← Home

barcode-detector

A Barcode Detection API polyfill that uses ZXing webassembly under the hood

16
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

sec-ant

Keywords

es6qrcodebarcodebarcode-detectorwasmpolyfillzxingesmodulewebassembly

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cjs/zxing-exported.js AI (source-diff): Bundled ZXing barcode-format data table; not obfuscation. Stable for this package. ai
source-diff obfuscated-file:dist/cjs/zxing-exported-xCdiQDv3.cjs AI (source-diff): Bundled ZXing barcode format data tables; expected minified output for this wasm-wrapping package. ai
source-diff obfuscated-file:dist/cjs/ponyfill.js AI (source-diff): Standard minified CJS build output; stable across versions. ai
source-diff obfuscated-file:dist/iife/ponyfill.js AI (source-diff): Standard minified IIFE build output; stable across versions. ai
provenance missing-githead AI (provenance): GitHub Actions publish flow doesn't set gitHead; SLSA provenance compensates. ai
provenance publisher-changed AI (provenance): Moved to GitHub Actions CI/CD publishing with SLSA provenance; legitimate transition. ai
source-diff obfuscated-file:dist/iife/polyfill.js AI (source-diff): Standard minified IIFE build output for barcode-detector; stable across versions. ai
dependencies unvetted-dep:zxing-wasm AI (dependencies): zxing-wasm is the expected runtime dependency for a ZXing WebAssembly barcode detection polyfill; its use is consistent with the package's documented purpose. ai

Versions (showing 16 of 16)

Version Deps Published
3.2.1 1 / 19
3.2.0 1 / 19
3.1.3 1 / 21
3.1.2 1 / 21
3.1.1 1 / 21
3.1.0 1 / 21
3.0.8 1 / 21
3.0.7 1 / 21
3.0.6 1 / 20
3.0.5 1 / 20
3.0.4 1 / 20
3.0.3 1 / 20
3.0.2 1 / 20
3.0.1 1 / 20
3.0.0 1 / 20
2.2.2 2 / 17

v3.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.