@picovoice/picovoice-react
React component for Picovoice SDK for Web
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/esm/index.js | AI (source-diff): Base64 wake-word/model data bundled in build output, not obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/esm/index.min.js | AI (source-diff): Minified bundle containing same base64 model data. | ai | |
| source-diff | encoded-string-file:dist/iife/index.js | AI (source-diff): Base64 wake-word/model data bundled in build output, not obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/iife/index.min.js | AI (source-diff): Minified bundle containing same base64 model data. | ai | |
| dependencies | unvetted-dep:@picovoice/picovoice-web | AI (dependencies): First-party Picovoice dependency; this React wrapper is designed to wrap @picovoice/picovoice-web. Stable relationship across all versions. | ai | |
| dependencies | unvetted-peer-dep:@picovoice/web-voice-processor | AI (dependencies): First-party Picovoice peer dependency; expected for this SDK wrapper package. Stable relationship across all versions. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 3.0.3 | 1 / 31 | |
| 3.0.2 | 1 / 31 | |
| 3.0.1 | 1 / 31 | |
| 3.0.0 | 1 / 31 |
v3.0.2
5 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
5 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.