@iiif/helpers
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Known IIIF-commons org contributors added; consistent with legitimate multi-maintainer OSS project. | ai | |
| source-diff | net-exec-file:dist/transcriptions.cjs | AI (source-diff): Bundled tsup output for transcriptions module; no fetched-binary or remote-exec behavior in sample. | ai | |
| source-diff | net-exec-file:dist/transcriptions.global.js | AI (source-diff): Same bundled output, global build variant; false positive on bundler pattern. | ai | |
| source-diff | obfuscated-file:dist/expand-target-CZ8vQvuu.cjs | AI (source-diff): Minified bundle chunk, bezier math utility code, no malicious signature. | ai | |
| source-diff | obfuscated-file:dist/batch-actions-W2rikJ_i.cjs | AI (source-diff): Minified bundle chunk from build tool switch, no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/ranges-C2KSIgJg.cjs | AI (source-diff): Minified bundle chunk, range/TOC helper logic, benign. | ai | |
| source-diff | obfuscated-file:dist/image-service-DxDB3RwC.cjs | AI (source-diff): Minified bundle chunk implementing IIIF image service logic, benign. | ai | |
| source-diff | obfuscated-file:dist/get-global-DQ_cm4rC.cjs | AI (source-diff): Minified bundle chunk, internal store/entity logic, no malicious signature. | ai | |
| source-diff | obfuscated-file:dist/store-ETm2gdol.cjs | AI (source-diff): Minified bundle chunk, zustand store/devtools wiring, benign. | ai | |
| source-diff | obfuscated-file:dist/search1-bRUj5bc5.cjs | AI (source-diff): Minified bundle chunk, search service fetch to same-service endpoint, benign. | ai | |
| source-diff | obfuscated-file:dist/expand-target-CjBhcgOE.cjs | AI (source-diff): Minified bundler output for svg-arc/bezier math, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/expand-target-C_i3AMeE.js | AI (source-diff): Minified bundler output for svg-arc/bezier math, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/search1-DQzAv11a.cjs | AI (source-diff): Minified bundler output, fetch calls target caller-supplied search endpoint (documented feature). | ai | |
| source-diff | obfuscated-file:dist/batch-actions-CsxiKs1c.cjs | AI (source-diff): Minified bundler output (redux-style actions), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/expand-target-DVlF5UUe.cjs | AI (source-diff): Minified bundler output, standard geometry/bezier helper code. | ai | |
| source-diff | obfuscated-file:dist/get-global-5LOa_ogl.cjs | AI (source-diff): Minified bundler output requiring sibling chunks, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/image-service-DzA8DJSB.cjs | AI (source-diff): Minified bundler output implementing IIIF image service logic. | ai | |
| source-diff | obfuscated-file:dist/ranges-Cn8Hw8aB.cjs | AI (source-diff): Minified bundler output, IIIF ranges logic. | ai | |
| source-diff | obfuscated-file:dist/store-DFoPWb49.cjs | AI (source-diff): Minified zustand store code, standard bundler output. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Established maintainer with strong track record; likely reflects unimported intermediate releases. | ai | |
| source-diff | obfuscated-file:dist/batch-actions-DujgnHVQ.cjs | AI (source-diff): Bundled build output, not obfuscation; matches package's stated redux-action functionality. | ai | |
| source-diff | obfuscated-file:dist/store-D3Ghrc4T.cjs | AI (source-diff): Bundled zustand store code, minified not obfuscated. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Expected from bundler chunk-splitting change, not injected code. | ai | |
| source-diff | obfuscated-file:dist/search2-ESH9DQ4w.cjs | AI (source-diff): Bundled minified output from tsdown build, not obfuscation; matches package's search feature. | ai | |
| source-diff | obfuscated-file:dist/search2-D4UlNnNi.js | AI (source-diff): Bundled minified output, benign search feature. | ai | |
| source-diff | obfuscated-file:dist/search1-CgL6hZz1.js | AI (source-diff): Bundled minified output, benign search feature. | ai | |
| source-diff | obfuscated-file:dist/ranges-DOfZS_6m.js | AI (source-diff): Bundled minified output, benign ranges helper. | ai | |
| source-diff | obfuscated-file:dist/image-service-CM_RIOQ_.js | AI (source-diff): Bundled minified output, benign IIIF image-service logic. | ai | |
| source-diff | obfuscated-file:dist/get-global-DULwOgjp.js | AI (source-diff): Bundled minified output, benign vault/state helper. | ai | |
| source-diff | obfuscated-file:dist/expand-target-DxChDtpj.js | AI (source-diff): Bundled minified output, benign geometry helper. | ai | |
| source-diff | obfuscated-file:dist/css-selectors-C83GcWIX.js | AI (source-diff): Bundled minified output, benign CSS parsing helper. | ai | |
| phantom-deps | phantom-dep:@iiif/presentation-2 | AI (phantom-deps): Same-org IIIF package; likely used as type-only or re-exported, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/geojson | AI (phantom-deps): Type-only package used as a type dependency; not directly imported at runtime by convention. | ai |
Versions (showing 34 of 34)
| Version | Deps | Published |
|---|---|---|
| 1.6.0 | 4 / 16 | |
| 1.5.9 | 4 / 16 | |
| 1.5.8 | 4 / 16 | |
| 1.5.7 | 4 / 16 | |
| 1.5.6 | 4 / 16 | |
| 1.5.5 | 4 / 16 | |
| 1.5.4 | 4 / 16 | |
| 1.5.3 | 4 / 16 | |
| 1.5.2 | 4 / 16 | |
| 1.5.1 | 4 / 16 | |
| 1.5.0 | 4 / 16 | |
| 1.4.0 | 4 / 16 | |
| 1.3.2 | 4 / 16 | |
| 1.3.1 | 4 / 16 | |
| 1.3.0 | 4 / 16 | |
| 1.2.19 | 4 / 16 | |
| 1.2.18 | 4 / 16 | |
| 1.2.17 | 4 / 16 | |
| 1.2.16 | 4 / 16 | |
| 1.2.15 | 4 / 16 | |
| 1.2.14 | 4 / 16 | |
| 1.2.13 | 4 / 16 | |
| 1.2.12 | 4 / 16 | |
| 1.2.11 | 4 / 16 | |
| 1.2.10 | 4 / 16 | |
| 1.2.9 | 4 / 16 | |
| 1.2.8 | 4 / 16 | |
| 1.2.7 | 4 / 16 | |
| 1.2.6 | 4 / 16 | |
| 1.2.5 | 4 / 16 | |
| 1.2.4 | 4 / 16 | |
| 1.2.3 | 4 / 16 | |
| 1.2.2 | 4 / 16 | |
| 1.2.1 | 4 / 16 |
v1.6.0
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.19
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.18
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.17
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.16
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.15
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.14
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.13
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.12
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.11
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.10
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.9
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.