@picovoice/picovoice-web
Picovoice SDK for web browsers (via WebAssembly)
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/esm/index.js | AI (source-diff): Base64 wake-word/model data constants in official Picovoice SDK, not obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/esm/index.min.js | AI (source-diff): Minified bundle output containing same base64 data constants; not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/iife/index.js | AI (source-diff): Base64 wake-word/model data constants in official Picovoice SDK, not obfuscated payload. | ai | |
| source-diff | encoded-string-file:dist/iife/index.min.js | AI (source-diff): Minified bundle output containing same base64 data constants; not obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): Established Picovoice SDK package with 1339-day history; lack of Sigstore provenance is common and not a risk signal for this package. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 3.0.3 | 3 / 23 | |
| 3.0.2 | 3 / 23 | |
| 3.0.1 | 3 / 23 | |
| 3.0.0 | 3 / 23 |
v3.0.2
5 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.