← Home

@vitessce/spatial-zarr

19
Versions
MIT
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

keller-mark

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-DJV3mJxe.js AI (source-diff): Vite/rollup bundle output, not true obfuscation; readable library code. ai
source-diff net-exec-file:dist/index-DJV3mJxe.js AI (source-diff): Bundled decoder library code, no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/lerc-f6jewSRf.js AI (source-diff): Bundled Esri LERC decoder, minified not obfuscated. ai
source-diff obfuscated-file:dist/lerc-DL1mSZGK.js AI (source-diff): Esri LERC decoder bundled via Vite, legitimate library code. ai
source-diff net-exec-file:dist/index-BU57EnXK.js AI (source-diff): Bundled app code (map/network viz lib), no dropper behavior present. ai
source-diff obfuscated-file:dist/index-BU57EnXK.js AI (source-diff): Vite bundle output with long minified lines, not true obfuscation. ai
source-diff net-exec-file:dist/index-s5uXlzCq.js AI (source-diff): Bundled library code (map/codec libs), no malicious network+exec behavior found. ai
source-diff obfuscated-file:dist/lerc-CaiPQuPF.js AI (source-diff): Minified Esri LERC codec library bundled by build, not obfuscation. ai
source-diff obfuscated-file:dist/index-s5uXlzCq.js AI (source-diff): Bundled vite/rollup output, not true obfuscation. ai
source-diff net-exec-file:dist/index-O5TnEDtg.js AI (source-diff): Bundled build artifact, no malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/index-O5TnEDtg.js AI (source-diff): Vite-bundled output, readable code, not true obfuscation. ai
source-diff obfuscated-file:dist/lerc-BE7AO24C.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscated malware. ai
source-diff obfuscated-file:dist/lerc-4QDR8Tjo.js AI (source-diff): Bundled LERC decoder (Esri library), minified not obfuscated. ai
source-diff net-exec-file:dist/index-L_3KnJHu.js AI (source-diff): Bundled app code with normal fetch/eval-like patterns from dependencies, no malicious destination found. ai
source-diff obfuscated-file:dist/index-L_3KnJHu.js AI (source-diff): Vite/rollup bundle output, not true obfuscation; matches package build tooling. ai
source-diff obfuscated-file:dist/lerc-BlBjyogg.js AI (source-diff): Esri LERC decoder bundled via Vite, legitimate library with copyright header. ai
source-diff net-exec-file:dist/index-hzXpsWKL.js AI (source-diff): Bundler-produced code, no concrete malicious network/exec behavior found in sample. ai
source-diff obfuscated-file:dist/index-hzXpsWKL.js AI (source-diff): Bundled Vite output, not true obfuscation; readable source with clear module structure. ai
source-diff obfuscated-file:dist/index-C-gXUhRi.js AI (source-diff): Vite/Rollup bundle output for geospatial libs, not true obfuscation. ai
source-diff obfuscated-file:dist/lerc-wMX1hw4T.js AI (source-diff): Bundled LERC/pako decoder library, standard minified build output. ai
source-diff net-exec-file:dist/index-C-gXUhRi.js AI (source-diff): Bundled minified code triggers pattern match; no concrete malicious network/exec behavior found. ai
source-diff obfuscated-file:dist/lerc-B0TRnLza.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscated code. ai
source-diff obfuscated-file:dist/index-Opql4jgY.js AI (source-diff): Vite/Rollup bundled output, not true obfuscation; sample shows readable JS with source structure. ai
source-diff net-exec-file:dist/index-Opql4jgY.js AI (source-diff): Bundled build artifact triggers net+exec pattern match, no malicious behavior in sample. ai
source-diff net-exec-file:dist/index-2t0pAbDy.js AI (source-diff): False positive on bundled decoder/network code, no dropper behavior. ai
source-diff obfuscated-file:dist/lerc-B4aKq5O2.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscation. ai
source-diff obfuscated-file:dist/index-2t0pAbDy.js AI (source-diff): Bundled Vite/Rollup output, not true obfuscation. ai
source-diff obfuscated-file:dist/index-C-UIQtDR.js AI (source-diff): Vite-bundled dist output, not obfuscation. ai
source-diff obfuscated-file:dist/lerc-BE-pX_4s.js AI (source-diff): Bundled third-party LERC/pako decoder library, not obfuscation. ai
source-diff net-exec-file:dist/index-C-UIQtDR.js AI (source-diff): Bundled app code (view types etc.), no malicious network/exec behavior shown. ai
source-diff net-exec-file:dist/index-C-i6H75_.js AI (source-diff): Bundled JS with normal fetch/eval patterns from deps, no malicious destination. ai
source-diff obfuscated-file:dist/lerc-Dcax99Ml.js AI (source-diff): Bundled Esri LERC decoder library, not obfuscated malware. ai
source-diff obfuscated-file:dist/index-C-i6H75_.js AI (source-diff): Vite bundle output for a large legit package, not true obfuscation. ai
source-diff net-exec-file:dist/index-xFqX0yiB.js AI (source-diff): False positive: bundled decoder/library code, no malicious network+exec behavior. ai
publish-pattern new-deps-added AI (publish-pattern): Same-org sibling package @vitessce/zarr-utils, versioned in lockstep. ai
source-diff obfuscated-file:dist/lerc-C2Ws2n1e.js AI (source-diff): Bundled LERC decoder library, minified not obfuscated. ai
source-diff obfuscated-file:dist/index-xFqX0yiB.js AI (source-diff): Bundled Vite output, not true obfuscation; matches package's stated code. ai
source-diff net-exec-file:dist/index-BhNyOJPs.js AI (source-diff): Network calls and dynamic property access in a spatial viz bundle are expected; no dropper pattern present. ai
source-diff obfuscated-file:dist/lerc-aoreA0lx.js AI (source-diff): LERC decoder (Esri Apache-licensed) bundled via Vite; long lines from minified third-party codec, not malicious obfuscation. ai
source-diff obfuscated-file:dist/index-BhNyOJPs.js AI (source-diff): Vite-bundled ESM output; readable code, not obfuscated. Stable pattern for this package. ai
phantom-deps phantom-dep:parquet-wasm AI (phantom-deps): Platform-specific binary dep; phantom-dep heuristic not applicable here. ai
phantom-deps phantom-dep:d3-array AI (phantom-deps): Monorepo package; d3-array used transitively or in config, stable false positive. ai

Versions (showing 19 of 19)

Version Deps Published
4.0.0 15 / 3
3.9.11 15 / 3
3.9.10 15 / 3
3.9.9 15 / 3
3.9.8 15 / 3
3.9.7 15 / 3
3.9.6 15 / 3
3.9.5 15 / 3
3.9.4 15 / 3
3.9.3 15 / 3
3.9.2 14 / 3
3.9.1 14 / 3
3.9.0 14 / 3
3.8.13 14 / 2
3.8.10 14 / 2
3.8.9 14 / 2
3.8.8 14 / 2
3.8.7 14 / 2
3.8.6 14 / 2

v4.0.0

4 findings
HIGH New obfuscated file: dist/index-BU57EnXK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-BU57EnXK.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-DL1mSZGK.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.6

5 findings
HIGH New obfuscated file: dist/index-C-gXUhRi.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-gXUhRi.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-wMX1hw4T.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-03-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-03-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.5

5 findings
HIGH New obfuscated file: dist/index-xFqX0yiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-xFqX0yiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-C2Ws2n1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.4

5 findings
HIGH New obfuscated file: dist/index-xFqX0yiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-xFqX0yiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-C2Ws2n1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.3

5 findings
HIGH New obfuscated file: dist/index-xFqX0yiB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-xFqX0yiB.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-C2Ws2n1e.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.2

5 findings
HIGH New obfuscated file: dist/index-L_3KnJHu.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-L_3KnJHu.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-4QDR8Tjo.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-02-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-02-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.1

5 findings
HIGH New obfuscated file: dist/index-s5uXlzCq.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-s5uXlzCq.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-CaiPQuPF.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-01-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-01-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.0

5 findings
HIGH New obfuscated file: dist/index-O5TnEDtg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-O5TnEDtg.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BE7AO24C.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2026-01-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2026-01-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.8.13

5 findings
HIGH New obfuscated file: dist/index-hzXpsWKL.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-hzXpsWKL.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BlBjyogg.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: keller-mark → GitHub Actions (on 2025-12-14, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (keller-mark) on 2025-12-14, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.8.10

4 findings
HIGH New obfuscated file: dist/index-2t0pAbDy.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-2t0pAbDy.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-B4aKq5O2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.9

4 findings
HIGH New obfuscated file: dist/index-C-i6H75_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-i6H75_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-Dcax99Ml.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.8

4 findings
HIGH New obfuscated file: dist/index-C-i6H75_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-i6H75_.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-Dcax99Ml.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.7

4 findings
HIGH New obfuscated file: dist/index-C-UIQtDR.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/index-C-UIQtDR.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: dist/lerc-BE-pX_4s.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.8.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.