← Home

@rive-app/webgl2

51
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

rive-engineeringluigi-rossoguidorossoavivian_rivephil_rive

Keywords

riveanimation

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
npm-metadata bundled-binaries AI (npm-metadata): rive.wasm/rive_fallback.wasm are the package's core runtime binaries; expected every version. ai

Versions (showing 51 of 124)

View all versions
Version Deps Published
2.39.1 0 / 0
2.39.0 0 / 0
2.38.5 0 / 0
2.38.4 0 / 0
2.38.3 0 / 0
2.38.2 0 / 0
2.38.1 0 / 0
2.38.0 0 / 0
2.37.8 0 / 0
2.37.7 0 / 0
2.37.6 0 / 0
2.37.5 0 / 0
2.37.4 0 / 0
2.37.3 0 / 0
2.37.2 0 / 0
2.37.1 0 / 0
2.37.0 0 / 0
2.36.0 0 / 0
2.35.4 0 / 0
2.35.3 0 / 0
2.35.2 0 / 0
2.35.1 0 / 0
2.35.0 0 / 0
2.34.3 0 / 0
2.34.2 0 / 0
2.34.1 0 / 0
2.34.0 0 / 0
2.33.3 0 / 0
2.33.2 0 / 0
2.33.1 0 / 0
2.33.0 0 / 0
2.32.2 0 / 0
2.32.1 0 / 0
2.32.0 0 / 0
2.31.6 0 / 0
2.31.5 0 / 0
2.31.4 0 / 0
2.31.3 0 / 0
2.31.2 0 / 0
2.31.1 0 / 0
2.31.0 0 / 0
2.30.4 0 / 0
2.30.3 0 / 0
2.30.2 0 / 0
2.30.1 0 / 0
2.30.0 0 / 0
2.29.4 0 / 0
2.29.3 0 / 0
2.29.2 0 / 0
2.29.1 0 / 0
2.29.0 0 / 0

v2.39.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.39.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.5

2 findings
HIGH Bundled binary files (2) npm-metadata

Package contains compiled binaries that could be backdoors: • rive_fallback.wasm • rive.wasm

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.38.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.