← Home

@vercel/og

8
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

mattjaredjeffrafterjulianbenegas3mdistalijjkquietshuah100101nandafyijooliashicmeyer_verceljankaiferuchenkadicodemknichel-vercelsouporseriousofhousealejandro-vercelchris-tsongas-vercelbalazsorbanandymckaytmickleydoylecorrettojscond0rkevinrupertjanecakemasterraunofreibergjoebell93smaeda-ksmanovotnytbremervercel-release-botvvotcc-sejohnsonjueungracetobiaslinstimolinscfofiutjkohliemilkowalskitorirusselltsiegemehulkargnoffshaquilhansfordmrkevdrcmdakit-fosterhellojennifertranaidenschrockwepanicinapewmaxleitersr_internchris-olszewskiwbinnssmithcalebboydgargis5dummdidummadriancooney_vercelbrookemosbyamyeganonebutterhenryheffernanalexkirszbvred4244jridgewellcb1kenobijasonwikersebastianrominganthonyshewokikiobroooooklynypessoazlw241nalalamimbrakkenwyattjohpearlbeagt-codeshannesbornoethomsonlubakravcheaaronbrown-vercelreconbotjavierbytekayernycjanorycodyogdendcartertwofeedthejimtilly3gwitsmegbirdfeugydizzyupedgarcerecerezvlivcarmansambeckercraigandrewsmjakobischloe.tedderkale-stewpbtodaniel.campbellarian-vercelnutaalmonksamselikoffbaruchadiejcaaorrisdoqueryantonathanhammondsnokohnjohnphamoustknickmanagadzikthomcroweemeraldsantoecklftimeyoutakeitcramforcebalazs4casey.gowriesamuel.fosterswarnavasenguptalydiahallieethan_arrowoodmitchellwrightkwonojkakadiadarpanendangeredmassanick.traceycrowterligsoltisschlezepallerolsdomyseenwienertarbwgudmundurmarcgreenstockstephdietzfalcoagustinnabsulbmealeybrethudsonmaedahbatooljasongullicksonf3d0rgaspar09jtaylor0196pieparkerdferber90healeycodesbroph123codybrouwersebb-tidegdbortonmsimulcikjeffreyarnesonjaredpalmerkikobeatsdomecclestonnutlopehungrybearstudiomattcleggkaragkiaourisgeovanisouza92dglsparsonspralhad-vercelwilliamlisouthpolestevegoncychibicodeandybitziamevilrabbittootallnatestyflemglagolajavivelascotimerluclerayleerobinsonmatheussnkzawaanatrajkovskatimneutkenselsighcl3arglasssamsislechriswdmrrizbizkitsernestdismaelrumzanmrmckebkuvoscreationixrauchghuozhicmvnklfadespaulogdmktcarterokbelpadmaiamsweeneydevdelbacatsaremlgsteventeysokragsandhudbredvickkdy1matt.strakazeit-bot

Keywords

open graph imageopen graphog imageog:imagesocialcardimage

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/index.edge.js AI (source-diff): base64 resvg.wasm vendored into bundle; expected for this renderer. ai
source-diff encoded-string-file:dist/index.node.js AI (source-diff): base64 resvg.wasm vendored into bundle; expected for this renderer. ai
source-diff source-size-tripled AI (source-diff): size growth from vendored wasm binary, benign. ai
npm-metadata bundled-binaries AI (npm-metadata): resvg.wasm is the documented SVG-rendering wasm dependency; stable for this package. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'joi'. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Official @vercel scoped package; Levenshtein match to 'pg' is a false positive with no plausible impersonation. ai
phantom-deps phantom-dep:@resvg/resvg-wasm AI (phantom-deps): Platform-specific WASM binary dependency; declared as runtime dep and bundled via copy script, not directly imported in source. ai
typosquat typosquat.levenshtein:zod AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'zod'. ai
typosquat typosquat.levenshtein:koa AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'koa'. ai
typosquat typosquat.levenshtein:got AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'got'. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'qs'. ai

Versions (showing 8 of 8)

Version Deps Published
0.11.1 2 / 4
0.11.0 2 / 4
0.10.1 2 / 4
0.10.0 2 / 4
0.9.0 2 / 4
0.8.6 2 / 4
0.8.3 2 / 4
0.8.2 2 / 4

v0.11.0

3 findings
HIGH Long encoded string in modified file: dist/index.edge.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.node.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.1

3 findings
HIGH Long encoded string in modified file: dist/index.edge.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.node.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.10.0

3 findings
HIGH Long encoded string in modified file: dist/index.edge.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.node.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.9.0

3 findings
HIGH Long encoded string in modified file: dist/index.edge.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.node.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.6

3 findings
HIGH Long encoded string in modified file: dist/index.edge.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: dist/index.node.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.3

2 findings
HIGH Bundled binary files (1) npm-metadata

Package contains compiled binaries that could be backdoors: • dist/resvg.wasm

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.