← Home

@tsparticles/basic

27
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

matteobruni

Keywords

front-endfrontendtsparticlesparticles.jsparticlesjsparticlesparticlecanvasjsparticlesxparticlesparticles-jsparticles-bgparticles-bg-vueparticles-tsparticles.tsreact-particles-jsreact-particles.jsreact-particlesreactreactjsvue-particlesngx-particlesangular-particlesparticlegroundvuevuejspreactpreactjsjqueryangularjsangulartypescriptjavascriptanimationwebhtml5web-designwebdesigncsshtmlcss3animatedbackgroundconfetticanvasfireworksfireworks-jsconfetti-jsconfettijsfireworksjscanvas-confetti

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file-transition:tsparticles.basic.bundle.min.js AI (source-diff): minified webpack bundle; benign build output ai
semgrep semgrep:new-function-constructor AI (semgrep): standard globalThis polyfill in webpack runtime ai
source-diff large-new-source-files AI (source-diff): per-chunk browser dist bundles from legit build ai
source-diff net-exec-file-transition:tsparticles.basic.bundle.js AI (source-diff): webpack eval-devtool bundle module loader, not net+exec malware ai
source-diff obfuscated-file-transition:tsparticles.basic.bundle.js AI (source-diff): webpack minified bundle, not obfuscation ai
publish-pattern new-deps-added AI (publish-pattern): Same-org deps replacing removed ones in a major version bump; internal refactor. ai
provenance publisher-changed AI (provenance): Publisher moved to GitHub Actions CI/CD with SLSA provenance; legitimate automation transition. ai
dependencies unvetted-dep:@tsparticles/plugin-hex-color AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/plugin-hsl-color AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
semgrep semgrep:eval-usage AI (semgrep): eval calls are webpack devtool bundle artifacts, not dynamic user input; stable pattern across all tsparticles bundle packages. ai
dependencies unvetted-dep:@tsparticles/updater-out-modes AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/plugin-rgb-color AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/engine AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/move-base AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/shape-circle AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/updater-size AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/updater-color AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai
dependencies unvetted-dep:@tsparticles/updater-opacity AI (dependencies): First-party sibling package from the same tsparticles monorepo and publisher. ai

Versions (showing 27 of 27)

Version Deps Published
4.3.2 11 / 0
4.3.1 11 / 0
4.3.0 11 / 0
4.2.1 11 / 0
4.2.0 11 / 0
4.1.3 11 / 0
4.1.2 11 / 0
4.1.1 11 / 0
4.1.0 11 / 0
4.0.5 11 / 0
4.0.4 11 / 0
4.0.3 11 / 0
4.0.2 10 / 0
4.0.1 10 / 0
4.0.0 10 / 0
3.9.1 10 / 0
3.9.0 10 / 0
3.7.0 10 / 0
3.6.0 7 / 0
3.5.0 7 / 0
3.4.0 7 / 0
3.2.1 7 / 0
3.1.0 7 / 0
3.0.3 7 / 0
3.0.2 7 / 0
3.0.1 7 / 0
3.0.0 7 / 0

v4.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: matteobruni.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.6.0

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: matteobruni.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.2.1

20 findings
HIGH New obfuscated file: engine_dist_browser_Core_Container_js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: engine_dist_browser_Core_Container_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: engine_dist_browser_Core_Particle_js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: engine_dist_browser_Core_Particle_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: move_base_dist_browser_Utils_js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New file with network + code execution: move_base_dist_browser_Utils_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH New obfuscated file: updaters_outModes_dist_browser_OutOutMode_js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New file with network + code execution: updaters_outModes_dist_browser_OutOutMode_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: move_base_dist_browser_BaseMover_js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New file with network + code execution: move_base_dist_browser_BaseMover_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: updaters_outModes_dist_browser_Utils_js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New file with network + code execution: updaters_outModes_dist_browser_Utils_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New obfuscated file: updaters_outModes_dist_browser_OutOfCanvasUpdater_js.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New file with network + code execution: updaters_outModes_dist_browser_OutOfCanvasUpdater_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New file with network + code execution: updaters_outModes_dist_browser_NoneOutMode_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH New file with network + code execution: updaters_opacity_dist_browser_OpacityUpdater_js.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — minified bundler output, not obfuscation on its own.

HIGH Modified file became obfuscated: tsparticles.basic.bundle.js source-diff

This file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH Modified file gained network + code execution: tsparticles.basic.bundle.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.

HIGH Modified file gained network + code execution: tsparticles.basic.bundle.min.js source-diff

This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.