@picovoice/porcupine-vue
Vue binding for Porcupine Web SDK
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/esm/index.js | AI (source-diff): Base64 wake-word model constants (ALEXA_64 etc.), not hidden payloads. | ai | |
| source-diff | encoded-string-file:dist/esm/index.min.js | AI (source-diff): Minified bundle containing same model data; build output not obfuscation. | ai | |
| source-diff | encoded-string-file:dist/iife/index.js | AI (source-diff): Same embedded model constants as ESM build. | ai | |
| source-diff | encoded-string-file:dist/iife/index.min.js | AI (source-diff): Minified IIFE bundle, same benign encoded model data. | ai | |
| semgrep | semgrep:api-obfuscation-reflect | AI (semgrep): Reflect.get() is used inside a standard JavaScript Proxy trap handler — idiomatic pattern for forwarding property access, not obfuscation. Stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@picovoice/porcupine-web | AI (dependencies): First-party Picovoice dependency; the Vue binding naturally depends on the core Porcupine Web SDK from the same organization. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 3.0.3 | 1 / 29 | |
| 3.0.2 | 1 / 29 | |
| 3.0.1 | 1 / 29 | |
| 3.0.0 | 1 / 29 |
v3.0.2
5 findingsModified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.1
5 findingsModified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 17 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.