← Home

@yudiel/react-qr-scanner

19
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

yudielcurbelo

Keywords

reactqrcodeqrcode-scanqrcode-readerqrcode-scannerqr-code-scanqr-code-readerqr-code-scannerbarcodebarcode-scannerbarcode-detectioncamerawebrtc

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/assets/base64Beep.d.ts AI (source-diff): Long line is a base64 MP3 beep asset embedded in declarations, not obfuscated code. ai

Versions (showing 19 of 19)

Version Deps Published
2.6.0 2 / 27
2.5.1 2 / 20
2.5.0 2 / 20
2.4.1 2 / 20
2.4.0 2 / 20
2.3.1 2 / 16
2.3.0 2 / 16
2.2.1 2 / 17
2.2.0 2 / 17
2.1.0 2 / 17
2.0.8 2 / 17
2.0.7 2 / 17
2.0.6 2 / 17
2.0.5 2 / 17
2.0.4 2 / 17
2.0.3 2 / 17
2.0.2 2 / 17
2.0.1 2 / 17
2.0.0 2 / 17

v2.2.1

2 findings
HIGH New obfuscated file: dist/assets/base64Beep.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.