← Home

@vitessce/comparative

This folder contains a sub-package which: - re-exports all of the entries from `vitessce` (i.e., the exports of the subpackage located in `packages/main/prod`) - plus, exports controlled and un-controlled variants of a component that wraps `<Vitessce/>` f

10
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/lerc-BIJmc6fl.js AI (source-diff): Esri LERC codec vendor bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-D_tJZ2DX.js AI (source-diff): Bundled sub-module, minified build output. ai
source-diff net-exec-file:dist/index-2HxK8U2z.js AI (source-diff): Bundled output, no malicious behavior evidenced. ai
source-diff obfuscated-file:dist/index-2HxK8U2z.js AI (source-diff): Vite-bundled main chunk, minified not obfuscated. ai
source-diff net-exec-file:dist/higlass-DJTjCY0s.js AI (source-diff): Bundled viz lib, no concrete malicious network+exec behavior. ai
source-diff obfuscated-file:dist/higlass-DJTjCY0s.js AI (source-diff): Bundled vendor code (higlass/promise polyfill), not obfuscation. ai
source-diff net-exec-file:dist/ReactNeuroglancer-Bg6A0u4L.js AI (source-diff): Bundled neuroglancer viewer code, no malicious behavior. ai
source-diff obfuscated-file:dist/higlass-DHc5-L51.js AI (source-diff): Bundled third-party lib (higlass), minified not obfuscated. ai
source-diff net-exec-file:dist/ReactNeuroglancer-UbR-Ehra.js AI (source-diff): Bundled neuroglancer viewer lib. ai
source-diff obfuscated-file:dist/lerc-Bj34z9Qs.js AI (source-diff): Bundled Esri LERC codec lib. ai
source-diff net-exec-file:dist/index-cJZeOqnJ.js AI (source-diff): Bundled chunk with normal fetch/wasm code. ai
source-diff obfuscated-file:dist/index-cJZeOqnJ.js AI (source-diff): Main bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-BLxG4AHN.js AI (source-diff): Bundled build output. ai
source-diff net-exec-file:dist/higlass-DHc5-L51.js AI (source-diff): Bundled viz lib with fetch/wasm loading, not a dropper. ai
source-diff net-exec-file:dist/higlass-D6CnhtOV.js AI (source-diff): Bundled viewer lib; network+eval patterns are standard bundler/runtime code. ai
source-diff net-exec-file:dist/ReactNeuroglancer-DIEM_zJZ.js AI (source-diff): Bundled Neuroglancer viewer wrapper, standard patterns. ai
source-diff obfuscated-file:dist/lerc-CxXz0epg.js AI (source-diff): Esri LERC codec bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-D1nv5RxH.js AI (source-diff): three.js/react-three-fiber bundle, minified not obfuscated. ai
source-diff net-exec-file:dist/index-BK52HWA4.js AI (source-diff): Main vite bundle; no malicious behavior found in sample. ai
source-diff obfuscated-file:dist/index-BK52HWA4.js AI (source-diff): Main vite bundle, minified not obfuscated. ai
source-diff obfuscated-file:dist/higlass-D6CnhtOV.js AI (source-diff): Bundled minified higlass viewer code, not true obfuscation. ai
source-diff obfuscated-file:dist/higlass-B2khB7Nj.js AI (source-diff): Bundled third-party lib (higlass) minified output, not obfuscation. ai
source-diff net-exec-file:dist/ReactNeuroglancer-Cs2epjxP.js AI (source-diff): Bundled neuroglancer wrapper; no concrete malicious behavior identified. ai
source-diff obfuscated-file:dist/lerc-BPxUHtEx.js AI (source-diff): Esri lerc decoder library bundled, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-DtnIW1ir.js AI (source-diff): Bundled chunk, minified build output. ai
source-diff net-exec-file:dist/index-C-6liJcn.js AI (source-diff): Bundled output; pattern-match false positive. ai
source-diff net-exec-file:dist/higlass-B2khB7Nj.js AI (source-diff): Generic bundled code pattern, no concrete exfil/dropper behavior found. ai
source-diff obfuscated-file:dist/index-C-6liJcn.js AI (source-diff): Main vite-bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/higlass-BEH4mkyQ.js AI (source-diff): Bundled vendor code (higlass/react-dom), not true obfuscation. ai
source-diff net-exec-file:dist/higlass-BEH4mkyQ.js AI (source-diff): Bundled vendor library, fetch+eval pattern is normal wasm/polyfill loading. ai
source-diff obfuscated-file:dist/index-B647KJHU.js AI (source-diff): Vite-bundled chunk, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-CAwdUct2.js AI (source-diff): Main bundled vendor chunk (react etc), minified build output. ai
source-diff net-exec-file:dist/index-CAwdUct2.js AI (source-diff): Bundled vendor code; no evidence of malicious network exfil target. ai
source-diff obfuscated-file:dist/lerc-BouNgUty.js AI (source-diff): Esri LERC wasm codec bundle, minified not malicious. ai
source-diff net-exec-file:dist/ReactNeuroglancer-QJktSXqC.js AI (source-diff): Bundled neuroglancer viewer library, standard wasm fetch pattern. ai
source-diff obfuscated-file:dist/index-Ce5JOk5t.js AI (source-diff): Main bundled output of the package build, not obfuscation. ai
source-diff net-exec-file:dist/index-Ce5JOk5t.js AI (source-diff): Bundled output containing legit network/wasm loading code. ai
source-diff obfuscated-file:dist/index-Dmp8XDxB.js AI (source-diff): Bundled chunk, standard Vite build output. ai
source-diff obfuscated-file:dist/lerc-IcvUBGkp.js AI (source-diff): Bundled third-party codec (lerc/Esri), not obfuscation. ai
source-diff net-exec-file:dist/ReactNeuroglancer-BXqSFHUD.js AI (source-diff): Bundled neuroglancer wasm loader, standard pattern. ai
publish-pattern new-deps-added AI (publish-pattern): Same-org @vitessce/* packages plus common libs, part of monorepo build restructure. ai
source-diff net-exec-file:dist/higlass-BBW7WDEo.js AI (source-diff): Bundled dep with wasm/network fetch pattern, not dropper. ai
source-diff obfuscated-file:dist/higlass-BBW7WDEo.js AI (source-diff): Bundled vendor lib (higlass), not true obfuscation. ai
source-diff net-exec-file:dist/higlass-DA6D2z7x.js AI (source-diff): Network calls and dynamic code in HiGlass bundle are part of normal visualization library functionality, not malware. ai
source-diff net-exec-file:dist/ReactNeuroglancer-DVTouLdy.js AI (source-diff): ReactNeuroglancer bundle; network/dynamic patterns are part of the Neuroglancer 3D viewer functionality. ai
source-diff obfuscated-file:dist/lerc-C__sKrTH.js AI (source-diff): LERC (Esri raster codec) bundled as minified output; expected for geospatial visualization library. ai
source-diff net-exec-file:dist/index-D10X079V.js AI (source-diff): Network/dynamic patterns in main bundle are part of vitessce's data-fetching visualization functionality. ai
source-diff obfuscated-file:dist/index-D10X079V.js AI (source-diff): Main Vite bundle for vitessce; minified output is expected and consistent with prior releases. ai
source-diff obfuscated-file:dist/index-CtfYbkUc.js AI (source-diff): Standard Vite bundle output for vitessce component; minification is expected. ai
source-diff obfuscated-file:dist/higlass-DA6D2z7x.js AI (source-diff): Standard Vite bundle of HiGlass visualization library; minified output is expected for this package. ai
source-diff obfuscated-file:dist/zstd-DoGJTjDa.js AI (source-diff): Bundled zstd codec; minification expected. ai
provenance publisher-changed AI (provenance): Monorepo migrated to GitHub Actions CI publishing; SLSA attestation confirms legitimate CI origin. ai
source-diff obfuscated-file:dist/index-ByPsZX9d.js AI (source-diff): Vite-bundled spatial viewer code; minification expected. ai
source-diff obfuscated-file:dist-tsc/ComparativeConfig.js AI (source-diff): TypeScript-compiled output with long lines; not obfuscated malware. ai
source-diff net-exec-file:dist/index-BlHlPnNM.js AI (source-diff): Main bundle uses fetch for data loading; standard for a viz toolkit. ai
source-diff obfuscated-file:dist/index-BlHlPnNM.js AI (source-diff): Main Vite bundle; minification is standard build output. ai
source-diff net-exec-file:dist/higlass-DaUGvOUd.js AI (source-diff): higlass bundle legitimately uses fetch + dynamic rendering; not malware. ai
source-diff obfuscated-file:dist/higlass-DaUGvOUd.js AI (source-diff): Bundled higlass visualization library; minification expected. ai
source-diff obfuscated-file:dist/blosc-DKW2fp0s.js AI (source-diff): Vite-bundled WASM codec; minification is expected for this package. ai
source-diff net-exec-file:dist/ReactNeuroglancer-BtggQLeE.js AI (source-diff): ReactNeuroglancer is a known 3D neuroscience viewer; network+rendering is expected. ai
source-diff obfuscated-file:dist/lz4-D5NbssRf.js AI (source-diff): Bundled LZ4 codec; minification expected. ai
source-diff obfuscated-file:dist/lerc-RGuForS6.js AI (source-diff): Bundled LERC codec (Esri); minification expected. ai
phantom-deps phantom-dep:@vitessce/zarr AI (phantom-deps): Same-org monorepo sibling; may be re-exported rather than directly imported. ai
phantom-deps phantom-dep:internmap AI (phantom-deps): Likely used transitively or via re-export in this monorepo package. ai
phantom-deps phantom-dep:@vitessce/constants-internal AI (phantom-deps): Same-org monorepo sibling; re-export pattern is expected. ai
phantom-deps phantom-dep:@vitessce/abstract AI (phantom-deps): Same-org monorepo sibling; re-export pattern is expected. ai
phantom-deps phantom-dep:@vitessce/error AI (phantom-deps): Same-org monorepo sibling; re-export pattern is expected. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; sparse README and no keywords are expected for internal scoped packages. ai
phantom-deps phantom-dep:react-window AI (phantom-deps): Likely used transitively or via re-export in this monorepo package. ai

Versions (showing 10 of 10)

Version Deps Published
4.0.0 16 / 5
3.9.11 16 / 5
3.9.10 16 / 5
3.9.9 16 / 5
3.9.8 16 / 5
3.9.7 16 / 5
3.9.6 16 / 5
3.9.5 16 / 5
3.9.4 16 / 5
0.0.1 0 / 1

v4.0.0

8 findings
HIGH New obfuscated file: dist/higlass-D6CnhtOV.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/higlass-D6CnhtOV.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BK52HWA4.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BK52HWA4.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-D1nv5RxH.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lerc-CxXz0epg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ReactNeuroglancer-DIEM_zJZ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.6

9 findings
HIGH New obfuscated file: dist/higlass-BEH4mkyQ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/higlass-BEH4mkyQ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B647KJHU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-CAwdUct2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-CAwdUct2.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BouNgUty.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ReactNeuroglancer-QJktSXqC.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-03-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.5

9 findings
HIGH New obfuscated file: dist/higlass-DHc5-L51.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/higlass-DHc5-L51.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BLxG4AHN.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index-cJZeOqnJ.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-cJZeOqnJ.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-Bj34z9Qs.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ReactNeuroglancer-UbR-Ehra.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.4

9 findings
HIGH New obfuscated file: dist/higlass-BBW7WDEo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/higlass-BBW7WDEo.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Ce5JOk5t.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-Ce5JOk5t.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-Dmp8XDxB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lerc-IcvUBGkp.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ReactNeuroglancer-BXqSFHUD.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.