← Home

@iiif/helpers

34
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

sdellisedsilv-adminmejackreedstephenwfadamjarlingdemiankatzglen.robson

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Known IIIF-commons org contributors added; consistent with legitimate multi-maintainer OSS project. ai
source-diff net-exec-file:dist/transcriptions.cjs AI (source-diff): Bundled tsup output for transcriptions module; no fetched-binary or remote-exec behavior in sample. ai
source-diff net-exec-file:dist/transcriptions.global.js AI (source-diff): Same bundled output, global build variant; false positive on bundler pattern. ai
source-diff obfuscated-file:dist/expand-target-CZ8vQvuu.cjs AI (source-diff): Minified bundle chunk, bezier math utility code, no malicious signature. ai
source-diff obfuscated-file:dist/batch-actions-W2rikJ_i.cjs AI (source-diff): Minified bundle chunk from build tool switch, no malicious behavior in sample. ai
source-diff obfuscated-file:dist/ranges-C2KSIgJg.cjs AI (source-diff): Minified bundle chunk, range/TOC helper logic, benign. ai
source-diff obfuscated-file:dist/image-service-DxDB3RwC.cjs AI (source-diff): Minified bundle chunk implementing IIIF image service logic, benign. ai
source-diff obfuscated-file:dist/get-global-DQ_cm4rC.cjs AI (source-diff): Minified bundle chunk, internal store/entity logic, no malicious signature. ai
source-diff obfuscated-file:dist/store-ETm2gdol.cjs AI (source-diff): Minified bundle chunk, zustand store/devtools wiring, benign. ai
source-diff obfuscated-file:dist/search1-bRUj5bc5.cjs AI (source-diff): Minified bundle chunk, search service fetch to same-service endpoint, benign. ai
source-diff obfuscated-file:dist/expand-target-CjBhcgOE.cjs AI (source-diff): Minified bundler output for svg-arc/bezier math, not true obfuscation. ai
source-diff obfuscated-file:dist/expand-target-C_i3AMeE.js AI (source-diff): Minified bundler output for svg-arc/bezier math, not true obfuscation. ai
source-diff obfuscated-file:dist/search1-DQzAv11a.cjs AI (source-diff): Minified bundler output, fetch calls target caller-supplied search endpoint (documented feature). ai
source-diff obfuscated-file:dist/batch-actions-CsxiKs1c.cjs AI (source-diff): Minified bundler output (redux-style actions), not obfuscation. ai
source-diff obfuscated-file:dist/expand-target-DVlF5UUe.cjs AI (source-diff): Minified bundler output, standard geometry/bezier helper code. ai
source-diff obfuscated-file:dist/get-global-5LOa_ogl.cjs AI (source-diff): Minified bundler output requiring sibling chunks, no malicious behavior. ai
source-diff obfuscated-file:dist/image-service-DzA8DJSB.cjs AI (source-diff): Minified bundler output implementing IIIF image service logic. ai
source-diff obfuscated-file:dist/ranges-Cn8Hw8aB.cjs AI (source-diff): Minified bundler output, IIIF ranges logic. ai
source-diff obfuscated-file:dist/store-DFoPWb49.cjs AI (source-diff): Minified zustand store code, standard bundler output. ai
publish-pattern dormant-publish AI (publish-pattern): Established maintainer with strong track record; likely reflects unimported intermediate releases. ai
source-diff obfuscated-file:dist/batch-actions-DujgnHVQ.cjs AI (source-diff): Bundled build output, not obfuscation; matches package's stated redux-action functionality. ai
source-diff obfuscated-file:dist/store-D3Ghrc4T.cjs AI (source-diff): Bundled zustand store code, minified not obfuscated. ai
source-diff large-new-source-files AI (source-diff): Expected from bundler chunk-splitting change, not injected code. ai
source-diff obfuscated-file:dist/search2-ESH9DQ4w.cjs AI (source-diff): Bundled minified output from tsdown build, not obfuscation; matches package's search feature. ai
source-diff obfuscated-file:dist/search2-D4UlNnNi.js AI (source-diff): Bundled minified output, benign search feature. ai
source-diff obfuscated-file:dist/search1-CgL6hZz1.js AI (source-diff): Bundled minified output, benign search feature. ai
source-diff obfuscated-file:dist/ranges-DOfZS_6m.js AI (source-diff): Bundled minified output, benign ranges helper. ai
source-diff obfuscated-file:dist/image-service-CM_RIOQ_.js AI (source-diff): Bundled minified output, benign IIIF image-service logic. ai
source-diff obfuscated-file:dist/get-global-DULwOgjp.js AI (source-diff): Bundled minified output, benign vault/state helper. ai
source-diff obfuscated-file:dist/expand-target-DxChDtpj.js AI (source-diff): Bundled minified output, benign geometry helper. ai
source-diff obfuscated-file:dist/css-selectors-C83GcWIX.js AI (source-diff): Bundled minified output, benign CSS parsing helper. ai
phantom-deps phantom-dep:@iiif/presentation-2 AI (phantom-deps): Same-org IIIF package; likely used as type-only or re-exported, stable false positive for this package. ai
phantom-deps phantom-dep:@types/geojson AI (phantom-deps): Type-only package used as a type dependency; not directly imported at runtime by convention. ai

Versions (showing 34 of 34)

Version Deps Published
1.6.0 4 / 16
1.5.9 4 / 16
1.5.8 4 / 16
1.5.7 4 / 16
1.5.6 4 / 16
1.5.5 4 / 16
1.5.4 4 / 16
1.5.3 4 / 16
1.5.2 4 / 16
1.5.1 4 / 16
1.5.0 4 / 16
1.4.0 4 / 16
1.3.2 4 / 16
1.3.1 4 / 16
1.3.0 4 / 16
1.2.19 4 / 16
1.2.18 4 / 16
1.2.17 4 / 16
1.2.16 4 / 16
1.2.15 4 / 16
1.2.14 4 / 16
1.2.13 4 / 16
1.2.12 4 / 16
1.2.11 4 / 16
1.2.10 4 / 16
1.2.9 4 / 16
1.2.8 4 / 16
1.2.7 4 / 16
1.2.6 4 / 16
1.2.5 4 / 16
1.2.4 4 / 16
1.2.3 4 / 16
1.2.2 4 / 16
1.2.1 4 / 16

v1.6.0

9 findings
HIGH New obfuscated file: dist/search2-ESH9DQ4w.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/css-selectors-C83GcWIX.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/expand-target-DxChDtpj.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/get-global-DULwOgjp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/image-service-CM_RIOQ_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/ranges-DOfZS_6m.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/search1-CgL6hZz1.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/search2-D4UlNnNi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.19

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.18

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.17

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.16

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.15

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.14

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.13

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.12

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.11

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.10

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.9

3 findings
HIGH New file with network + code execution: dist/transcriptions.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: dist/transcriptions.global.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.