@docmentis/udoc-viewer
Universal document viewer for the web — open-source, framework-agnostic viewer powered by a built-from-scratch WebAssembly engine for high-fidelity rendering across PDF, DOCX, PPTX, SVG, and images.
51
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
xeranic
Keywords
viewerpdfpdf-viewerdocxdocx-viewerpptxpptx-viewerxlsxxlsx-viewercsvcsv-viewersvgsvg-viewerimageimage-viewerdocumentdocument-viewerofficeoffice-viewerwordpowerpointwasmwebassembly
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/src/ui/viewer/components/Branding.js | AI (source-diff): Long lines are minified SVG/CSS in a documented branding component; not malicious obfuscation. Stable for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions publisher is backed by SLSA provenance attestation, indicating legitimate CI/CD automation. | ai | |
| source-diff | obfuscated-file:dist/src/ui/viewer/components/LoadingOverlay.js | AI (source-diff): Sample shows readable, well-commented UI component code; long lines are from inline SVG/styles, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/ui/viewer/styles-inline.d.ts | AI (source-diff): File is a .d.ts exporting inlined CSS as a string literal; long lines are CSS content, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/src/wasm/udoc.js | AI (source-diff): Standard wasm-bindgen JS glue file; network+exec pattern is inherent to WASM module loading, not malware. | ai | |
| source-diff | obfuscated-file:dist/styles-inline.d.ts | AI (source-diff): Long line is an inlined CSS string in a .d.ts file, generated by build-styles.js; not obfuscation. | ai |
Versions (showing 51 of 54)
| Version | Deps | Published |
|---|---|---|
| 0.7.6 | 0 / 7 | |
| 0.7.5 | 0 / 7 | |
| 0.7.4 | 0 / 7 | |
| 0.7.3 | 0 / 7 | |
| 0.7.2 | 0 / 7 | |
| 0.7.1 | 0 / 7 | |
| 0.7.0 | 0 / 7 | |
| 0.6.43 | 0 / 7 | |
| 0.6.42 | 0 / 7 | |
| 0.6.41 | 0 / 3 | |
| 0.6.40 | 0 / 3 | |
| 0.6.39 | 0 / 3 | |
| 0.6.38 | 0 / 3 | |
| 0.6.37 | 0 / 3 | |
| 0.6.36 | 0 / 3 | |
| 0.6.35 | 0 / 3 | |
| 0.6.34 | 0 / 3 | |
| 0.6.33 | 0 / 3 | |
| 0.6.32 | 0 / 3 | |
| 0.6.31 | 0 / 3 | |
| 0.6.30 | 0 / 3 | |
| 0.6.29 | 0 / 3 | |
| 0.6.28 | 0 / 3 | |
| 0.6.27 | 0 / 3 | |
| 0.6.26 | 0 / 3 | |
| 0.6.25 | 0 / 3 | |
| 0.6.24 | 0 / 3 | |
| 0.6.23 | 0 / 3 | |
| 0.6.22 | 0 / 3 | |
| 0.6.21 | 0 / 3 | |
| 0.6.20 | 0 / 3 | |
| 0.6.19 | 0 / 3 | |
| 0.5.3 | 0 / 1 | |
| 0.2.13 | 0 / 1 | |
| 0.2.12 | 0 / 1 | |
| 0.2.11 | 0 / 1 | |
| 0.2.10 | 0 / 1 | |
| 0.2.9 | 0 / 1 | |
| 0.2.8 | 0 / 1 | |
| 0.2.7 | 0 / 1 | |
| 0.2.6 | 0 / 1 | |
| 0.2.5 | 0 / 1 | |
| 0.2.4 | 0 / 1 | |
| 0.2.3 | 0 / 1 | |
| 0.2.2 | 0 / 1 | |
| 0.2.1 | 0 / 1 | |
| 0.2.0 | 0 / 1 | |
| 0.1.7 | 0 / 1 | |
| 0.1.6 | 0 / 1 | |
| 0.1.5 | 0 / 1 | |
| 0.1.4 | 0 / 1 |
v0.7.6
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.5
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.7.4
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.