← Home

pdfmake

45
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bpampuchdanawoodmanmiltadorliborm85

Keywords

pdfjavascriptprintinglayout

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dev-playground/public/ace.js AI (source-diff): Vendored ace editor for dev playground; minified. ai
source-diff obfuscated-file:build/pdfmake.js AI (source-diff): Webpack bundle output, not obfuscation. ai
source-diff source-size-tripled AI (source-diff): Growth is committed webpack bundles + fonts, not injected payload. ai
source-diff net-exec-file:build/pdfmake.js AI (source-diff): Browser bundle with window.open/blob PDF handling; benign. ai
source-diff obfuscated-file:build/vfs_fonts.js AI (source-diff): Base64-encoded embedded fonts (VFS), standard pdfmake asset. ai
source-diff net-exec-file:build/pdfmake.min.js AI (source-diff): Minified browser bundle of same source; benign. ai
dependencies unvetted-dep:pdfmake-pdfkit AI (dependencies): Legitimate fork swap by trusted long-standing maintainer, not a supply-chain attack. ai
phantom-deps phantom-dep:iconv-lite AI (phantom-deps): Used via config/build references, not a direct import; stable FP. ai
source-diff encoded-string-file:build/vfs_fonts.js AI (source-diff): Embedded base64 TTF font data in generated VFS bundle; benign and stable. ai
npm-metadata url-dep:svg-to-pdfkit AI (npm-metadata): Long-standing SHA-pinned devDependency for vendored fork; not a runtime risk. ai
source-diff encoded-string-file:build/pdfmake.js AI (source-diff): Webpack bundle embeds base64 font/Unicode data; expected for a PDF library. ai
source-diff encoded-string-file:build/pdfmake.min.js AI (source-diff): Minified build bundle with same embedded font data; stable false positive. ai
dependencies unvetted-dep:@foliojs-fork/linebreak AI (dependencies): @foliojs-fork/linebreak is a known Folio.js fork used by pdfmake for line-breaking logic; stable, legitimate dependency. ai
dependencies unvetted-dep:@foliojs-fork/pdfkit AI (dependencies): @foliojs-fork/pdfkit is pdfmake's long-standing PDF rendering engine dependency; a known, legitimate fork used across versions. ai
email-domain unclaimed-email:yandex.ua AI (email-domain): Historical maintainer email on defunct yandex.ua domain; package published via GitHub Actions with SLSA provenance, not via this maintainer's npm credentials. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding of data-URI embedded images is core PDF generation functionality for pdfmake; not a malicious payload. ai

Versions (showing 45 of 45)

Version Deps Published
0.3.11 3 / 31
0.3.10 3 / 31
0.3.9 3 / 31
0.3.8 3 / 31
0.3.7 3 / 31
0.3.6 3 / 31
0.2.23 4 / 31
0.2.22 4 / 31
0.2.21 4 / 31
0.2.20 4 / 31
0.2.19 4 / 31
0.2.18 4 / 31
0.2.17 4 / 31
0.2.16 4 / 31
0.2.15 4 / 31
0.2.14 4 / 29
0.2.13 4 / 29
0.2.12 4 / 29
0.2.11 4 / 29
0.2.2 5 / 26
0.1.24 2 / 22
0.1.23 2 / 28
0.1.22 2 / 27
0.1.17 3 / 11
0.1.14 1 / 10
0.1.13 1 / 10
0.1.11 1 / 10
0.1.8 1 / 10
0.1.6 1 / 10
0.1.4 1 / 10
0.1.3 1 / 10
0.1.2 1 / 10
0.0.41 1 / 9
0.0.12 1 / 9
0.0.11 1 / 9
0.0.10 1 / 9
0.0.9 1 / 9
0.0.8 1 / 9
0.0.7 1 / 9
0.0.6 1 / 9
0.0.5 1 / 9
0.0.4 1 / 9
0.0.3 1 / 5
0.0.2 1 / 5
0.0.1 1 / 5

v0.2.18

2 findings
HIGH Long encoded string in modified file: build/vfs_fonts.js source-diff

Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.17

2 findings
HIGH Long encoded string in modified file: build/vfs_fonts.js source-diff

Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.16

2 findings
HIGH Long encoded string in modified file: build/vfs_fonts.js source-diff

Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.15

2 findings
HIGH Long encoded string in modified file: build/vfs_fonts.js source-diff

Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.14

2 findings
HIGH Long encoded string in modified file: build/vfs_fonts.js source-diff

Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.13

2 findings
HIGH Long encoded string in modified file: build/vfs_fonts.js source-diff

Modified file contains 4 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.2

6 findings
HIGH New obfuscated file: build/pdfmake.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/pdfmake.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: build/pdfmake.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/vfs_fonts.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: bpampuch → liborm85 (on 2021-08-02, unremoved on npm for 1813d) provenance

This version was published by a different npm account (liborm85) than the most recent previously approved version (bpampuch) on 2021-08-02. It has since remained available on npm for 1813 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.24

7 findings
HIGH New obfuscated file: build/pdfmake.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/pdfmake.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: build/pdfmake.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/vfs_fonts.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dev-playground/public/ace.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: bpampuch → liborm85 (on 2017-01-08, unremoved on npm for 3480d) provenance

This version was published by a different npm account (liborm85) than the most recent previously approved version (bpampuch) on 2017-01-08. It has since remained available on npm for 3480 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.23

7 findings
HIGH New obfuscated file: build/pdfmake.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/pdfmake.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: build/pdfmake.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/vfs_fonts.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dev-playground/public/ace.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: bpampuch → liborm85 (on 2016-12-29, unremoved on npm for 3490d) provenance

This version was published by a different npm account (liborm85) than the most recent previously approved version (bpampuch) on 2016-12-29. It has since remained available on npm for 3490 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.22

7 findings
HIGH New obfuscated file: build/pdfmake.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: build/pdfmake.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: build/pdfmake.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New obfuscated file: build/vfs_fonts.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dev-playground/public/ace.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: bpampuch → liborm85 (on 2016-12-23, unremoved on npm for 3496d) provenance

This version was published by a different npm account (liborm85) than the most recent previously approved version (bpampuch) on 2016-12-23. It has since remained available on npm for 3496 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.41

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.