← Home

html2canvas-pro

24
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

yorickshan

Keywords

html2canvasscreenshot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/html2canvas-pro.cjs AI (source-diff): Long string is a base64 UTRIE2 Unicode data table in build output; benign and stable across versions. ai
source-diff obfuscated-file:dist/html2canvas-pro.cjs AI (source-diff): Bundled minified dist output, legible with license banner; stable build artifact. ai
source-diff net-exec-file:dist/html2canvas-pro.cjs AI (source-diff): Same bundled dist; net+exec pattern is benign library code, no hostile target. ai
provenance missing-githead AI (provenance): CI/CD publish via GitHub Actions with SLSA provenance; gitHead absence is expected. ai
provenance publisher-changed AI (provenance): Transition from manual publish to GitHub Actions CI/CD with SLSA attestation. ai
semgrep semgrep:new-function-constructor AI (semgrep): CSS color expression evaluator inherited from html2canvas; stable pattern. ai
semgrep semgrep:etc-passwd-access AI (semgrep): Test file validating that file:// URLs are rejected; not credential harvesting. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Test assertions verifying that raw-IP URLs are rejected by the validator. ai
source-diff encoded-string-file:dist/html2canvas-pro.esm.js AI (source-diff): Long strings are base64 alphabet and Unicode property tables used for CSS text rendering — benign build artifact. ai
source-diff encoded-string-file:dist/html2canvas-pro.min.js AI (source-diff): Minified bundle of the same source; encoded strings are identical Unicode/base64 tables. ai
source-diff encoded-string-file:dist/html2canvas-pro.js AI (source-diff): Same base64/Unicode table data as esm build; stable false positive for this package. ai

Versions (showing 24 of 24)

Version Deps Published
2.3.2 2 / 58
2.3.1 2 / 58
2.3.0 2 / 58
2.2.4 2 / 59
2.2.3 2 / 59
2.2.2 2 / 59
2.2.1 2 / 59
2.2.0 2 / 59
2.1.1 2 / 64
2.1.0 2 / 70
2.0.4 2 / 71
2.0.3 2 / 71
2.0.2 2 / 71
2.0.1 2 / 71
2.0.0 2 / 71
1.6.7 2 / 70
1.6.6 2 / 70
1.6.5 2 / 70
1.6.4 2 / 70
1.6.3 2 / 70
1.6.2 2 / 70
1.6.1 2 / 70
1.6.0 2 / 67
1.5.13 2 / 67

v2.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.1

2 findings
HIGH Long encoded string in modified file: dist/html2canvas-pro.cjs source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.3.0

3 findings
HIGH New obfuscated file: dist/html2canvas-pro.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: dist/html2canvas-pro.cjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.3

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v2.2.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

v2.2.1

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.