@vitessce/gl
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:glslify | AI (dependencies): Known GLSL shader bundler; consistent with this WebGL package's purpose. | ai | |
| dependencies | unvetted-dep:nebula.gl | AI (dependencies): Known deck.gl editing library; stable dependency for this visualization package. | ai | |
| dependencies | unvetted-dep:@hms-dbmi/viv | AI (dependencies): Same org (HMS DBMI) as package author; core imaging dependency. | ai | |
| dependencies | unvetted-dep:@luma.gl/gltools | AI (dependencies): Known luma.gl WebGL toolkit; consistent with this package's GL purpose. | ai | |
| dependencies | unvetted-dep:@nebula.gl/layers | AI (dependencies): Known nebula.gl layers package; stable visualization dependency. | ai | |
| dependencies | unvetted-dep:@luma.gl/experimental | AI (dependencies): Known luma.gl experimental package; consistent with WebGL usage. | ai | |
| dependencies | unvetted-dep:@nebula.gl/edit-modes | AI (dependencies): Known nebula.gl edit-modes package; stable visualization dependency. | ai | |
| phantom-deps | phantom-dep:@deck.gl/react | AI (phantom-deps): deck.gl React binding; consistent with visualization package, may be re-exported. | ai | |
| phantom-deps | phantom-dep:@luma.gl/webgl | AI (phantom-deps): luma.gl WebGL binding; consistent with GL package purpose. | ai | |
| phantom-deps | phantom-dep:@turf/centroid | AI (phantom-deps): Turf.js geospatial utility; consistent with package purpose. | ai | |
| phantom-deps | phantom-dep:@luma.gl/engine | AI (phantom-deps): luma.gl engine; consistent with GL package purpose. | ai | |
| phantom-deps | phantom-dep:@vitessce/utils | AI (phantom-deps): Same-org sibling package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/core | AI (phantom-deps): loaders.gl core; consistent with GL package purpose. | ai | |
| typosquat | typosquat.levenshtein:glob | AI (typosquat): Scoped @vitessce/gl package; not a typosquat of glob. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/images | AI (phantom-deps): loaders.gl images; consistent with visualization package purpose. | ai | |
| phantom-deps | phantom-dep:@deck.gl/mesh-layers | AI (phantom-deps): deck.gl mesh layers; consistent with GL package purpose. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/3d-tiles | AI (phantom-deps): loaders.gl 3D tiles; consistent with GL package purpose. | ai | |
| phantom-deps | phantom-dep:@luma.gl/shadertools | AI (phantom-deps): luma.gl shader tools; consistent with GL package purpose. | ai | |
| phantom-deps | phantom-dep:@luma.gl/experimental | AI (phantom-deps): luma.gl experimental; consistent with GL package purpose. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/loader-utils | AI (phantom-deps): loaders.gl utilities; consistent with GL package purpose. | ai | |
| phantom-deps | phantom-dep:@luma.gl/gltools | AI (phantom-deps): luma.gl GL tools; consistent with GL package purpose. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Scoped @vitessce/gl package; not a typosquat of got. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @vitessce/gl package; not a typosquat of pg. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped @vitessce/gl package; not a typosquat of qs. | ai | |
| phantom-deps | phantom-dep:glslify | AI (phantom-deps): glslify is used as a build-time CLI tool via the glslify script, not a direct import. | ai | |
| phantom-deps | phantom-dep:mathjs | AI (phantom-deps): GL/math utility; may be used indirectly via re-exports or config. | ai | |
| phantom-deps | phantom-dep:math.gl | AI (phantom-deps): GL math library; consistent with package purpose, used via transitive imports. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 3.9.11 | 42 / 3 | |
| 3.9.10 | 42 / 3 | |
| 3.9.9 | 42 / 3 | |
| 3.9.8 | 42 / 3 | |
| 3.9.7 | 42 / 3 |
v3.9.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.9.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.