← Home

@vitessce/spatial-zarr

19
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-DJV3mJxe.js AI (source-diff): Vite/rollup bundle output, not true obfuscation; readable library code. ai
source-diff net-exec-file:dist/index-DJV3mJxe.js AI (source-diff): Bundled decoder library code, no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/lerc-f6jewSRf.js AI (source-diff): Bundled Esri LERC decoder, minified not obfuscated. ai
source-diff obfuscated-file:dist/lerc-DL1mSZGK.js AI (source-diff): Esri LERC decoder bundled via Vite, legitimate library code. ai
source-diff net-exec-file:dist/index-BU57EnXK.js AI (source-diff): Bundled app code (map/network viz lib), no dropper behavior present. ai
source-diff obfuscated-file:dist/index-BU57EnXK.js AI (source-diff): Vite bundle output with long minified lines, not true obfuscation. ai
source-diff net-exec-file:dist/index-s5uXlzCq.js AI (source-diff): Bundled library code (map/codec libs), no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/lerc-CaiPQuPF.js AI (source-diff): Minified Esri LERC codec library bundled by build, not obfuscation. ai
source-diff obfuscated-file:dist/index-s5uXlzCq.js AI (source-diff): Bundled vite/rollup output, not true obfuscation. ai
source-diff net-exec-file:dist/index-O5TnEDtg.js AI (source-diff): Bundled build artifact, no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/index-O5TnEDtg.js AI (source-diff): Vite-bundled output, readable code, not true obfuscation. ai
source-diff obfuscated-file:dist/lerc-BE7AO24C.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscated malware. ai
source-diff obfuscated-file:dist/lerc-4QDR8Tjo.js AI (source-diff): Bundled LERC decoder (Esri library), minified not obfuscated. ai
source-diff net-exec-file:dist/index-L_3KnJHu.js AI (source-diff): Bundled app code with normal fetch/eval-like patterns from dependencies, no malicious destination found. ai
source-diff obfuscated-file:dist/index-L_3KnJHu.js AI (source-diff): Vite/rollup bundle output, not true obfuscation; matches package build tooling. ai
source-diff obfuscated-file:dist/lerc-BlBjyogg.js AI (source-diff): Esri LERC decoder bundled via Vite, legitimate library with copyright header. ai
source-diff net-exec-file:dist/index-hzXpsWKL.js AI (source-diff): Bundler-produced code, no concrete malicious network/exec behavior found in sample. ai
source-diff obfuscated-file:dist/index-hzXpsWKL.js AI (source-diff): Bundled Vite output, not true obfuscation; readable source with clear module structure. ai
source-diff obfuscated-file:dist/index-C-gXUhRi.js AI (source-diff): Vite/Rollup bundle output for geospatial libs, not true obfuscation. ai
source-diff obfuscated-file:dist/lerc-wMX1hw4T.js AI (source-diff): Bundled LERC/pako decoder library, standard minified build output. ai
source-diff net-exec-file:dist/index-C-gXUhRi.js AI (source-diff): Bundled minified code triggers pattern match; no concrete malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/lerc-B0TRnLza.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscated code. ai
source-diff obfuscated-file:dist/index-Opql4jgY.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation; sample shows readable JS with source structure. ai
source-diff net-exec-file:dist/index-Opql4jgY.js AI (source-diff): Bundled build artifact triggers net+exec pattern match, no malicious behavior in sample. ai
source-diff net-exec-file:dist/index-2t0pAbDy.js AI (source-diff): False positive on bundled decoder/network code, no dropper behavior. ai
source-diff obfuscated-file:dist/lerc-B4aKq5O2.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscation. ai
source-diff obfuscated-file:dist/index-2t0pAbDy.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-C-UIQtDR.js AI (source-diff): Vite-bundled dist output, not obfuscation. ai
source-diff obfuscated-file:dist/lerc-BE-pX_4s.js AI (source-diff): Bundled third-party LERC/pako decoder library, not obfuscation. ai
source-diff net-exec-file:dist/index-C-UIQtDR.js AI (source-diff): Bundled app code (view types etc.), no malicious network/exec behavior shown. ai
source-diff net-exec-file:dist/index-C-i6H75_.js AI (source-diff): Bundled JS with normal fetch/eval patterns from deps, no malicious destination. ai
source-diff obfuscated-file:dist/lerc-Dcax99Ml.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscated malware. ai
source-diff obfuscated-file:dist/index-C-i6H75_.js AI (source-diff): Vite bundle output for a large legit package, not true obfuscation. ai
source-diff net-exec-file:dist/index-xFqX0yiB.js AI (source-diff): False positive: bundled decoder/library code, no malicious network+exec behavior. ai
publish-pattern new-deps-added AI (publish-pattern): Same-org sibling package @vitessce/zarr-utils, versioned in lockstep. ai
source-diff obfuscated-file:dist/lerc-C2Ws2n1e.js AI (source-diff): Bundled LERC decoder library, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-xFqX0yiB.js AI (source-diff): Bundled Vite output, not true obfuscation; matches package's stated code. ai
source-diff net-exec-file:dist/index-BhNyOJPs.js AI (source-diff): Network calls and dynamic property access in a spatial viz bundle are expected; no dropper pattern present. ai
source-diff obfuscated-file:dist/lerc-aoreA0lx.js AI (source-diff): LERC decoder (Esri Apache-licensed) bundled via Vite; long lines from minified third-party codec, not malicious obfuscation. ai
source-diff obfuscated-file:dist/index-BhNyOJPs.js AI (source-diff): Vite-bundled ESM output; readable code, not obfuscated. Stable pattern for this package. ai
phantom-deps phantom-dep:parquet-wasm AI (phantom-deps): Platform-specific binary dep; phantom-dep heuristic not applicable here. ai
phantom-deps phantom-dep:d3-array AI (phantom-deps): Monorepo package; d3-array used transitively or in config, stable false positive. ai

Versions (showing 19 of 19)

Version Deps Published
4.0.0 15 / 3
3.9.11 15 / 3
3.9.10 15 / 3
3.9.9 15 / 3
3.9.8 15 / 3
3.9.7 15 / 3
3.9.6 15 / 3
3.9.5 15 / 3
3.9.4 15 / 3
3.9.3 15 / 3
3.9.2 14 / 3
3.9.1 14 / 3
3.9.0 14 / 3
3.8.13 14 / 2
3.8.10 14 / 2
3.8.9 14 / 2
3.8.8 14 / 2
3.8.7 14 / 2
3.8.6 14 / 2

v4.0.0

4 findings
HIGH New obfuscated file: dist/index-BU57EnXK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BU57EnXK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DL1mSZGK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.6

5 findings
HIGH New obfuscated file: dist/index-C-gXUhRi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-gXUhRi.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-wMX1hw4T.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-03-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.5

5 findings
HIGH New obfuscated file: dist/index-xFqX0yiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-xFqX0yiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-C2Ws2n1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.4

5 findings
HIGH New obfuscated file: dist/index-xFqX0yiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-xFqX0yiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-C2Ws2n1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.3

5 findings
HIGH New obfuscated file: dist/index-xFqX0yiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-xFqX0yiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-C2Ws2n1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.2

5 findings
HIGH New obfuscated file: dist/index-L_3KnJHu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-L_3KnJHu.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-4QDR8Tjo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.1

5 findings
HIGH New obfuscated file: dist/index-s5uXlzCq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-s5uXlzCq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-CaiPQuPF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-01-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-01-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.0

5 findings
HIGH New obfuscated file: dist/index-O5TnEDtg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-O5TnEDtg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BE7AO24C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-01-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-01-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.8.13

5 findings
HIGH New obfuscated file: dist/index-hzXpsWKL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-hzXpsWKL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BlBjyogg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2025-12-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2025-12-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.8.10

4 findings
HIGH New obfuscated file: dist/index-2t0pAbDy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-2t0pAbDy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-B4aKq5O2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.9

4 findings
HIGH New obfuscated file: dist/index-C-i6H75_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-i6H75_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-Dcax99Ml.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.8

4 findings
HIGH New obfuscated file: dist/index-C-i6H75_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-i6H75_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-Dcax99Ml.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.7

4 findings
HIGH New obfuscated file: dist/index-C-UIQtDR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-UIQtDR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BE-pX_4s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.