@vitessce/comparative
This folder contains a sub-package which: - re-exports all of the entries from `vitessce` (i.e., the exports of the subpackage located in `packages/main/prod`) - plus, exports controlled and un-controlled variants of a component that wraps `<Vitessce/>` f
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/lerc-BIJmc6fl.js | AI (source-diff): Esri LERC codec vendor bundle, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-D_tJZ2DX.js | AI (source-diff): Bundled sub-module, minified build output. | ai | |
| source-diff | net-exec-file:dist/index-2HxK8U2z.js | AI (source-diff): Bundled output, no malicious behavior evidenced. | ai | |
| source-diff | obfuscated-file:dist/index-2HxK8U2z.js | AI (source-diff): Vite-bundled main chunk, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/higlass-DJTjCY0s.js | AI (source-diff): Bundled viz lib, no concrete malicious network+exec behavior. | ai | |
| source-diff | obfuscated-file:dist/higlass-DJTjCY0s.js | AI (source-diff): Bundled vendor code (higlass/promise polyfill), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-Bg6A0u4L.js | AI (source-diff): Bundled neuroglancer viewer code, no malicious behavior. | ai | |
| source-diff | obfuscated-file:dist/higlass-DHc5-L51.js | AI (source-diff): Bundled third-party lib (higlass), minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-UbR-Ehra.js | AI (source-diff): Bundled neuroglancer viewer lib. | ai | |
| source-diff | obfuscated-file:dist/lerc-Bj34z9Qs.js | AI (source-diff): Bundled Esri LERC codec lib. | ai | |
| source-diff | net-exec-file:dist/index-cJZeOqnJ.js | AI (source-diff): Bundled chunk with normal fetch/wasm code. | ai | |
| source-diff | obfuscated-file:dist/index-cJZeOqnJ.js | AI (source-diff): Main bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-BLxG4AHN.js | AI (source-diff): Bundled build output. | ai | |
| source-diff | net-exec-file:dist/higlass-DHc5-L51.js | AI (source-diff): Bundled viz lib with fetch/wasm loading, not a dropper. | ai | |
| source-diff | net-exec-file:dist/higlass-D6CnhtOV.js | AI (source-diff): Bundled viewer lib; network+eval patterns are standard bundler/runtime code. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-DIEM_zJZ.js | AI (source-diff): Bundled Neuroglancer viewer wrapper, standard patterns. | ai | |
| source-diff | obfuscated-file:dist/lerc-CxXz0epg.js | AI (source-diff): Esri LERC codec bundle, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-D1nv5RxH.js | AI (source-diff): three.js/react-three-fiber bundle, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/index-BK52HWA4.js | AI (source-diff): Main vite bundle; no malicious behavior found in sample. | ai | |
| source-diff | obfuscated-file:dist/index-BK52HWA4.js | AI (source-diff): Main vite bundle, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/higlass-D6CnhtOV.js | AI (source-diff): Bundled minified higlass viewer code, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/higlass-B2khB7Nj.js | AI (source-diff): Bundled third-party lib (higlass) minified output, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-Cs2epjxP.js | AI (source-diff): Bundled neuroglancer wrapper; no concrete malicious behavior identified. | ai | |
| source-diff | obfuscated-file:dist/lerc-BPxUHtEx.js | AI (source-diff): Esri lerc decoder library bundled, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-DtnIW1ir.js | AI (source-diff): Bundled chunk, minified build output. | ai | |
| source-diff | net-exec-file:dist/index-C-6liJcn.js | AI (source-diff): Bundled output; pattern-match false positive. | ai | |
| source-diff | net-exec-file:dist/higlass-B2khB7Nj.js | AI (source-diff): Generic bundled code pattern, no concrete exfil/dropper behavior found. | ai | |
| source-diff | obfuscated-file:dist/index-C-6liJcn.js | AI (source-diff): Main vite-bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/higlass-BEH4mkyQ.js | AI (source-diff): Bundled vendor code (higlass/react-dom), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/higlass-BEH4mkyQ.js | AI (source-diff): Bundled vendor library, fetch+eval pattern is normal wasm/polyfill loading. | ai | |
| source-diff | obfuscated-file:dist/index-B647KJHU.js | AI (source-diff): Vite-bundled chunk, minified not obfuscated. | ai | |
| source-diff | obfuscated-file:dist/index-CAwdUct2.js | AI (source-diff): Main bundled vendor chunk (react etc), minified build output. | ai | |
| source-diff | net-exec-file:dist/index-CAwdUct2.js | AI (source-diff): Bundled vendor code; no evidence of malicious network exfil target. | ai | |
| source-diff | obfuscated-file:dist/lerc-BouNgUty.js | AI (source-diff): Esri LERC wasm codec bundle, minified not malicious. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-QJktSXqC.js | AI (source-diff): Bundled neuroglancer viewer library, standard wasm fetch pattern. | ai | |
| source-diff | obfuscated-file:dist/index-Ce5JOk5t.js | AI (source-diff): Main bundled output of the package build, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/index-Ce5JOk5t.js | AI (source-diff): Bundled output containing legit network/wasm loading code. | ai | |
| source-diff | obfuscated-file:dist/index-Dmp8XDxB.js | AI (source-diff): Bundled chunk, standard Vite build output. | ai | |
| source-diff | obfuscated-file:dist/lerc-IcvUBGkp.js | AI (source-diff): Bundled third-party codec (lerc/Esri), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-BXqSFHUD.js | AI (source-diff): Bundled neuroglancer wasm loader, standard pattern. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Same-org @vitessce/* packages plus common libs, part of monorepo build restructure. | ai | |
| source-diff | net-exec-file:dist/higlass-BBW7WDEo.js | AI (source-diff): Bundled dep with wasm/network fetch pattern, not dropper. | ai | |
| source-diff | obfuscated-file:dist/higlass-BBW7WDEo.js | AI (source-diff): Bundled vendor lib (higlass), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/higlass-DA6D2z7x.js | AI (source-diff): Network calls and dynamic code in HiGlass bundle are part of normal visualization library functionality, not malware. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-DVTouLdy.js | AI (source-diff): ReactNeuroglancer bundle; network/dynamic patterns are part of the Neuroglancer 3D viewer functionality. | ai | |
| source-diff | obfuscated-file:dist/lerc-C__sKrTH.js | AI (source-diff): LERC (Esri raster codec) bundled as minified output; expected for geospatial visualization library. | ai | |
| source-diff | net-exec-file:dist/index-D10X079V.js | AI (source-diff): Network/dynamic patterns in main bundle are part of vitessce's data-fetching visualization functionality. | ai | |
| source-diff | obfuscated-file:dist/index-D10X079V.js | AI (source-diff): Main Vite bundle for vitessce; minified output is expected and consistent with prior releases. | ai | |
| source-diff | obfuscated-file:dist/index-CtfYbkUc.js | AI (source-diff): Standard Vite bundle output for vitessce component; minification is expected. | ai | |
| source-diff | obfuscated-file:dist/higlass-DA6D2z7x.js | AI (source-diff): Standard Vite bundle of HiGlass visualization library; minified output is expected for this package. | ai | |
| source-diff | obfuscated-file:dist/zstd-DoGJTjDa.js | AI (source-diff): Bundled zstd codec; minification expected. | ai | |
| provenance | publisher-changed | AI (provenance): Monorepo migrated to GitHub Actions CI publishing; SLSA attestation confirms legitimate CI origin. | ai | |
| source-diff | obfuscated-file:dist/index-ByPsZX9d.js | AI (source-diff): Vite-bundled spatial viewer code; minification expected. | ai | |
| source-diff | obfuscated-file:dist-tsc/ComparativeConfig.js | AI (source-diff): TypeScript-compiled output with long lines; not obfuscated malware. | ai | |
| source-diff | net-exec-file:dist/index-BlHlPnNM.js | AI (source-diff): Main bundle uses fetch for data loading; standard for a viz toolkit. | ai | |
| source-diff | obfuscated-file:dist/index-BlHlPnNM.js | AI (source-diff): Main Vite bundle; minification is standard build output. | ai | |
| source-diff | net-exec-file:dist/higlass-DaUGvOUd.js | AI (source-diff): higlass bundle legitimately uses fetch + dynamic rendering; not malware. | ai | |
| source-diff | obfuscated-file:dist/higlass-DaUGvOUd.js | AI (source-diff): Bundled higlass visualization library; minification expected. | ai | |
| source-diff | obfuscated-file:dist/blosc-DKW2fp0s.js | AI (source-diff): Vite-bundled WASM codec; minification is expected for this package. | ai | |
| source-diff | net-exec-file:dist/ReactNeuroglancer-BtggQLeE.js | AI (source-diff): ReactNeuroglancer is a known 3D neuroscience viewer; network+rendering is expected. | ai | |
| source-diff | obfuscated-file:dist/lz4-D5NbssRf.js | AI (source-diff): Bundled LZ4 codec; minification expected. | ai | |
| source-diff | obfuscated-file:dist/lerc-RGuForS6.js | AI (source-diff): Bundled LERC codec (Esri); minification expected. | ai | |
| phantom-deps | phantom-dep:@vitessce/zarr | AI (phantom-deps): Same-org monorepo sibling; may be re-exported rather than directly imported. | ai | |
| phantom-deps | phantom-dep:internmap | AI (phantom-deps): Likely used transitively or via re-export in this monorepo package. | ai | |
| phantom-deps | phantom-dep:@vitessce/constants-internal | AI (phantom-deps): Same-org monorepo sibling; re-export pattern is expected. | ai | |
| phantom-deps | phantom-dep:@vitessce/abstract | AI (phantom-deps): Same-org monorepo sibling; re-export pattern is expected. | ai | |
| phantom-deps | phantom-dep:@vitessce/error | AI (phantom-deps): Same-org monorepo sibling; re-export pattern is expected. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package; sparse README and no keywords are expected for internal scoped packages. | ai | |
| phantom-deps | phantom-dep:react-window | AI (phantom-deps): Likely used transitively or via re-export in this monorepo package. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 4.0.0 | 16 / 5 | |
| 3.9.11 | 16 / 5 | |
| 3.9.10 | 16 / 5 | |
| 3.9.9 | 16 / 5 | |
| 3.9.8 | 16 / 5 | |
| 3.9.7 | 16 / 5 | |
| 3.9.6 | 16 / 5 | |
| 3.9.5 | 16 / 5 | |
| 3.9.4 | 16 / 5 | |
| 0.0.1 | 0 / 1 |
v4.0.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.6
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v3.9.5
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v3.9.4
9 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.