← Home

dcmjs

16
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

swederikandrebotchafeydannyrbsedghiwayfarer3130stevepieperhackermdcornerstonejs-botjamesapettssandrasieevren217brunoalvesdefaria

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:build/dcmjs.es.js AI (source-diff): Long strings are DICOM dictionary name blobs and bundled JS — legitimate build artifacts for this DICOM library. ai
source-diff encoded-string-file:build/dcmjs.js AI (source-diff): Same DICOM dictionary blob pattern; stable false positive for this package. ai
source-diff encoded-string-file:build/dcmjs.min.js AI (source-diff): Minified bundle; long strings are expected in minified DICOM library output. ai
phantom-deps phantom-dep:loglevel AI (phantom-deps): Legitimate runtime dependency declared in package.json; heuristic false positive. ai
phantom-deps phantom-dep:gl-matrix AI (phantom-deps): Legitimate runtime dependency declared in package.json; heuristic false positive. ai
typosquat typosquat.levenshtein:dayjs AI (typosquat): dcmjs is a long-established DICOM library unrelated to dayjs; name similarity is coincidental. ai
phantom-deps phantom-dep:@babel/runtime-corejs3 AI (phantom-deps): Babel runtime dep loaded by convention via Babel plugin; heuristic false positive. ai
phantom-deps phantom-dep:lodash.clonedeep AI (phantom-deps): Legitimate runtime dependency declared in package.json; heuristic false positive. ai
phantom-deps phantom-dep:adm-zip AI (phantom-deps): Legitimate runtime dependency declared in package.json; heuristic false positive. ai
phantom-deps phantom-dep:ndarray AI (phantom-deps): Legitimate runtime dependency declared in package.json; heuristic false positive. ai

Versions (showing 16 of 16)

Version Deps Published
0.52.0 7 / 24
0.51.1 7 / 22
0.51.0 7 / 22
0.50.3 7 / 22
0.50.2 7 / 22
0.50.1 7 / 22
0.50.0 7 / 22
0.49.4 7 / 22
0.49.3 7 / 22
0.49.2 7 / 22
0.49.1 7 / 22
0.49.0 7 / 22
0.48.0 7 / 22
0.47.1 7 / 22
0.47.0 7 / 22
0.0.2 0 / 1

v0.50.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.