@wix/image
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/statics/janet/main.21c6bcc5.iframe.bundle.js | AI (source-diff): Bundled build artifact, not a dropper/loader. | ai | |
| source-diff | net-exec-file:dist/statics/janet/734.d6bdffa02e1ee79abbb8.manager.bundle.js | AI (source-diff): Webpack bundle chunk loader, no evidence of dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/734.d6bdffa02e1ee79abbb8.manager.bundle.js | AI (source-diff): Webpack-bundled build output for internal janet tooling, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/main.21c6bcc5.iframe.bundle.js | AI (source-diff): Webpack bundle for storybook iframe, standard minified output. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/main.a0336d4e.iframe.bundle.js | AI (source-diff): Webpack-bundled build output from janet-build, not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/statics/janet/main.a0336d4e.iframe.bundle.js | AI (source-diff): Bundled iframe app code, no concrete malicious network/exec behavior shown. | ai | |
| source-diff | net-exec-file:dist/statics/janet/main.2adfbb25.iframe.bundle.js | AI (source-diff): False positive on bundled storybook iframe code; no malicious network+exec behavior evident. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/main.2adfbb25.iframe.bundle.js | AI (source-diff): Webpack bundle output (janet-build), not true obfuscation; long lines are minification. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/main.762d3c70.iframe.bundle.js | AI (source-diff): Webpack bundle output from janet-build storybook tooling, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/734.bbbeb0e1577a30b30072.manager.bundle.js | AI (source-diff): Webpack bundle output from janet-build storybook tooling, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/statics/janet/734.bbbeb0e1577a30b30072.manager.bundle.js | AI (source-diff): Bundled storybook manager code; heuristic false positive, no malicious behavior in sample. | ai | |
| source-diff | net-exec-file:dist/statics/janet/main.762d3c70.iframe.bundle.js | AI (source-diff): Bundled storybook iframe code; heuristic false positive, no malicious behavior in sample. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/main.52ccb40c.iframe.bundle.js | AI (source-diff): Standard webpack/janet-build bundle output; Wix CI publisher with strong track record. | ai | |
| source-diff | net-exec-file:dist/statics/janet/main.52ccb40c.iframe.bundle.js | AI (source-diff): Network+exec pattern in a webpack bundle is expected for a Wix iframe component; not dropper behavior. | ai | |
| phantom-deps | phantom-dep:tslib | AI (phantom-deps): tslib is a declared runtime dependency used implicitly by TypeScript compilation output. | ai | |
| source-diff | net-exec-file:dist/statics/janet/main.8862e441.iframe.bundle.js | AI (source-diff): Network+exec pattern is expected in a webpack iframe bundle for a UI component; no malicious payload. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/main.8862e441.iframe.bundle.js | AI (source-diff): Standard webpack bundle produced by janet-build; long lines are minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/statics/janet/main.cf1e1edc.iframe.bundle.js | AI (source-diff): Standard webpack/janet-build output with source map; minified but not obfuscated, consistent with Wix build toolchain. | ai | |
| source-diff | net-exec-file:dist/statics/janet/main.cf1e1edc.iframe.bundle.js | AI (source-diff): Network+exec pattern is expected in a UI component bundle (iframe storybook/preview); no dropper indicators in the readable sample. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 1.452.0 | 4 / 19 | |
| 1.451.0 | 4 / 19 | |
| 1.450.0 | 4 / 19 | |
| 1.449.0 | 4 / 19 | |
| 1.448.0 | 4 / 19 | |
| 1.447.0 | 4 / 19 | |
| 1.446.0 | 4 / 19 | |
| 1.445.0 | 4 / 19 | |
| 1.436.0 | 4 / 19 | |
| 1.435.0 | 4 / 19 | |
| 1.434.0 | 4 / 19 | |
| 1.433.0 | 4 / 19 | |
| 1.427.0 | 4 / 19 | |
| 1.426.0 | 4 / 19 | |
| 1.425.0 | 4 / 19 | |
| 1.424.0 | 4 / 19 |
v1.452.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.447.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.446.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.445.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware. Artifact: bundled (webpack) — bundler banner in the scanned head, but the file is larger than the scan window and its remainder is unclassified, so this is not a clean bill of health.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.436.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.435.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.434.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.433.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.427.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.426.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.425.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.424.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.