@vertexvis/viewer
The Vertex SDK for viewing models.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a well-known TypeScript runtime helper; implicit dependency is expected. | ai | |
| source-diff | obfuscated-file:dist/viewer/p-29f090db.entry.js | AI (source-diff): Stencil.js minified web component bundle; expected build output. | ai | |
| source-diff | obfuscated-file:dist/viewer/p-38ada1c0.js | AI (source-diff): Stencil.js minified web component bundle; expected build output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large Stencil SDK with many split bundle chunks; file count growth is expected. | ai | |
| source-diff | net-exec-file:dist/cjs/bundle.esm-1249b5ea.js | AI (source-diff): Standard protobuf/gRPC bundled output for Vertex SDK; not malware. | ai | |
| source-diff | net-exec-file:dist/esm/bundle.esm-769cd382.js | AI (source-diff): Standard protobuf/gRPC bundled output for Vertex SDK; not malware. | ai | |
| source-diff | net-exec-file:dist/cjs/controller-8f8877b1.js | AI (source-diff): Generated protobuf controller code; legitimate SDK artifact. | ai | |
| source-diff | net-exec-file:dist/esm/controller-fd0a5470.js | AI (source-diff): Generated protobuf controller code; legitimate SDK artifact. | ai | |
| source-diff | obfuscated-file:dist/viewer/p-00687e87.entry.js | AI (source-diff): Stencil.js minified web component bundle; expected build output. | ai | |
| source-diff | obfuscated-file:dist/viewer/p-04a3a38c.entry.js | AI (source-diff): Stencil.js minified web component bundle; expected build output. | ai | |
| source-diff | obfuscated-file:dist/viewer/p-04a7b833.entry.js | AI (source-diff): Stencil.js minified web component bundle; expected build output. | ai | |
| source-diff | obfuscated-file:dist/viewer/p-1d273379.js | AI (source-diff): Stencil.js minified web component bundle; expected build output. | ai | |
| source-diff | obfuscated-file:dist/viewer/p-20a0b0c6.entry.js | AI (source-diff): Stencil.js minified web component bundle; expected build output. | ai | |
| phantom-deps | phantom-dep:camel-case | AI (phantom-deps): camel-case is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:protobufjs | AI (phantom-deps): protobufjs is a declared runtime dep; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:threads | AI (phantom-deps): threads is a declared runtime dep used via web workers; phantom-dep heuristic fires on indirect import patterns. | ai |
v0.24.5
12 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.