@barchart/chart-lib
Barchart HTML5 Streaming Chart
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside minified chart bundle; pattern is from date/timezone parsing, not dynamic code execution of external input. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get in minified bundle is a common bundler/transpiler artifact, not obfuscation for evasion. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Proprietary UNLICENSED compiled artifact; no repo/deps/keywords is expected for this distribution pattern. | ai |
Versions (showing 100 of 225)
| Version | Deps | Published |
|---|---|---|
| 2.386.8 | 0 / 0 | |
| 2.386.7 | 0 / 0 | |
| 2.386.6 | 0 / 0 | |
| 2.386.5 | 0 / 0 | |
| 2.386.3 | 0 / 0 | |
| 2.386.1 | 0 / 0 | |
| 2.386.0 | 0 / 0 | |
| 2.385.2 | 0 / 0 | |
| 2.385.1 | 0 / 0 | |
| 2.385.0 | 0 / 0 | |
| 2.384.3 | 0 / 0 | |
| 2.384.2 | 0 / 0 | |
| 2.384.1 | 0 / 0 | |
| 2.384.0 | 0 / 0 | |
| 2.383.1 | 0 / 0 | |
| 2.383.0 | 0 / 0 | |
| 2.382.2 | 0 / 0 | |
| 2.382.1 | 0 / 0 | |
| 2.382.0 | 0 / 0 | |
| 2.381.3 | 0 / 0 | |
| 2.381.2 | 0 / 0 | |
| 2.381.1 | 0 / 0 | |
| 2.381.0 | 0 / 0 | |
| 2.380.2 | 0 / 0 | |
| 2.380.0 | 0 / 0 | |
| 2.379.5 | 0 / 0 | |
| 2.379.4 | 0 / 0 | |
| 2.379.3 | 0 / 0 | |
| 2.379.2 | 0 / 0 | |
| 2.379.1 | 0 / 0 | |
| 2.379.0 | 0 / 0 | |
| 2.378.0 | 0 / 0 | |
| 2.377.6 | 0 / 0 | |
| 2.377.5 | 0 / 0 | |
| 2.377.4 | 0 / 0 | |
| 2.377.3 | 0 / 0 | |
| 2.377.2 | 0 / 0 | |
| 2.377.0 | 0 / 0 | |
| 2.376.6 | 0 / 0 | |
| 2.376.5 | 0 / 0 | |
| 2.376.4 | 0 / 0 | |
| 2.376.2 | 0 / 0 | |
| 2.376.1 | 0 / 0 | |
| 2.376.0 | 0 / 0 | |
| 2.375.1 | 0 / 0 | |
| 2.375.0 | 0 / 0 | |
| 2.374.5 | 0 / 0 | |
| 2.374.4 | 0 / 0 | |
| 2.374.2 | 0 / 0 | |
| 2.374.1 | 0 / 0 | |
| 2.374.0 | 0 / 0 | |
| 2.373.0 | 0 / 0 | |
| 2.372.17 | 0 / 0 | |
| 2.372.16 | 0 / 0 | |
| 2.372.15 | 0 / 0 | |
| 2.372.14 | 0 / 0 | |
| 2.372.13 | 0 / 0 | |
| 2.372.12 | 0 / 0 | |
| 2.372.11 | 0 / 0 | |
| 2.372.10 | 0 / 0 | |
| 2.372.9 | 0 / 0 | |
| 2.372.8 | 0 / 0 | |
| 2.372.7 | 0 / 0 | |
| 2.372.6 | 0 / 0 | |
| 2.372.5 | 0 / 0 | |
| 2.372.4 | 0 / 0 | |
| 2.372.3 | 0 / 0 | |
| 2.372.2 | 0 / 0 | |
| 2.372.1 | 0 / 0 | |
| 2.372.0 | 0 / 0 | |
| 2.371.3 | 0 / 0 | |
| 2.371.2 | 0 / 0 | |
| 2.371.1 | 0 / 0 | |
| 2.371.0 | 0 / 0 | |
| 2.370.1 | 0 / 0 | |
| 2.370.0 | 0 / 0 | |
| 2.369.1 | 0 / 0 | |
| 2.369.0 | 0 / 0 | |
| 2.368.1 | 0 / 0 | |
| 2.368.0 | 0 / 0 | |
| 2.367.6 | 0 / 0 | |
| 2.367.4 | 0 / 0 | |
| 2.367.0 | 0 / 0 | |
| 2.366.1 | 0 / 0 | |
| 2.366.0 | 0 / 0 | |
| 2.365.2 | 0 / 0 | |
| 2.365.1 | 0 / 0 | |
| 2.365.0 | 0 / 0 | |
| 2.364.0 | 0 / 0 | |
| 2.363.0 | 0 / 0 | |
| 2.362.4 | 0 / 0 | |
| 2.362.3 | 0 / 0 | |
| 2.362.2 | 0 / 0 | |
| 2.362.1 | 0 / 0 | |
| 2.362.0 | 0 / 0 | |
| 2.361.8 | 0 / 0 | |
| 2.361.7 | 0 / 0 | |
| 2.361.6 | 0 / 0 | |
| 2.361.5 | 0 / 0 | |
| 2.361.4 | 0 / 0 |
v2.386.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.386.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.386.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.386.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.386.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.386.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.386.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.385.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.385.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.385.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.384.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.384.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.384.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.384.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.383.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.383.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.382.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.382.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.382.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.381.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.381.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.381.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.380.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.380.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.379.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.379.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.379.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.379.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.379.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.378.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.377.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.377.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.377.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.377.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.377.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.377.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.376.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.376.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.376.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.376.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.376.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.376.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.375.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.375.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.374.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.374.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.374.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.374.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.374.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.373.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.372.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.372.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.372.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.372.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.371.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.371.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.371.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.371.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.370.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.370.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.369.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.369.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.368.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.368.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.367.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.367.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.367.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.366.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.366.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.365.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.365.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.365.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.364.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.363.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.362.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.362.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.362.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.362.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.362.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.361.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.361.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.361.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.361.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.361.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.