← Home

@vitessce/dev

This package is the main `vitessce` package on NPM. It exports the `<Vitessce/>` from `@vitessce/all` for backwards compatibility.

5
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/ReactNeuroglancer-DvvZ7TpP.js AI (source-diff): Neuroglancer React wrapper bundle; network calls are for neuroscience data fetching, expected. ai
source-diff obfuscated-file:dist/index-BopFrQ1h.js AI (source-diff): Minified 3D volume rendering code; legitimate bundler output. ai
source-diff obfuscated-file:dist/lerc-CixLzOtk.js AI (source-diff): LERC raster decoder library, minified; Esri Apache-licensed code, not malicious. ai
source-diff obfuscated-file:dist/higlass-BNRNwGCm.js AI (source-diff): Standard Vite-minified bundle for HiGlass visualization library; not malicious obfuscation. ai
source-diff net-exec-file:dist/higlass-BNRNwGCm.js AI (source-diff): Network calls and dynamic code in bundled HiGlass visualization code; expected for this package. ai
source-diff obfuscated-file:dist/index-B31N-uNr.js AI (source-diff): Standard Vite-minified main bundle; bundler boilerplate, not malicious. ai
source-diff net-exec-file:dist/index-B31N-uNr.js AI (source-diff): Network + dynamic code in main visualization bundle; expected for vitessce. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; sparse README and no keywords are expected for internal tooling packages. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped @vitessce/* monorepo package; Levenshtein match to 'ajv' is coincidental, not a typosquat. ai

Versions (showing 5 of 5)

Version Deps Published
3.9.9 4 / 4
3.9.8 4 / 4
3.9.7 4 / 4
3.8.9 4 / 4
3.8.6 4 / 4

v3.8.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.