@perceptimagery/dita-configurator-staging
| An embeddable package for Dita's 3D configurator
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@perceptimagery/sprie-widget-auth | AI (dependencies): Same-org scoped package from established publisher; consistent across versions. | ai | |
| phantom-deps | phantom-dep:@perceptimagery/sprie-widget-auth | AI (phantom-deps): Same-org dep declared but not directly imported; consistent with other phantom deps in this package. | ai | |
| source-diff | encoded-string-file:dist/index.js | AI (source-diff): Long encoded strings are GSAP (GreenSock) minified animation library code, not obfuscated malware. | ai | |
| provenance | no-provenance | AI (provenance): Internal/private staging package; provenance attestation not expected for this org's workflow. | ai | |
| license | uncommon-license:UNLICENSED | AI (license): Intentionally proprietary/private package; UNLICENSED is expected for this org. | ai | |
| dependencies | unvetted-dep:@perceptimagery/3d-configurator | AI (dependencies): Same-org scoped package from the same publisher; expected internal dependency. | ai | |
| dependencies | unvetted-dep:dat.gui | AI (dependencies): dat.gui is a well-known open-source GUI library; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@perceptimagery/sprie-asset-auth | AI (dependencies): Same-org scoped package from the same publisher; expected internal dependency. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Peer/bundled dep in a Vite-built library; not directly imported in source is expected. | ai | |
| phantom-deps | phantom-dep:@perceptimagery/sprie-asset-auth | AI (phantom-deps): Same org scope; bundled/re-exported dep, stable false positive. | ai | |
| phantom-deps | phantom-dep:@perceptimagery/3d-configurator | AI (phantom-deps): Same org scope; bundled/re-exported dep, stable false positive. | ai | |
| phantom-deps | phantom-dep:dat.gui | AI (phantom-deps): Bundled in Vite output; phantom detection is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:events | AI (phantom-deps): Likely used transitively or in bundled output; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Peer/bundled dep in a Vite-built library; not directly imported in source is expected. | ai |
Versions (showing 21 of 21)
| Version | Deps | Published |
|---|---|---|
| 1.3.6011 | 6 / 20 | |
| 1.3.6005 | 6 / 20 | |
| 1.3.6003 | 6 / 20 | |
| 1.3.5003 | 6 / 20 | |
| 1.3.5001 | 6 / 20 | |
| 1.3.2001 | 6 / 20 | |
| 1.3.1009 | 6 / 20 | |
| 1.3.1007 | 6 / 20 | |
| 1.3.1005 | 6 / 20 | |
| 1.3.23 | 7 / 20 | |
| 1.3.22 | 7 / 20 | |
| 1.3.21 | 6 / 20 | |
| 1.3.19 | 6 / 20 | |
| 1.3.18 | 6 / 20 | |
| 1.3.17 | 6 / 20 | |
| 1.3.16 | 6 / 20 | |
| 1.3.14 | 6 / 20 | |
| 1.3.13 | 6 / 20 | |
| 1.3.9 | 6 / 20 | |
| 1.3.8 | 6 / 20 | |
| 1.3.7 | 6 / 20 |
v1.3.6011
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.6005
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.6003
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.5003
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.5001
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.2001
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1009
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1007
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.1005
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.23
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.22
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.3.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.3.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.