← Home

@viamrobotics/motion-tools

Motion visualization with Viam

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cheuktstevebriskinviambotmicheal.parksmpviamnjoomadevin-viamale7714amaschas

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@connectrpc/connect AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@connectrpc/connect-web AI (phantom-deps): Config-referenced dependency; stable pattern for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): mcous removal paired with CI publishing transition; expected org maintainer rotation. ai
maintainer-change maintainer-added AI (maintainer-change): devin-viam is a viam-labs org member; legitimate team change. ai
dependencies unvetted-dep:koota AI (dependencies): koota is a well-known ECS library; use in a 3D motion visualization package is expected and benign. ai
publish-pattern new-deps-added AI (publish-pattern): filtrex is a legitimate expression parser replacing expr-eval; SLSA provenance confirms CI/CD publish integrity. ai
provenance slsa-provenance AI (provenance): SLSA provenance present; strongest supply chain integrity signal. ai
provenance publisher-changed AI (provenance): Org migrated publishing to GitHub Actions CI/CD with SLSA provenance; expected for viam-labs org automation. ai
source-diff obfuscated-file:dist/loaders/pcd/worker.inline.js AI (source-diff): Auto-generated bundled worker code from build-workers.js script; minification is expected for inlined web workers. ai
source-diff source-size-tripled AI (source-diff): Size increase explained by bundled Three.js worker and new 3D visualization features; consistent with added deps. ai
source-diff large-new-source-files AI (source-diff): 149 new files consistent with major feature expansion in a 3D motion visualization library. ai
dependencies unvetted-dep:uuid-tool AI (dependencies): uuid-tool is a benign UUID utility; no malicious history or suspicious behavior. ai
phantom-deps phantom-dep:earcut AI (phantom-deps): Svelte component library; earcut may be used indirectly via three.js/threlte ecosystem. ai
bogus-package bogus-package AI (bogus-package): Established Viam Labs package with 125 versions; sparse README is cosmetic, not a risk signal. ai
phantom-deps phantom-dep:@tanstack/svelte-query-devtools AI (phantom-deps): Declared runtime dep; Svelte component library import patterns may not be detected by static analysis. ai
phantom-deps phantom-dep:@neodrag/svelte AI (phantom-deps): Declared runtime dep; Svelte component library import patterns may not be detected by static analysis. ai
phantom-deps phantom-dep:filtrex AI (phantom-deps): Declared runtime dep; phantom-dep heuristic likely misses indirect import patterns in bundled Svelte output. ai

Versions (showing 51 of 71)

View all versions
Version Deps Published
1.37.0 8 / 87
1.36.2 8 / 86
1.36.1 8 / 86
1.36.0 8 / 86
1.35.1 8 / 86
1.35.0 8 / 86
1.34.10 8 / 86
1.34.9 8 / 86
1.34.8 8 / 86
1.34.7 8 / 84
1.34.6 8 / 84
1.34.5 8 / 83
1.34.4 8 / 83
1.34.3 8 / 83
1.34.2 12 / 81
1.34.1 12 / 81
1.34.0 12 / 81
1.33.2 8 / 81
1.33.1 8 / 81
1.33.0 7 / 80
1.32.0 7 / 80
1.31.0 10 / 77
1.30.0 10 / 77
1.29.1 11 / 76
1.29.0 11 / 76
1.28.1 11 / 75
1.28.0 11 / 75
1.27.1 11 / 75
1.25.4 11 / 75
1.25.3 11 / 75
1.25.2 11 / 75
1.25.1 11 / 75
1.25.0 11 / 75
1.24.0 11 / 75
1.23.1 11 / 75
1.23.0 11 / 75
1.22.0 11 / 75
1.21.0 11 / 75
1.19.1 11 / 73
1.19.0 11 / 73
1.18.1 11 / 73
1.18.0 11 / 73
1.16.0 11 / 72
1.15.7 11 / 72
1.15.5 11 / 72
1.13.0 11 / 71
1.2.1 6 / 65
1.2.0 6 / 65
1.1.6 6 / 65
1.1.5 6 / 65
1.1.4 6 / 63

v1.37.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.36.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.36.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.36.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.35.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.35.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.34.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.34.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.34.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.