← Home

@pmndrs/msdfonts

8
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

abernierpmndrs01drcmdabjornstardennissmolekbela-bohlenderisaacmasonkrispyaa

Keywords

fontsuikiticonsthreejsr3fmsdf

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/crimsonText.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/firaCode.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/inconsolata.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/inter.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/lato.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/libreBaskerville.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/merriweather.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/montserrat.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/nunito.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/openSans.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/playfairDisplay.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/poppins.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/raleway.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/roboto.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/sourceCodePro.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/spaceMono.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff obfuscated-file:dist/workSans.js AI (source-diff): Long lines are base64-encoded WebP font atlas data; expected for MSDF font distribution. ai
source-diff large-new-source-files AI (source-diff): New font files added as package expands its font catalog; consistent with package purpose. ai

Versions (showing 8 of 8)

Version Deps Published
1.0.73 0 / 0
1.0.72 0 / 0
1.0.71 0 / 0
1.0.70 0 / 0
1.0.69 0 / 0
1.0.68 0 / 0
1.0.67 0 / 0
1.0.66 0 / 0

v1.0.73

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.72

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.71

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.70

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.69

18 findings
HIGH New obfuscated file: dist/crimsonText.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/firaCode.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/inconsolata.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/inter.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lato.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/libreBaskerville.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/merriweather.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/montserrat.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/nunito.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/openSans.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/playfairDisplay.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/poppins.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/raleway.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/roboto.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/sourceCodePro.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/spaceMono.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/workSans.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.68

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.67

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.66

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.