← Home

@vitessce/gl

11
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:glslify AI (dependencies): Known GLSL shader bundler; consistent with this WebGL package's purpose. ai
dependencies unvetted-dep:nebula.gl AI (dependencies): Known deck.gl editing library; stable dependency for this visualization package. ai
dependencies unvetted-dep:@hms-dbmi/viv AI (dependencies): Same org (HMS DBMI) as package author; core imaging dependency. ai
dependencies unvetted-dep:@luma.gl/gltools AI (dependencies): Known luma.gl WebGL toolkit; consistent with this package's GL purpose. ai
dependencies unvetted-dep:@nebula.gl/layers AI (dependencies): Known nebula.gl layers package; stable visualization dependency. ai
dependencies unvetted-dep:@luma.gl/experimental AI (dependencies): Known luma.gl experimental package; consistent with WebGL usage. ai
dependencies unvetted-dep:@nebula.gl/edit-modes AI (dependencies): Known nebula.gl edit-modes package; stable visualization dependency. ai
phantom-deps phantom-dep:@deck.gl/react AI (phantom-deps): deck.gl React binding; consistent with visualization package, may be re-exported. ai
phantom-deps phantom-dep:@luma.gl/webgl AI (phantom-deps): luma.gl WebGL binding; consistent with GL package purpose. ai
phantom-deps phantom-dep:@turf/centroid AI (phantom-deps): Turf.js geospatial utility; consistent with package purpose. ai
phantom-deps phantom-dep:@luma.gl/engine AI (phantom-deps): luma.gl engine; consistent with GL package purpose. ai
phantom-deps phantom-dep:@vitessce/utils AI (phantom-deps): Same-org sibling package; stable false positive. ai
phantom-deps phantom-dep:@loaders.gl/core AI (phantom-deps): loaders.gl core; consistent with GL package purpose. ai
typosquat typosquat.levenshtein:glob AI (typosquat): Scoped @vitessce/gl package; not a typosquat of glob. ai
phantom-deps phantom-dep:@loaders.gl/images AI (phantom-deps): loaders.gl images; consistent with visualization package purpose. ai
phantom-deps phantom-dep:@deck.gl/mesh-layers AI (phantom-deps): deck.gl mesh layers; consistent with GL package purpose. ai
phantom-deps phantom-dep:@loaders.gl/3d-tiles AI (phantom-deps): loaders.gl 3D tiles; consistent with GL package purpose. ai
phantom-deps phantom-dep:@luma.gl/shadertools AI (phantom-deps): luma.gl shader tools; consistent with GL package purpose. ai
phantom-deps phantom-dep:@luma.gl/experimental AI (phantom-deps): luma.gl experimental; consistent with GL package purpose. ai
phantom-deps phantom-dep:@loaders.gl/loader-utils AI (phantom-deps): loaders.gl utilities; consistent with GL package purpose. ai
phantom-deps phantom-dep:@luma.gl/gltools AI (phantom-deps): luma.gl GL tools; consistent with GL package purpose. ai
typosquat typosquat.levenshtein:got AI (typosquat): Scoped @vitessce/gl package; not a typosquat of got. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @vitessce/gl package; not a typosquat of pg. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @vitessce/gl package; not a typosquat of qs. ai
phantom-deps phantom-dep:glslify AI (phantom-deps): glslify is used as a build-time CLI tool via the glslify script, not a direct import. ai
phantom-deps phantom-dep:mathjs AI (phantom-deps): GL/math utility; may be used indirectly via re-exports or config. ai
phantom-deps phantom-dep:math.gl AI (phantom-deps): GL math library; consistent with package purpose, used via transitive imports. ai

Versions (showing 11 of 11)

Version Deps Published
3.9.11 42 / 3
3.9.10 42 / 3
3.9.9 42 / 3
3.9.8 42 / 3
3.9.7 42 / 3
3.8.13 42 / 3
3.8.10 42 / 3
3.8.9 42 / 3
3.8.8 42 / 3
3.8.7 42 / 3
3.8.6 42 / 3

v3.8.13

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2025-12-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2025-12-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.8.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.