← Home

highcharts

JavaScript charting framework

44
Versions
https://www.highcharts.com/license
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

torsteinhonsikarol.kolodziejjtisteljszuminskibre1470cvassengoysteinmosengkhliengppotaczekaskeljgoransleskrulling

Keywords

chartsdatavizgraphsvisualizationdatabrowserifywebpack

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:modules/renko.js AI (source-diff): Highcharts ships minified/bundled module files via webpack as standard practice; long lines are minification artifacts, not obfuscation. ai
source-diff obfuscated-file:modules/bullet.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/coloraxis.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/cylinder.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:themes/dark-blue.js AI (source-diff): Standard minified Highcharts theme file; normal distribution format. ai
source-diff obfuscated-file:indicators/dmi.js AI (source-diff): Standard minified Highcharts indicator module; normal distribution format. ai
source-diff obfuscated-file:modules/drag-panes.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/draggable-points.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/drilldown.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/export-data.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/exporting.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/flowmap.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/full-screen.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/datagrouping.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/data.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:themes/dark-unica.js AI (source-diff): Standard minified Highcharts theme file; normal distribution format. ai
source-diff obfuscated-file:modules/dumbbell.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:themes/dark-green.js AI (source-diff): Standard minified Highcharts theme file; normal distribution format. ai
source-diff obfuscated-file:modules/broken-axis.js AI (source-diff): Standard minified Highcharts module with copyright header and UMD wrapper; this is the normal distribution format for highcharts. ai
source-diff obfuscated-file:modules/debugger.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:modules/dependency-wheel.js AI (source-diff): Standard minified Highcharts module; normal distribution format. ai
source-diff obfuscated-file:standalone-navigator.js AI (source-diff): Standard webpack-minified Highcharts distribution bundle with proper copyright headers; expected for this charting library. ai
source-diff obfuscated-file:modules/boost.js AI (source-diff): Standard webpack-minified distribution file for Highcharts charting library module. ai
source-diff obfuscated-file:indicators/aroon-oscillator.js AI (source-diff): Standard webpack-minified distribution file for Highcharts charting library indicator module. ai
source-diff obfuscated-file:indicators/aroon.js AI (source-diff): Standard webpack-minified distribution file for Highcharts charting library indicator module. ai
source-diff obfuscated-file:indicators/bollinger-bands.js AI (source-diff): Standard webpack-minified distribution file for Highcharts charting library indicator module. ai
source-diff obfuscated-file:modules/boost-canvas.js AI (source-diff): Standard webpack-minified distribution file for Highcharts charting library module. ai
source-diff obfuscated-file:es5/modules/annotations.js AI (source-diff): Standard minified ES5 distribution file for Highcharts; proper headers and UMD wrapper present. Expected build artifact. ai
source-diff obfuscated-file:es5/modules/accessibility.js AI (source-diff): Standard minified ES5 distribution file for Highcharts; proper headers and UMD wrapper present. Expected build artifact. ai
source-diff obfuscated-file:es5/indicators/acceleration-bands.js AI (source-diff): Standard minified ES5 distribution file for Highcharts charting library; has proper copyright headers and UMD wrapper. Minified builds are expected. ai
source-diff obfuscated-file:es5/modules/annotations-advanced.js AI (source-diff): Standard minified ES5 distribution file for Highcharts; proper headers and UMD wrapper present. Expected build artifact. ai
source-diff obfuscated-file:modules/contour.js AI (source-diff): Standard Highcharts UMD minified module build with matching .src.js source file included. Normal build pattern for Highcharts modules. ai
source-diff obfuscated-file:esm/modules/contour.js AI (source-diff): Standard Highcharts minified module build with matching .src.js source file included. This is the normal build pattern for all Highcharts modules. ai
source-diff obfuscated-file:modules/navigator.js AI (source-diff): Standard Highcharts minified module output with proper copyright headers and UMD wrapper; this is the dist package's normal build artifact. ai
source-diff obfuscated-file:esm/modules/coloraxis.js AI (source-diff): Minified production build of Highcharts color axis module; standard for this charting library that ships both src and minified ESM bundles. ai
source-diff obfuscated-file:es5/modules/boost.js AI (source-diff): Standard minified ES5 build output with proper Highcharts copyright headers; expected distribution format for this package. ai
source-diff obfuscated-file:es5/modules/boost-canvas.js AI (source-diff): Standard minified ES5 build output with proper Highcharts copyright headers; expected distribution format for this package. ai
source-diff obfuscated-file:esm/themes/brand-dark.js AI (source-diff): Minified production build of Highcharts theme; standard for this package. ai
source-diff obfuscated-file:esm/modules/boost-canvas.js AI (source-diff): Minified production build of Highcharts boost-canvas module; standard for this package. ai
source-diff obfuscated-file:esm/indicators/bollinger-bands.js AI (source-diff): Minified production build of Highcharts stock indicator module; standard for this package. ai
source-diff obfuscated-file:esm/modules/broken-axis.js AI (source-diff): Minified production build of Highcharts broken-axis module; standard for this package. ai
source-diff obfuscated-file:esm/modules/boost.js AI (source-diff): Minified production build of Highcharts boost module; standard for this package. ai
source-diff obfuscated-file:themes/adaptive.js AI (source-diff): UMD-wrapped minified Highcharts theme; standard distribution format. ai
source-diff obfuscated-file:esm/themes/adaptive.js AI (source-diff): Minified Highcharts theme file with CSS variable definitions; clearly legitimate. ai
source-diff obfuscated-file:esm/indicators/acceleration-bands.js AI (source-diff): Minified production build of Highcharts stock indicator module; standard webpack output for this package. ai
source-diff obfuscated-file:esm/modules/accessibility.js AI (source-diff): Minified production build of Highcharts accessibility module; standard for this package. ai
source-diff obfuscated-file:esm/modules/annotations-advanced.js AI (source-diff): Minified production build of Highcharts annotations module; standard for this package. ai
source-diff obfuscated-file:esm/modules/annotations.js AI (source-diff): Minified production build of Highcharts annotations module; standard for this package. ai
source-diff obfuscated-file:esm/modules/arc-diagram.js AI (source-diff): Minified production build of Highcharts arc-diagram module; standard for this package. ai
source-diff obfuscated-file:esm/indicators/aroon-oscillator.js AI (source-diff): Minified production build of Highcharts stock indicator module; standard for this package. ai
source-diff obfuscated-file:esm/indicators/aroon.js AI (source-diff): Minified production build of Highcharts stock indicator module; standard for this package. ai
source-diff obfuscated-file:modules/pointandfigure.js AI (source-diff): Same as renko.js — standard Highcharts minified module distribution. ai
maintainer-change maintainer-added AI (maintainer-change): Added maintainers are known Highsoft AS team members visible in the Highcharts GitHub organization. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of 'blacklabel' is consistent with normal Highsoft team roster changes. ai
source-diff obfuscated-file:themes/brand-light.js AI (source-diff): Standard minified Highcharts theme file containing only chart styling config (colors, fonts, backgrounds). No executable payload. ai
source-diff obfuscated-file:themes/brand-dark.js AI (source-diff): Standard minified Highcharts theme file containing only chart styling config (colors, fonts, backgrounds). No executable payload. ai
license uncommon-license:https://www.highcharts.com/license AI (license): Highcharts has always used its own proprietary license; this is stable and well-known across all versions. ai
source-diff obfuscated-file:modules/data-tools.js AI (source-diff): Standard Highcharts minified production JS with copyright header; this is a dist package that ships minified modules by design. ai
source-diff large-new-source-files AI (source-diff): Major version bumps in Highcharts routinely add new chart type modules; expected for this package. ai
source-diff obfuscated-file:indicators/acceleration-bands.js AI (source-diff): Standard webpack-minified production build of Highcharts module; source .src.js files also shipped. Expected for this package. ai
provenance no-provenance AI (provenance): Highcharts has historically published without provenance; low-risk for this well-established package. ai
source-diff obfuscated-file:modules/arc-diagram.js AI (source-diff): Standard webpack-minified production build of Highcharts module; source .src.js files also shipped. ai
source-diff obfuscated-file:modules/annotations.js AI (source-diff): Standard webpack-minified production build of Highcharts module; source .src.js files also shipped. ai
source-diff obfuscated-file:modules/annotations-advanced.js AI (source-diff): Standard webpack-minified production build of Highcharts module; source .src.js files also shipped. ai
source-diff obfuscated-file:modules/accessibility.js AI (source-diff): Standard webpack-minified production build of Highcharts module; source .src.js files also shipped. ai

Versions (showing 44 of 44)

Version Deps Published
12.6.0 0 / 0
12.5.0 0 / 0
12.4.0 0 / 0
12.3.0 0 / 0
12.2.0 0 / 0
12.1.2 0 / 0
12.1.1 0 / 0
12.1.0 0 / 0
12.0.2 0 / 0
12.0.1 0 / 0
12.0.0 0 / 0
11.4.8 0 / 0
11.4.7 0 / 0
11.4.6 0 / 0
11.4.5 0 / 0
11.4.4 0 / 0
11.4.3 0 / 0
11.4.1 0 / 0
11.4.0 0 / 0
11.3.0 0 / 0
11.2.0 0 / 0
11.1.0 0 / 0
11.0.1 0 / 0
11.0.0 0 / 0
10.3.3 0 / 0
10.3.2 0 / 0
10.3.1 0 / 0
10.3.0 0 / 0
10.2.1 0 / 0
10.2.0 0 / 0
10.1.0 0 / 0
10.0.0 0 / 0
9.3.3 0 / 0
9.3.2 0 / 0
9.3.1 0 / 0
9.3.0 0 / 0
9.2.2 0 / 0
9.2.1 0 / 0
9.2.0 0 / 0
9.1.2 0 / 0
9.1.1 0 / 0
9.1.0 0 / 0
9.0.1 0 / 0
9.0.0 0 / 0