@scandit/web-datacapture-core
Scandit Data Capture SDK for the Web
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@types/howler | AI (dependencies): @types/howler is a DefinitelyTyped type-definition package; no runtime risk for this SDK. | ai | |
| phantom-deps | phantom-dep:howler | AI (phantom-deps): Bundled SDK loads howler at runtime; phantom-dep is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:js-cookie | AI (phantom-deps): Bundled SDK loads js-cookie at runtime; stable false positive. | ai | |
| phantom-deps | phantom-dep:@types/howler | AI (phantom-deps): Type-only dep used by bundler/tsc; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/js-cookie | AI (phantom-deps): Type-only dep used by bundler/tsc; stable false positive for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Commercial SDK publisher with templated package names and minimal README is expected for Scandit's SDK family. | ai | |
| phantom-deps | phantom-dep:@types/emscripten | AI (phantom-deps): Type-only dep for Emscripten WASM bindings; convention-loaded, stable FP for this package. | ai | |
| phantom-deps | phantom-dep:@types/ua-parser-js | AI (phantom-deps): Type-only companion to ua-parser-js; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:wasm-feature-detect | AI (phantom-deps): WASM feature detection dep referenced in config; stable FP for this SDK package. | ai | |
| phantom-deps | phantom-dep:@types/offscreencanvas | AI (phantom-deps): Type-only dep for OffscreenCanvas Web API; convention-loaded, stable FP for this package. | ai | |
| phantom-deps | phantom-dep:ua-parser-js | AI (phantom-deps): Runtime dep used via bundled WASM lib; not directly imported in TS source but legitimately declared. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 8.3.1 | 6 / 0 | |
| 8.3.0 | 6 / 0 | |
| 8.1.4 | 10 / 0 | |
| 8.0.1 | 10 / 0 | |
| 8.0.0 | 10 / 0 | |
| 7.6.14 | 10 / 0 | |
| 7.6.13 | 10 / 0 | |
| 7.6.12 | 10 / 0 | |
| 7.6.11 | 10 / 0 | |
| 7.6.10 | 10 / 0 | |
| 7.6.7 | 10 / 0 | |
| 7.6.6 | 10 / 0 | |
| 7.6.5 | 10 / 0 | |
| 7.6.4 | 10 / 0 | |
| 7.5.2 | 10 / 0 | |
| 7.4.4 | 10 / 0 | |
| 7.3.4 | 10 / 0 | |
| 7.2.6 | 10 / 0 | |
| 7.2.5 | 10 / 0 |
v8.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.1.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.6.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.6.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.6.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.6.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v7.6.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.6.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.6.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.5.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.4.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.3.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v7.2.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.