← Home

@vitessce/dev

This package is the main `vitessce` package on NPM. It exports the `<Vitessce/>` from `@vitessce/all` for backwards compatibility.

3
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/ReactNeuroglancer-DvvZ7TpP.js AI (source-diff): Neuroglancer React wrapper bundle; network calls are for neuroscience data fetching, expected. ai
source-diff obfuscated-file:dist/index-BopFrQ1h.js AI (source-diff): Minified 3D volume rendering code; legitimate bundler output. ai
source-diff obfuscated-file:dist/lerc-CixLzOtk.js AI (source-diff): LERC raster decoder library, minified; Esri Apache-licensed code, not malicious. ai
source-diff obfuscated-file:dist/higlass-BNRNwGCm.js AI (source-diff): Standard Vite-minified bundle for HiGlass visualization library; not malicious obfuscation. ai
source-diff net-exec-file:dist/higlass-BNRNwGCm.js AI (source-diff): Network calls and dynamic code in bundled HiGlass visualization code; expected for this package. ai
source-diff obfuscated-file:dist/index-B31N-uNr.js AI (source-diff): Standard Vite-minified main bundle; bundler boilerplate, not malicious. ai
source-diff net-exec-file:dist/index-B31N-uNr.js AI (source-diff): Network + dynamic code in main visualization bundle; expected for vitessce. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; sparse README and no keywords are expected for internal tooling packages. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped @vitessce/* monorepo package; Levenshtein match to 'ajv' is coincidental, not a typosquat. ai

Versions (showing 3 of 3)

Version Deps Published
3.9.9 4 / 4
3.9.8 4 / 4
3.9.7 4 / 4

v3.9.9

8 findings
HIGH New obfuscated file: dist/higlass-BNRNwGCm.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/higlass-BNRNwGCm.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-B31N-uNr.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-B31N-uNr.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/index-BopFrQ1h.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/lerc-CixLzOtk.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/ReactNeuroglancer-DvvZ7TpP.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.