@embedpdf/snippet
<div align="center"> <a href="https://www.embedpdf.com"> <img alt="EmbedPDF logo" src="https://www.embedpdf.com/logo-192.png" height="96"> </a>
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/worker-engine-BkD2-rJn.js | AI (source-diff): WASM worker loader, benign. | ai | |
| source-diff | net-exec-file:dist/direct-engine-BA2WfEti.js | AI (source-diff): WASM loader fetch+instantiate, not a dropper. | ai | |
| source-diff | obfuscated-file:dist/browser-BKLM0ThC-CkSOgtCM.js | AI (source-diff): Minified task-queue bundle. | ai | |
| source-diff | obfuscated-file:dist/worker-engine-BkD2-rJn.js | AI (source-diff): Minified WASM worker engine bundle. | ai | |
| source-diff | obfuscated-file:dist/embedpdf-7TNsu-EA.js | AI (source-diff): Minified Rollup/terser bundle, not obfuscation; stable build output. | ai | |
| source-diff | obfuscated-file:dist/direct-engine-BA2WfEti.js | AI (source-diff): Minified pdfium WASM engine bundle. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): pdfium.wasm is the package's core PDF rendering engine; expected artifact. | ai | |
| phantom-deps | phantom-dep:@embedpdf/engines | AI (phantom-deps): Same-org scoped dep, likely re-exported/config-referenced; stable FP. | ai | |
| source-diff | obfuscated-file:dist/worker-engine-Bavu2VBD.js | AI (source-diff): Minified WebWorker bundle for PDF rendering; expected build artifact. | ai | |
| source-diff | obfuscated-file:dist/embedpdf-DM0Wgh5n.js | AI (source-diff): Standard Rollup minified bundle for a PDF viewer library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/browser-BKLM0ThC-BV1_qgB9.js | AI (source-diff): Standard Rollup minified bundle; content is legitimate task-queue/PDF viewer code. | ai | |
| source-diff | obfuscated-file:dist/direct-engine-B8Y1coUd.js | AI (source-diff): Minified WASM engine bundle with EPDF API symbols; expected build artifact. | ai | |
| source-diff | net-exec-file:dist/direct-engine-B8Y1coUd.js | AI (source-diff): Network calls are WASM binary fetches; dynamic execution is WASM instantiation — standard pattern for pdfium WASM engine. | ai | |
| source-diff | net-exec-file:dist/worker-engine-Bavu2VBD.js | AI (source-diff): WebWorker postMessage + WASM init pattern; not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/browser-BKLM0ThC-DR-w7ZZG.js | AI (source-diff): Standard Rollup minified output for a PDF viewer SDK; content is readable PDF/UI logic. | ai | |
| source-diff | net-exec-file:dist/worker-engine-7ImTik9Y.js | AI (source-diff): Worker postMessage + WASM URL fetch is the documented worker-engine pattern for this PDF SDK. | ai | |
| source-diff | net-exec-file:dist/direct-engine-B_w0Ka7Y.js | AI (source-diff): Network calls are WASM binary fetches; dynamic execution is WASM instantiation — standard PDF engine pattern. | ai | |
| source-diff | obfuscated-file:dist/worker-engine-7ImTik9Y.js | AI (source-diff): Minified Web Worker engine; content shows RemoteExecutor/WASM init pattern, expected for PDF SDK. | ai | |
| source-diff | obfuscated-file:dist/embedpdf-Ds41aXHo.js | AI (source-diff): Minified shared library bundle; content shows standard JS utility helpers, not malware. | ai | |
| source-diff | obfuscated-file:dist/direct-engine-B_w0Ka7Y.js | AI (source-diff): Minified WASM engine bundle with visible EPDF API symbols; expected build artifact. | ai | |
| phantom-deps | phantom-dep:@embedpdf/pdfium | AI (phantom-deps): Same-org dependency; likely used transitively or referenced indirectly in the bundle. | ai | |
| phantom-deps | phantom-dep:tailwind-merge | AI (phantom-deps): Bundled snippet package; tailwind-merge is likely inlined at build time rather than directly imported. | ai |
Versions (showing 31 of 31)
| Version | Deps | Published |
|---|---|---|
| 2.14.4 | 34 / 30 | |
| 2.14.3 | 34 / 30 | |
| 2.14.2 | 34 / 30 | |
| 2.14.1 | 34 / 30 | |
| 2.14.0 | 34 / 30 | |
| 2.13.0 | 34 / 30 | |
| 2.12.1 | 33 / 30 | |
| 2.12.0 | 33 / 30 | |
| 2.11.1 | 33 / 30 | |
| 2.11.0 | 33 / 30 | |
| 2.10.1 | 32 / 30 | |
| 2.10.0 | 32 / 30 | |
| 2.9.1 | 31 / 30 | |
| 2.9.0 | 31 / 30 | |
| 2.8.0 | 31 / 30 | |
| 2.7.0 | 31 / 30 | |
| 2.6.2 | 31 / 30 | |
| 2.6.1 | 31 / 30 | |
| 2.6.0 | 31 / 30 | |
| 2.5.0 | 31 / 30 | |
| 2.4.1 | 31 / 30 | |
| 2.4.0 | 31 / 30 | |
| 2.3.0 | 31 / 30 | |
| 2.2.0 | 31 / 30 | |
| 2.1.2 | 31 / 30 | |
| 2.1.1 | 31 / 31 | |
| 2.1.0 | 31 / 31 | |
| 2.0.2 | 31 / 31 | |
| 2.0.1 | 31 / 31 | |
| 2.0.0 | 31 / 32 | |
| 1.0.0 | 31 / 31 |
v2.12.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.12.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.11.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.11.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.10.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.9.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.9.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.8.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.7.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.6.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.6.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.6.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.5.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.3.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.1.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.2
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.1
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
2 findingsPackage contains compiled binaries that could be backdoors: • dist/pdfium.wasm
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.