@livekit/components-react
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/components-DTrwFVVj.mjs | AI (source-diff): Bundled ESM component output; benign React/livekit code. | ai | |
| source-diff | obfuscated-file:dist/components-DTrwFVVj.mjs | AI (source-diff): vite dist build; minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/shared-OSRVnQKu.js | AI (source-diff): vite-bundled dist output; minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/shared-OSRVnQKu.js | AI (source-diff): Bundled component code; no dropper behavior, standard LiveKit UI. | ai | |
| source-diff | net-exec-file:dist/components-01Mw9Q_q.mjs | AI (source-diff): Bundled React output; hashed chunk name changes each build, no real net+exec payload. | ai | |
| source-diff | obfuscated-file:dist/shared-a5-jFrQo.js | AI (source-diff): Minified vite bundle output, not obfuscation; recurs every release. | ai | |
| source-diff | obfuscated-file:dist/components-CG43NVTo.mjs | AI (source-diff): Vite/rollup bundle output, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/shared-a5-jFrQo.js | AI (source-diff): Long-line heuristic on bundled React code; no fetch+eval dropper behavior. | ai | |
| source-diff | net-exec-file:dist/components-CG43NVTo.mjs | AI (source-diff): Bundled component code; benign minified build artifact. | ai | |
| source-diff | obfuscated-file:dist/components-OLOni9K_.mjs | AI (source-diff): Minified ESM build output. | ai | |
| source-diff | net-exec-file:dist/components-OLOni9K_.mjs | AI (source-diff): WebRTC component code in bundle, no fetched-payload exec. | ai | |
| source-diff | obfuscated-file:dist/shared-Dm0MXW3h.js | AI (source-diff): Minified Vite build output. | ai | |
| source-diff | obfuscated-file:dist/shared-Bs9ANjHC.js | AI (source-diff): Minified vite build output, not obfuscation; new hashed dist filenames each build. | ai | |
| source-diff | net-exec-file:dist/shared-Bs9ANjHC.js | AI (source-diff): Bundled fetch/eval patterns in legit React lib; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/components-BO8CL-ek.mjs | AI (source-diff): Bundled build output; benign network/exec heuristic. | ai | |
| source-diff | obfuscated-file:dist/components-zhA5OhZT.mjs | AI (source-diff): Minified vite build output. | ai | |
| source-diff | obfuscated-file:dist/shared-DDSu96zI.js | AI (source-diff): Minified vite build output. | ai | |
| source-diff | net-exec-file:dist/shared-B1zkM8Hq.js | AI (source-diff): Minified bundle long-line FP; no hostile fetch/exec destination. | ai | |
| source-diff | obfuscated-file:dist/shared-B1zkM8Hq.js | AI (source-diff): Minified vite build output, not obfuscation; stable for this build pipeline. | ai | |
| source-diff | obfuscated-file:dist/shared-DA5APR6H.js | AI (source-diff): Minified vite build output. | ai | |
| source-diff | obfuscated-file:dist/shared-D7MwGPop.js | AI (source-diff): Minified vite build output. | ai | |
| source-diff | net-exec-file:dist/components-zhA5OhZT.mjs | AI (source-diff): Minified bundle long-line FP; no hostile destination. | ai | |
| source-diff | net-exec-file:dist/shared-DZpGbsVN.js | AI (source-diff): Minified React/livekit bundle; no hostile fetch+exec, benign UI code. | ai | |
| source-diff | obfuscated-file:dist/shared-Brl3fS_M.js | AI (source-diff): Vite minified bundle output, not obfuscation; regenerated hash names retrigger each release. | ai | |
| source-diff | net-exec-file:dist/components-B5MIutP6.mjs | AI (source-diff): Minified React component bundle; benign, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/components-DZxz2YwG.mjs | AI (source-diff): Vite ESM build output, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/shared-CB2jSgEs.js | AI (source-diff): Minified React bundle; no fetched-binary or hostile destination, false positive. | ai | |
| source-diff | obfuscated-file:dist/shared-CB2jSgEs.js | AI (source-diff): Vite-minified dist output, not obfuscation; stable build artifact for this library. | ai | |
| source-diff | net-exec-file:dist/components-DZxz2YwG.mjs | AI (source-diff): Minified React component bundle; benign build output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Bundler code-splitting produces many dist chunks; expected. | ai | |
| source-diff | net-exec-file:dist/shared-CIkkbnQt.js | AI (source-diff): Minified React bundle; no fetched-code execution or exfil. | ai | |
| source-diff | obfuscated-file:dist/shared-BKbzPkyA.js | AI (source-diff): Vite minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/components-DoUKwDyM.mjs | AI (source-diff): Minified React bundle; benign net/dynamic patterns from build. | ai | |
| source-diff | obfuscated-file:dist/components-C8upqnw3.mjs | AI (source-diff): Vite minified build output. | ai | |
| source-diff | net-exec-file:dist/components-C8upqnw3.mjs | AI (source-diff): Minified bundle; no hostile net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/shared-neKmoI-s.js | AI (source-diff): Vite minified build output. | ai | |
| source-diff | obfuscated-file:dist/shared-DC80XrNJ.js | AI (source-diff): Vite minified build output. | ai | |
| source-diff | obfuscated-file:dist/shared-D5tPReEg.js | AI (source-diff): Vite minified build output. | ai | |
| source-diff | net-exec-file:dist/shared-Cw4WR6ck.js | AI (source-diff): Minified bundle; no hostile net+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/shared-Cw4WR6ck.js | AI (source-diff): Vite minified build output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/components-BVYoD26g.mjs | AI (source-diff): Minified React component bundle; benign build output. | ai | |
| source-diff | obfuscated-file:dist/shared-6K4zJAEk.js | AI (source-diff): Vite-minified dist output, not obfuscation; regenerated hashed filename each build. | ai | |
| source-diff | obfuscated-file:dist/shared-BIa_RsNN.js | AI (source-diff): Vite-minified dist output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-BMXanl1Z.js | AI (source-diff): Vite-minified dist output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-Cc_YJiVx.js | AI (source-diff): Vite-minified dist output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components-BVYoD26g.mjs | AI (source-diff): Vite-minified dist output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/shared-Cc_YJiVx.js | AI (source-diff): Minified React/livekit component bundle; no hostile fetch+exec target. | ai | |
| source-diff | obfuscated-file:dist/components-CVxZce7u.mjs | AI (source-diff): Vite-minified build output. | ai | |
| source-diff | net-exec-file:dist/components-CVxZce7u.mjs | AI (source-diff): Normal React/WebRTC bundle, no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/shared-BXLWvMOJ.js | AI (source-diff): WebRTC lib code; no fetched-binary or exec of hostile target. | ai | |
| source-diff | obfuscated-file:dist/shared-BXLWvMOJ.js | AI (source-diff): Vite-minified build output. | ai | |
| source-diff | obfuscated-file:dist/shared--BWexiI_.js | AI (source-diff): Vite-minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-BDwp6ARD.js | AI (source-diff): Vite-minified build output, not obfuscation; stable for this package. | ai | |
| source-diff | obfuscated-file:dist/shared-BVkaV3ZE.js | AI (source-diff): Vite-minified build output; benign component code. | ai | |
| source-diff | obfuscated-file:dist/shared-DIDUFRLS.js | AI (source-diff): Vite-minified build output; benign. | ai | |
| source-diff | obfuscated-file:dist/shared-rO8zu34b.js | AI (source-diff): Vite-minified build output; benign. | ai | |
| source-diff | obfuscated-file:dist/components-DtauMl4Q.mjs | AI (source-diff): Vite-minified ESM build; benign. | ai | |
| source-diff | net-exec-file:dist/shared-BVkaV3ZE.js | AI (source-diff): React/livekit component bundle; no dropper behavior. | ai | |
| source-diff | net-exec-file:dist/components-DtauMl4Q.mjs | AI (source-diff): React/livekit component bundle; no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/shared-LIGJj7s6.js | AI (source-diff): Vite-bundled dist chunk, hashed filename changes each build; readable minified React code. | ai | |
| source-diff | net-exec-file:dist/shared-LIGJj7s6.js | AI (source-diff): Bundled component chunk; net+exec heuristic on standard build output, no hostile target. | ai | |
| source-diff | net-exec-file:dist/components-DEJtG3uc.mjs | AI (source-diff): Bundled mjs chunk; benign React component bundle. | ai | |
| source-diff | obfuscated-file:dist/components-DEJtG3uc.mjs | AI (source-diff): Vite mjs build output, hashed name. | ai | |
| source-diff | obfuscated-file:dist/shared-DomGioiC.js | AI (source-diff): Bundled dist chunk. | ai | |
| source-diff | obfuscated-file:dist/shared-sXcAE4ma.js | AI (source-diff): Bundled dist chunk. | ai | |
| source-diff | obfuscated-file:dist/shared-D_Ks7MZc.js | AI (source-diff): Vite-minified dist bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-CJvqer9K.js | AI (source-diff): Vite-minified dist bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-C9EfKMR-.js | AI (source-diff): Vite-minified dist bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-BPsc5SeK.js | AI (source-diff): Vite-minified dist bundle, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/components-Y1IPllFz.mjs | AI (source-diff): Minified build output of a React WebRTC lib; no hostile net/exec target. | ai | |
| source-diff | net-exec-file:dist/shared-CJvqer9K.js | AI (source-diff): Minified build output of a React WebRTC lib; no hostile net/exec target. | ai | |
| source-diff | obfuscated-file:dist/components-Y1IPllFz.mjs | AI (source-diff): Vite-minified dist bundle, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components-CwZ8kStA.mjs | AI (source-diff): Standard Vite/Rollup minified bundle output; code is readable LiveKit/React component logic. | ai | |
| source-diff | obfuscated-file:dist/shared-jZUXaCo3.js | AI (source-diff): Standard Vite/Rollup minified bundle output; code is readable LiveKit/React logic, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/shared-CmjH0W2G.js | AI (source-diff): Standard Vite/Rollup minified bundle output; code is readable LiveKit/React logic, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/shared-BCAxwLPA.js | AI (source-diff): Standard Vite/Rollup minified bundle output; code is readable LiveKit/React logic, not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/shared-9gJpzp77.js | AI (source-diff): Standard Vite/Rollup minified bundle output; code is readable LiveKit/React logic, not obfuscated. | ai | |
| source-diff | net-exec-file:dist/shared-CmjH0W2G.js | AI (source-diff): Network calls are LiveKit WebRTC API usage; dynamic code execution is React createElement — no dropper pattern. | ai | |
| source-diff | net-exec-file:dist/components-CwZ8kStA.mjs | AI (source-diff): Network calls are LiveKit WebRTC API usage; dynamic code execution is React createElement — no dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/shared-CY0Qaqwj.js | AI (source-diff): Standard Vite/Rollup minified bundle output for this React library; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-BmMQPxKc.js | AI (source-diff): Standard Vite/Rollup minified bundle output for this React library; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-VrpP8d_K.js | AI (source-diff): Standard Vite/Rollup minified bundle output for this React library; not malicious obfuscation. | ai | |
| source-diff | net-exec-file:dist/shared-VrpP8d_K.js | AI (source-diff): Network calls are livekit-client WebRTC APIs; no dynamic code execution pattern present in samples. | ai | |
| source-diff | obfuscated-file:dist/shared-XaRFWxdm.js | AI (source-diff): Standard Vite/Rollup minified bundle output; floating-ui/positioning code visible in sample. | ai | |
| source-diff | obfuscated-file:dist/components-Bz2b1Fa9.mjs | AI (source-diff): Standard Vite/Rollup minified ESM bundle for this React library. | ai | |
| source-diff | net-exec-file:dist/components-Bz2b1Fa9.mjs | AI (source-diff): Network calls are livekit-client WebRTC APIs; createElement is React rendering, not dynamic code execution. | ai | |
| source-diff | net-exec-file:dist/shared-CHuuWXU-.js | AI (source-diff): Network calls are livekit-client WebRTC APIs; dynamic code is normal React createElement/hooks patterns. | ai | |
| source-diff | net-exec-file:dist/components-DHWpi-op.mjs | AI (source-diff): Network calls are livekit-client WebRTC APIs; dynamic code is React createElement, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/shared-CHuuWXU-.js | AI (source-diff): Standard Vite minified bundle output for a React component library; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:dist/components-DHWpi-op.mjs | AI (source-diff): Vite-minified ESM bundle; sample shows forwardRef components and SVG icons, no malicious content. | ai | |
| source-diff | obfuscated-file:dist/shared-Dy7KtilJ.js | AI (source-diff): Vite-minified bundle; sample shows LiveKit room connection logic, no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/shared-DQInubaN.js | AI (source-diff): Vite-minified bundle; sample shows ResizeObserver, chat state reducer, standard React patterns. | ai | |
| source-diff | obfuscated-file:dist/shared-D3fcovJq.js | AI (source-diff): Standard Vite/Rollup minified bundle output; LiveKit room/hook logic, no malicious content. | ai | |
| source-diff | obfuscated-file:dist/shared-Cxl3cIQC.js | AI (source-diff): Standard Vite/Rollup minified bundle output; floating-UI positioning logic, no malicious content. | ai | |
| source-diff | obfuscated-file:dist/shared-CE6LDR4K.js | AI (source-diff): Standard Vite/Rollup minified bundle output; code is normal React/LiveKit UI components. | ai | |
| source-diff | obfuscated-file:dist/shared-BLCMAVw2.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a React component library; no malicious patterns. | ai | |
| source-diff | net-exec-file:dist/components-DKVkostq.mjs | AI (source-diff): Network calls are LiveKit WebRTC API usage; no dynamic code execution present in the sample. | ai | |
| source-diff | net-exec-file:dist/shared-CE6LDR4K.js | AI (source-diff): Network calls are LiveKit WebRTC API usage; no dynamic code execution (eval/Function constructor) present. | ai | |
| source-diff | obfuscated-file:dist/components-DKVkostq.mjs | AI (source-diff): Standard Vite/Rollup minified ESM bundle; normal React component code. | ai | |
| source-diff | obfuscated-file:dist/shared-DZcVgX7j.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable LiveKit/React code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-CGFYrEgQ.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable LiveKit/React code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-BpdYlR3A.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable LiveKit/React code, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/shared-DZcVgX7j.js | AI (source-diff): Network calls are React/LiveKit API usage (matchMedia, ResizeObserver); createElement is React rendering, not code execution. | ai | |
| source-diff | net-exec-file:dist/components-CU_md5RK.mjs | AI (source-diff): Network calls are React/LiveKit API usage; createElement is React rendering, not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/components-CU_md5RK.mjs | AI (source-diff): Standard Vite/Rollup minified bundle output; readable LiveKit/React code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-VEQdJrv0.js | AI (source-diff): Standard Vite/Rollup minified bundle output; readable LiveKit/React code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-CFk85O47.js | AI (source-diff): Standard minified Vite bundle; code is readable React hooks logic. | ai | |
| source-diff | obfuscated-file:dist/shared-B-TxItyN.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a React component library; no actual obfuscation. | ai | |
| source-diff | net-exec-file:dist/components-k0KtCs0w.mjs | AI (source-diff): Network calls are LiveKit WebRTC API; no dynamic code execution present in samples. | ai | |
| source-diff | obfuscated-file:dist/components-k0KtCs0w.mjs | AI (source-diff): Standard minified Vite ESM bundle; code is readable React component definitions. | ai | |
| source-diff | obfuscated-file:dist/shared-DvBJFclv.js | AI (source-diff): Standard minified Vite bundle; code is floating-ui/positioning logic. | ai | |
| source-diff | net-exec-file:dist/shared-B-TxItyN.js | AI (source-diff): Network calls are WebRTC/LiveKit API usage; no dynamic code execution (eval/Function constructor) present. | ai | |
| source-diff | obfuscated-file:dist/shared-ChGsM9Y7.js | AI (source-diff): Standard minified Vite bundle; code is readable React component logic. | ai | |
| source-diff | obfuscated-file:dist/shared-Bh0fNkvu.js | AI (source-diff): Standard Vite minified bundle output for this React library; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/components-BlAy1Aks.mjs | AI (source-diff): Network calls are livekit-client SDK usage; no dropper/loader pattern in sample. | ai | |
| source-diff | obfuscated-file:dist/components-BlAy1Aks.mjs | AI (source-diff): Standard Vite minified ESM bundle for React components; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/shared-Bh0fNkvu.js | AI (source-diff): Network calls are livekit-client SDK usage; no dropper/loader pattern in sample. | ai | |
| source-diff | obfuscated-file:dist/shared-BVVr9jJ4.js | AI (source-diff): Minified floating-UI/positioning logic bundled by vite; expected build artifact. | ai | |
| source-diff | net-exec-file:dist/components-BeK2vIib.mjs | AI (source-diff): Network calls are LiveKit WebRTC API; no eval/dynamic execution in sampled code. | ai | |
| source-diff | obfuscated-file:dist/components-BeK2vIib.mjs | AI (source-diff): Minified React component bundle; long lines are normal vite minification. | ai | |
| source-diff | obfuscated-file:dist/shared-DXC9VBzT.js | AI (source-diff): Minified ResizeObserver/state utilities; standard build output. | ai | |
| source-diff | obfuscated-file:dist/shared-DimS3cEB.js | AI (source-diff): Minified LiveKit room/hook logic; standard build output. | ai | |
| source-diff | net-exec-file:dist/shared-BB7aiEfq.js | AI (source-diff): Network calls are LiveKit WebRTC API usage; no dynamic code execution (eval/Function) present in sampled code. | ai | |
| source-diff | obfuscated-file:dist/shared-BB7aiEfq.js | AI (source-diff): Standard vite-minified React/LiveKit bundle; long lines are normal minification output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-CQ-nEmIw.js | AI (source-diff): Standard Vite-minified bundle; samples show ResizeObserver and RxJS subscription patterns. | ai | |
| source-diff | net-exec-file:dist/shared-Bs34Ekar.js | AI (source-diff): Network calls are livekit-client WebRTC APIs; dynamic execution is React createElement — no dropper pattern. | ai | |
| source-diff | obfuscated-file:dist/shared-Bs34Ekar.js | AI (source-diff): Standard Vite-minified bundle output; samples show normal React/livekit-client code. | ai | |
| source-diff | obfuscated-file:dist/shared-B7S62mm5.js | AI (source-diff): Standard Vite-minified bundle output for this React component library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-DWpF098-.js | AI (source-diff): Standard Vite-minified bundle; samples show LiveKit room/participant hook code. | ai | |
| source-diff | obfuscated-file:dist/components-DmY-A_LL.mjs | AI (source-diff): Standard Vite-minified ESM bundle; samples show React component wrappers. | ai | |
| source-diff | net-exec-file:dist/components-DmY-A_LL.mjs | AI (source-diff): Network calls are livekit-client APIs; dynamic execution is React createElement — legitimate component library pattern. | ai | |
| source-diff | obfuscated-file:dist/shared-CJDltH4I.js | AI (source-diff): Standard Vite minified bundle output for this React UI library; not obfuscation. | ai | |
| source-diff | net-exec-file:dist/components-DqcPwJ_9.mjs | AI (source-diff): Network calls are livekit-client WebRTC API; dynamic code is React createElement — normal for this package. | ai | |
| source-diff | obfuscated-file:dist/components-DqcPwJ_9.mjs | AI (source-diff): Standard Vite minified ESM bundle; React component definitions, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-Pblsvaeh.js | AI (source-diff): Standard Vite minified bundle output for this React UI library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-IFvGP0Zf.js | AI (source-diff): Standard Vite minified bundle output; floating-UI/positioning logic, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/shared-CJDltH4I.js | AI (source-diff): Network calls are livekit-client WebRTC API; dynamic code is React createElement — normal for this package. | ai | |
| source-diff | obfuscated-file:dist/shared-BKTd9Oqq.js | AI (source-diff): Standard Vite minified bundle output for this React UI library; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-BdB9GPUj.js | AI (source-diff): Standard minified build output for a React component library; no obfuscation or malicious patterns. | ai | |
| source-diff | net-exec-file:dist/components-B0PMXyIS.mjs | AI (source-diff): Network calls are livekit-client WebRTC APIs; no malicious execution patterns. | ai | |
| source-diff | obfuscated-file:dist/components-B0PMXyIS.mjs | AI (source-diff): Standard minified ESM build output; normal React component patterns. | ai | |
| source-diff | net-exec-file:dist/shared-BdB9GPUj.js | AI (source-diff): Network calls are livekit-client WebRTC APIs; no dropper/loader patterns in the sample. | ai | |
| source-diff | obfuscated-file:dist/shared-I8hFcrmp.js | AI (source-diff): Standard minified build output; samples show normal React hooks and ResizeObserver usage. | ai | |
| source-diff | net-exec-file:dist/shared-DsGkPi0_.js | AI (source-diff): Network calls are livekit-client WebRTC APIs; dynamic code execution is React createElement — not dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/shared-BGiZtWPs.js | AI (source-diff): Standard minified build output for a React component library; no actual obfuscation. | ai | |
| source-diff | obfuscated-file:dist/shared-DsGkPi0_.js | AI (source-diff): Standard minified build output; samples show normal React/livekit-client code. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher is GitHub Actions with SLSA provenance attestation; CI/CD publishing is the documented release process for this package. | ai | |
| source-diff | net-exec-file:dist/components-Cc_gXqiR.mjs | AI (source-diff): Network calls are livekit-client APIs; dynamic execution is React createElement — not malware. | ai | |
| source-diff | obfuscated-file:dist/components-Cc_gXqiR.mjs | AI (source-diff): Standard minified build output; samples show normal React component definitions. | ai | |
| phantom-deps | phantom-dep:jose | AI (phantom-deps): jose is a declared runtime dependency in package.json; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 51 of 67)
| Version | Deps | Published |
|---|---|---|
| 2.9.23 | 5 / 23 | |
| 2.9.21 | 5 / 23 | |
| 2.9.20 | 5 / 23 | |
| 2.9.19 | 5 / 23 | |
| 2.9.18 | 5 / 23 | |
| 2.9.17 | 5 / 22 | |
| 2.9.16 | 5 / 22 | |
| 2.9.15 | 3 / 19 | |
| 2.9.14 | 3 / 19 | |
| 2.9.13 | 3 / 19 | |
| 2.9.12 | 3 / 19 | |
| 2.9.11 | 3 / 19 | |
| 2.9.10 | 3 / 19 | |
| 2.9.9 | 3 / 19 | |
| 2.9.8 | 3 / 19 | |
| 2.9.7 | 3 / 19 | |
| 2.9.6 | 3 / 19 | |
| 2.9.5 | 3 / 19 | |
| 2.9.4 | 3 / 19 | |
| 2.9.3 | 3 / 19 | |
| 2.9.2 | 3 / 19 | |
| 2.9.1 | 3 / 19 | |
| 2.9.0 | 3 / 19 | |
| 2.8.1 | 3 / 19 | |
| 2.8.0 | 3 / 19 | |
| 2.7.0 | 3 / 19 | |
| 2.6.11 | 3 / 19 | |
| 2.6.10 | 3 / 19 | |
| 2.6.9 | 3 / 19 | |
| 2.6.8 | 3 / 19 | |
| 2.6.7 | 3 / 19 | |
| 2.6.6 | 3 / 19 | |
| 2.6.5 | 3 / 19 | |
| 2.6.4 | 3 / 19 | |
| 2.6.3 | 3 / 17 | |
| 2.6.2 | 3 / 17 | |
| 2.6.1 | 3 / 17 | |
| 2.6.0 | 3 / 17 | |
| 2.5.4 | 3 / 17 | |
| 2.5.3 | 3 / 17 | |
| 2.5.2 | 3 / 17 | |
| 2.5.1 | 3 / 17 | |
| 2.5.0 | 3 / 17 | |
| 2.4.3 | 3 / 17 | |
| 2.4.2 | 3 / 17 | |
| 2.4.1 | 3 / 17 | |
| 2.4.0 | 3 / 17 | |
| 2.3.6 | 3 / 17 | |
| 2.3.5 | 4 / 17 | |
| 2.3.4 | 4 / 17 | |
| 2.3.3 | 4 / 17 |
v2.9.23
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.9.3
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lukasio) than the most recent previously approved version (thedavidzhao) on 2025-04-23, but lukasio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.9.2
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.11
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.10
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.9
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.8
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.7
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.6
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.5
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.4
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.