html2canvas-pro
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/html2canvas-pro.cjs | AI (source-diff): Long string is a base64 UTRIE2 Unicode data table in build output; benign and stable across versions. | ai | |
| source-diff | obfuscated-file:dist/html2canvas-pro.cjs | AI (source-diff): Bundled minified dist output, legible with license banner; stable build artifact. | ai | |
| source-diff | net-exec-file:dist/html2canvas-pro.cjs | AI (source-diff): Same bundled dist; net+exec pattern is benign library code, no hostile target. | ai | |
| provenance | missing-githead | AI (provenance): CI/CD publish via GitHub Actions with SLSA provenance; gitHead absence is expected. | ai | |
| provenance | publisher-changed | AI (provenance): Transition from manual publish to GitHub Actions CI/CD with SLSA attestation. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): CSS color expression evaluator inherited from html2canvas; stable pattern. | ai | |
| semgrep | semgrep:etc-passwd-access | AI (semgrep): Test file validating that file:// URLs are rejected; not credential harvesting. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Test assertions verifying that raw-IP URLs are rejected by the validator. | ai | |
| source-diff | encoded-string-file:dist/html2canvas-pro.esm.js | AI (source-diff): Long strings are base64 alphabet and Unicode property tables used for CSS text rendering — benign build artifact. | ai | |
| source-diff | encoded-string-file:dist/html2canvas-pro.min.js | AI (source-diff): Minified bundle of the same source; encoded strings are identical Unicode/base64 tables. | ai | |
| source-diff | encoded-string-file:dist/html2canvas-pro.js | AI (source-diff): Same base64/Unicode table data as esm build; stable false positive for this package. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 2.3.2 | 2 / 58 | |
| 2.3.1 | 2 / 58 | |
| 2.3.0 | 2 / 58 | |
| 2.2.4 | 2 / 59 | |
| 2.2.3 | 2 / 59 | |
| 2.2.2 | 2 / 59 | |
| 2.2.1 | 2 / 59 | |
| 2.2.0 | 2 / 59 | |
| 2.1.1 | 2 / 64 | |
| 2.1.0 | 2 / 70 | |
| 2.0.4 | 2 / 71 | |
| 2.0.3 | 2 / 71 | |
| 2.0.2 | 2 / 71 | |
| 2.0.1 | 2 / 71 | |
| 2.0.0 | 2 / 71 | |
| 1.6.7 | 2 / 70 | |
| 1.6.6 | 2 / 70 | |
| 1.6.5 | 2 / 70 | |
| 1.6.4 | 2 / 70 | |
| 1.6.3 | 2 / 70 | |
| 1.6.2 | 2 / 70 | |
| 1.6.1 | 2 / 70 | |
| 1.6.0 | 2 / 67 | |
| 1.5.13 | 2 / 67 |
v2.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.1
2 findingsModified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.3.0
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.3
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v2.2.2
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.
v2.2.1
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.