@vercel/og
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/index.edge.js | AI (source-diff): base64 resvg.wasm vendored into bundle; expected for this renderer. | ai | |
| source-diff | encoded-string-file:dist/index.node.js | AI (source-diff): base64 resvg.wasm vendored into bundle; expected for this renderer. | ai | |
| source-diff | source-size-tripled | AI (source-diff): size growth from vendored wasm binary, benign. | ai | |
| npm-metadata | bundled-binaries | AI (npm-metadata): resvg.wasm is the documented SVG-rendering wasm dependency; stable for this package. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'joi'. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Official @vercel scoped package; Levenshtein match to 'pg' is a false positive with no plausible impersonation. | ai | |
| phantom-deps | phantom-dep:@resvg/resvg-wasm | AI (phantom-deps): Platform-specific WASM binary dependency; declared as runtime dep and bundled via copy script, not directly imported in source. | ai | |
| typosquat | typosquat.levenshtein:zod | AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'zod'. | ai | |
| typosquat | typosquat.levenshtein:koa | AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'koa'. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'got'. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Official @vercel scoped package; no plausible impersonation of 'qs'. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 0.11.1 | 2 / 4 | |
| 0.11.0 | 2 / 4 | |
| 0.10.1 | 2 / 4 | |
| 0.10.0 | 2 / 4 | |
| 0.9.0 | 2 / 4 | |
| 0.8.6 | 2 / 4 | |
| 0.8.3 | 2 / 4 | |
| 0.8.2 | 2 / 4 |
v0.11.0
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.1
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.0
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.0
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.6
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.8.3
2 findingsPackage contains compiled binaries that could be backdoors: • dist/resvg.wasm
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.