← Home

@esotericsoftware/spine-core

The official Spine Runtimes for the web.

100
Versions
LicenseRef-LICENSE
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

badlogicnathansweetdaaaaa

Keywords

gamedevanimations2dspinegame-devruntimesskeletal

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/attachments/HasTextureRegion.js AI (source-diff): Standard TS-compiled JS with inline source maps; expected build output for this package. ai
source-diff obfuscated-file:dist/Updatable.js AI (source-diff): Standard TS-compiled JS with inline source maps; expected build output for this package. ai
source-diff obfuscated-file:dist/Constraint.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/DrawOrder.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/attachments/HasSequence.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/IkConstraintPose.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/PathConstraintPose.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/Physics.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/PhysicsConstraintPose.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/Posed.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/PosedActive.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/SkeletonRendererCore.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/Slider.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/SliderData.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/SliderPose.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/SlotPose.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/TransformConstraintPose.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/Update.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff large-new-source-files AI (source-diff): 38 new files are a v4.3 API refactor of the official Spine runtime, not injected code. ai
bogus-package bogus-package AI (bogus-package): Official Esoteric Software runtime; no deps by design (pure TS library), short README is normal for a scoped SDK package. ai
source-diff obfuscated-file:dist/PosedData.js AI (source-diff): Inline sourcemap base64 triggers long-line detector; readable compiled TS, not malicious. ai
source-diff obfuscated-file:dist/BonePose.js AI (source-diff): Long lines are inline sourcemaps, not obfuscation; stable pattern for this compiled TS package. ai
source-diff obfuscated-file:dist/PhysicsConstraint.js AI (source-diff): Readable Spine Runtime source with license header; long lines are from bundled dist output, not obfuscation. ai
source-diff obfuscated-file:dist/PhysicsConstraintData.js AI (source-diff): Same pattern — legitimate ES module source with Esoteric Software license header, not obfuscated. ai

Versions (showing 100 of 204)

Version Deps Published
4.3.7 0 / 0
4.3.6 0 / 0
4.3.5 0 / 0
4.3.4 0 / 0
4.3.3 0 / 0
4.3.2 0 / 0
4.3.1 0 / 0
4.3.0 0 / 0
4.2.119 0 / 0
4.2.118 0 / 0
4.2.117 0 / 0
4.2.116 0 / 0
4.2.115 0 / 0
4.2.114 0 / 0
4.2.113 0 / 0
4.2.112 0 / 0
4.2.111 0 / 0
4.2.110 0 / 0
4.2.109 0 / 0
4.2.108 0 / 0
4.2.107 0 / 0
4.2.106 0 / 0
4.2.105 0 / 0
4.2.104 0 / 0
4.2.103 0 / 0
4.2.102 0 / 0
4.2.101 0 / 0
4.2.100 0 / 0
4.2.99 0 / 0
4.2.98 0 / 0
4.2.97 0 / 0
4.2.96 0 / 0
4.2.95 0 / 0
4.2.94 0 / 0
4.2.93 0 / 0
4.2.92 0 / 0
4.2.91 0 / 0
4.2.90 0 / 0
4.2.89 0 / 0
4.2.88 0 / 0
4.2.87 0 / 0
4.2.86 0 / 0
4.2.85 0 / 0
4.2.84 0 / 0
4.2.83 0 / 0
4.2.82 0 / 0
4.2.81 0 / 0
4.2.80 0 / 0
4.2.79 0 / 0
4.2.78 0 / 0
4.2.77 0 / 0
4.2.76 0 / 0
4.2.75 0 / 0
4.2.74 0 / 0
4.2.73 0 / 0
4.2.72 0 / 0
4.2.71 0 / 0
4.2.70 0 / 0
4.2.69 0 / 0
4.2.68 0 / 0
4.2.67 0 / 0
4.2.66 0 / 0
4.2.65 0 / 0
4.2.64 0 / 0
4.2.63 0 / 0
4.2.62 0 / 0
4.2.61 0 / 0
4.2.60 0 / 0
4.2.59 0 / 0
4.2.58 0 / 0
4.2.57 0 / 0
4.2.48 0 / 0
4.2.47 0 / 0
4.2.46 0 / 0
4.2.45 0 / 0
4.2.44 0 / 0
4.2.43 0 / 0
4.2.42 0 / 0
4.2.41 0 / 0
4.2.40 0 / 0
4.2.39 0 / 0
4.2.38 0 / 0
4.2.37 0 / 0
4.2.36 0 / 0
4.2.35 0 / 0
4.2.34 0 / 0
4.2.33 0 / 0
4.2.32 0 / 0
4.2.31 0 / 0
4.2.30 0 / 0
4.2.29 0 / 0
4.2.28 0 / 0
4.2.27 0 / 0
4.2.26 0 / 0
4.2.25 0 / 0
4.2.24 0 / 0
4.2.23 0 / 0
4.2.22 0 / 0
4.2.21 0 / 0
4.2.20 0 / 0
Showing 100 of 204 Next page →

v4.2.80

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.79

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.78

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.77

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.76

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.75

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.74

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.73

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.72

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.71

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.70

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.69

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.68

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.67

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.66

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.65

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.64

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.63

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.62

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.60

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.48

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.47

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.46

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.45

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: badlogic → daaaaa (on 2024-06-06, known maintainer) provenance

This version was published by a different npm account (daaaaa) than the most recent previously approved version (badlogic) on 2024-06-06, but daaaaa is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.44

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: daaaaa → badlogic (on 2024-06-04, known maintainer) provenance

This version was published by a different npm account (badlogic) than the most recent previously approved version (daaaaa) on 2024-06-04, but badlogic is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.43

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: badlogic → daaaaa (on 2024-05-17, known maintainer) provenance

This version was published by a different npm account (daaaaa) than the most recent previously approved version (badlogic) on 2024-05-17, but daaaaa is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.2.42

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.39

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.38

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.2.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.