 21 | |
| 1.1.0 | 5 / 33 | |
| 1.0.7 | 5 / 33 | |
| 1.0.6 | 5 / 33 | |
| 1.0.4 | 5 / 35 | |
| 1.0.3 | 5 / 30 | |
| 1.0.2 | 5 / 30 | |
| 0.0.26 | 5 / 23 | |
| 0.0.25 | 5 / 23 | |
| 0.0.23 | 5 / 23 | |
| 0.0.20 | 6 / 23 | |
| 0.0.19 | 5 / 23 | |
| 0.0.13 | 6 / 22 | |
| 0.0.10 | 6 / 22 | |
| 0.0.8 | 6 / 22 | |
| 0.0.5 | 2 / 15 |
v1.3.4
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.13
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.10
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.8
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.