@scandit/web-datacapture-label
Scandit Data Capture SDK for the Web
9
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
scandit-lorenzoscandit-cimoritz-scanditscandit-sebastienscandit-thomas
Keywords
scanditbarcodedata capturecaptureqrscanscannerscanningcodewebassemblysdkjavascripttypescriptlabel capture
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:new-function-constructor | AI (semgrep): Emscripten-generated WASM JS glue; new Function() is standard in this build output across all Scandit SDK versions. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are ML model assets and WASM bundles expected for label-capture feature additions. | ai | |
| source-diff | obfuscated-file:build/js/NativeProxy-B98bIlIp.d.ts | AI (source-diff): Long lines are TypeScript declaration union-type imports, not obfuscated code; stable pattern for Scandit SDK packages. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scandit commercial SDK suite; templated naming and minimal README are expected patterns across their package family. | ai | |
| phantom-deps | phantom-dep:@types/emscripten | AI (phantom-deps): @types/emscripten is a type-only dependency for WebAssembly bindings; not directly imported at runtime by convention. | ai |