cesium
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:Build/Cesium/Workers/createPlaneOutlineGeometry.js | AI (source-diff): Minified build output of Cesium's own geometry worker, not obfuscation. | ai | |
| source-diff | obfuscated-file:Build/Cesium/Workers/createPlaneGeometry.js | AI (source-diff): Minified build output of Cesium's own geometry worker, not obfuscation. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known Cesium team maintainers added; publisher pjcozzi matches prior approved maintainer list. | ai | |
| source-diff | net-exec-file:Source/ThirdParty/knockout-3.4.2.js | AI (source-diff): Well-known third-party knockout.js library, not injected malware. | ai | |
| source-diff | obfuscated-file:Build/Cesium/Workers/createFrustumOutlineGeometry.js | AI (source-diff): Standard minified Cesium worker build output, not injected code. | ai | |
| source-diff | obfuscated-file:Build/Cesium/Workers/createFrustumGeometry.js | AI (source-diff): Standard minified Cesium worker build output, not injected code. | ai | |
| source-diff | obfuscated-file:Source/Core/GoogleEarthEnterpriseMetadata.js | AI (source-diff): New unminified feature source, long-line trigger false positive. | ai | |
| source-diff | obfuscated-file:Build/Cesium/Workers/createVerticesFromGoogleEarthEnterpriseBuffer.js | AI (source-diff): Minified worker bundle, legit GEE feature addition. | ai | |
| source-diff | obfuscated-file:Build/Cesium/Workers/decodeGoogleEarthEnterprisePacket.js | AI (source-diff): Minified worker bundle, legit GEE feature addition. | ai | |
| source-diff | obfuscated-file:Source/Scene/GoogleEarthEnterpriseMapsProvider.js | AI (source-diff): New unminified feature source, long-line trigger false positive. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Publisher is known prior maintainer per provenance INFO note; not a takeover. | ai | |
| source-diff | net-exec-file:Build/Cesium/Workers/transcodeCRNToDXT.js | AI (source-diff): Same crunch worker file; no malicious network/exec behavior, just minified WASM-era JS. | ai | |
| source-diff | net-exec-file:Source/ThirdParty/crunch.js | AI (source-diff): Same crunch library source file, benign. | ai | |
| source-diff | obfuscated-file:Source/ThirdParty/crunch.js | AI (source-diff): Third-party crunch/crnlib source, documented and licensed, not malicious obfuscation. | ai | |
| source-diff | net-exec-file:Build/CesiumUnminified/Workers/transcodeCRNToDXT.js | AI (source-diff): Same crunch library file, benign. | ai | |
| source-diff | obfuscated-file:Build/CesiumUnminified/Workers/transcodeCRNToDXT.js | AI (source-diff): Same crunch library, unminified build variant. | ai | |
| source-diff | obfuscated-file:Build/Cesium/Workers/transcodeCRNToDXT.js | AI (source-diff): Emscripten-compiled crunch texture lib, long lines are build output not obfuscation. | ai | |
| source-diff | obfuscated-file:Source/ThirdParty/earcut-2.1.1.js | AI (source-diff): earcut is a legitimate minified third-party triangulation library, not malicious obfuscation. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): Worker bootstrap shim pattern in bundled build output, not attacker-controlled input. | ai | |
| source-diff | encoded-string-file:Build/Cesium/Cesium.js | AI (source-diff): atob() of inline workers bundle; documented CesiumJS build artifact. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Chunk-hashed worker files rotate names each release; stable for CesiumJS. | ai | |
| source-diff | encoded-string-file:Build/CesiumUnminified/Cesium.js | AI (source-diff): atob() of inline workers bundle; documented CesiumJS build artifact. | ai | |
| source-diff | encoded-string-file:Build/CesiumUnminified/index.cjs | AI (source-diff): Base64-encoded inline workers; standard CesiumJS build pattern. | ai | |
| source-diff | encoded-string-file:Build/Cesium/index.cjs | AI (source-diff): GLSL shader strings and minified build output; stable pattern for CesiumJS. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside bundled KTX2 transcoder worker; standard pattern in Cesium's build output, not user-controlled input. | ai | |
| semgrep | semgrep:dynamic-require | AI (semgrep): Prod/dev conditional require in index.cjs is a well-known pattern; paths are static strings, not user input. | ai |
Versions (showing 33 of 33)
| Version | Deps | Published |
|---|---|---|
| 1.143.0 | 3 / 53 | |
| 1.142.0 | 2 / 53 | |
| 1.141.0 | 2 / 53 | |
| 1.140.0 | 2 / 51 | |
| 1.42.0 | 1 / 37 | |
| 1.41.0 | 1 / 36 | |
| 1.40.0 | 1 / 36 | |
| 1.39.0 | 1 / 36 | |
| 1.38.0 | 1 / 36 | |
| 1.37.0 | 1 / 36 | |
| 1.36.0 | 1 / 36 | |
| 1.35.2 | 1 / 36 | |
| 1.35.1 | 1 / 36 | |
| 1.34.0 | 1 / 36 | |
| 1.32.1 | 1 / 37 | |
| 1.31.0 | 1 / 37 | |
| 1.30.0 | 1 / 36 | |
| 1.29.0 | 1 / 36 | |
| 1.28.0 | 1 / 35 | |
| 1.27.0 | 1 / 35 | |
| 1.26.0 | 1 / 35 | |
| 1.25.0 | 1 / 35 | |
| 1.24.0 | 1 / 35 | |
| 1.23.0 | 1 / 35 | |
| 1.22.2 | 1 / 35 | |
| 1.22.1 | 1 / 35 | |
| 1.22.0 | 1 / 35 | |
| 1.21.0 | 1 / 35 | |
| 1.20.0 | 1 / 35 | |
| 1.19.0 | 1 / 21 | |
| 1.18.0 | 1 / 21 | |
| 1.17.0 | 1 / 21 | |
| 1.16.0 | 1 / 21 |
v1.143.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (ggetz) than the most recent previously approved version (lukemckinstry) on 2026-07-01, but ggetz is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.42.0
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (analyticalgraphics) than the most recent previously approved version (mramato) on 2018-02-01, but analyticalgraphics is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.41.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pjcozzi) than the most recent previously approved version (mramato) on 2018-01-02, but pjcozzi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.40.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tfili) than the most recent previously approved version (mramato) on 2017-12-01, but tfili is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.39.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.38.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.37.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lilleyse) than the most recent previously approved version (bagnell) on 2017-09-01, but lilleyse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.36.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hpinkos) than the most recent previously approved version (bagnell) on 2017-08-01, but hpinkos is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.35.2
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mramato) than the most recent previously approved version (bagnell) on 2017-07-11, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.35.1
12 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mramato) than the most recent previously approved version (hpinkos) on 2017-07-05, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.34.0
11 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tfili) than the most recent previously approved version (hpinkos) on 2017-06-01, but tfili is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.32.1
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bagnell) than the most recent previously approved version (hpinkos) on 2017-04-03, but bagnell is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.31.0
8 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lilleyse) than the most recent previously approved version (pjcozzi) on 2017-03-01, but lilleyse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.30.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hpinkos) than the most recent previously approved version (pjcozzi) on 2017-02-01, but hpinkos is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.29.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pjcozzi) than the most recent previously approved version (mramato) on 2017-01-02, but pjcozzi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.28.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (tfili) than the most recent previously approved version (mramato) on 2016-12-01, but tfili is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.27.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mramato) than the most recent previously approved version (lilleyse) on 2016-11-01, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.26.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bagnell) than the most recent previously approved version (lilleyse) on 2016-10-03, but bagnell is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.25.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (lilleyse) than the most recent previously approved version (mramato) on 2016-09-01, but lilleyse is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.24.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (hpinkos) than the most recent previously approved version (mramato) on 2016-08-01, but hpinkos is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.23.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (pjcozzi) than the most recent previously approved version (tfili) on 2016-07-01, but pjcozzi is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.22.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (mramato) than the most recent previously approved version (tfili) on 2016-06-14, but mramato is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.22.1
2 findingsThis version was published by a different npm account (tfili) than the most recent previously approved version (analyticalgraphicsinc) on 2016-06-13. It has since remained available on npm for 3693 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.22.0
2 findingsThis version was published by a different npm account (tfili) than the most recent previously approved version (analyticalgraphicsinc) on 2016-06-01. It has since remained available on npm for 3705 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.21.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.20.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.