@newview/file-ui
1、构件选择组件增加排序
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@embedpdf/vue-pdf-viewer | AI (phantom-deps): Consumed via bundled dist files from Vite build; not a direct import in source. | ai | |
| source-diff | net-exec-file:dist/direct-engine-CzzT8DSZ-cf7e226e.js | AI (source-diff): PDF WASM engine uses fetch for WASM loading; standard pattern for this dependency. | ai | |
| source-diff | obfuscated-file:dist/index-8bb88267.js | AI (source-diff): Vite-bundled Vue component library output; readable imports visible in sample. | ai | |
| source-diff | net-exec-file:dist/index-8bb88267.js | AI (source-diff): Vue UI component bundle with API calls; standard for a file-management UI library. | ai | |
| source-diff | obfuscated-file:dist/worker-engine-BZRBQvei-e86f78f0.js | AI (source-diff): Web Worker for PDF engine; readable RemoteExecutor pattern in sample. | ai | |
| source-diff | net-exec-file:dist/worker-engine-BZRBQvei-e86f78f0.js | AI (source-diff): Worker postMessage pattern for PDF rendering; no suspicious network activity. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase from bundling @embedpdf PDF engine with WASM; expected. | ai | |
| source-diff | obfuscated-file:dist/direct-engine-CzzT8DSZ-cf7e226e.js | AI (source-diff): Bundled WASM/PDF engine from @embedpdf; minified build output, not obfuscation. | ai | |
| phantom-deps | phantom-dep:sass | AI (phantom-deps): sass is a build-time preprocessor referenced in vite config; phantom-dep is a stable false positive here. | ai | |
| phantom-deps | phantom-dep:vue-router | AI (phantom-deps): Config-file reference; Vue component libraries commonly reference router in config without direct imports. | ai | |
| phantom-deps | phantom-dep:@newview/ui | AI (phantom-deps): Same-org scoped package; phantom-dep heuristic is unreliable for intra-org dependencies. | ai | |
| phantom-deps | phantom-dep:view-ui-plus | AI (phantom-deps): Config-file reference only; stable false positive for this Vue UI library. | ai | |
| phantom-deps | phantom-dep:@vueup/vue-quill | AI (phantom-deps): Config-file reference only; stable false positive for this Vue UI library. | ai | |
| phantom-deps | phantom-dep:linq | AI (phantom-deps): Config-file reference only; not a runtime import concern for this build-tool pattern. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 1.1.63 | 14 / 9 | |
| 1.1.62 | 13 / 9 | |
| 1.1.60 | 13 / 9 | |
| 1.1.57 | 13 / 9 | |
| 1.1.54 | 13 / 9 | |
| 1.1.53 | 13 / 9 | |
| 1.1.51 | 13 / 9 | |
| 1.1.50 | 13 / 9 |
v1.1.63
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.62
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.60
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.57
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.54
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.53
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.51
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.1.50
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.