@eox/map
[Examples](https://eox-a.github.io/EOxElements/elements/map/examples/index.html)
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index-CYUgfrsc.js | AI (source-diff): Bundled OpenLayers (ol) code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/eox-map-globe.js | AI (source-diff): Bundled openglobus globe rendering code, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/lerc-DNlc16Zc.js | AI (source-diff): Bundled LERC image decoder, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/decoder-CLokFc0V.js | AI (source-diff): Minified bundled decoder (LERC/worker polyfill), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/decoder-CLokFc0V.js | AI (source-diff): Web Worker feature-detect + generator polyfill, not dropper behavior. | ai | |
| source-diff | encoded-string-file:dist/eox-map-advanced-layers-and-sources.umd.cjs | AI (source-diff): Long strings are minified WebGL shader source code, not encoded payloads. | ai | |
| source-diff | obfuscated-file:dist/zstd-dJuUp1fl.js | AI (source-diff): Emscripten WASM wrapper for numcodecs/zstd codec; minified by design. | ai | |
| source-diff | obfuscated-file:dist/blosc-DL1kZHdE.js | AI (source-diff): Emscripten WASM wrapper for numcodecs/blosc compression codec; minified by design. | ai | |
| source-diff | obfuscated-file:dist/lerc-BRg84-C8.js | AI (source-diff): Minified LERC/zstddec decoder bundle from known upstream packages; not malicious. | ai | |
| source-diff | obfuscated-file:dist/lz4-Csz5aoFA.js | AI (source-diff): Emscripten WASM wrapper for numcodecs/lz4 codec; minified by design. | ai | |
| source-diff | obfuscated-file:dist/zstd-Cttq39rt.js | AI (source-diff): Minified zstddec streaming decoder from known upstream; not malicious. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): Scoped package @eox/map; Levenshtein match to 'hapi' is spurious, no squatting intent. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() used for documented serialize-javascript deserialization pattern; input is internally serialized layer config, not user-controlled arbitrary input. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped package @eox/map; Levenshtein match to 'yup' is spurious, no squatting intent. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 2.6.0 | 10 / 2 | |
| 2.5.1 | 10 / 2 | |
| 2.5.0 | 10 / 2 | |
| 2.4.0 | 10 / 2 | |
| 2.0.1 | 10 / 2 | |
| 2.0.0 | 10 / 2 | |
| 1.26.3 | 8 / 2 | |
| 1.26.2 | 8 / 2 |
v2.0.1
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
3 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (silvester-pari) than the most recent previously approved version (GitHub Actions) on 2025-12-13, but silvester-pari is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.26.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.26.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.