All react-json-tree versions

react-json-tree @0.10.8

rejected
This version was rejected. It did not pass GreenFlagged's security review and is not served by the registry. The findings and risk dispositions below explain why.
100
Risk Score
MIT
License
No
Install Scripts
3
Dependencies
26
Dev Dependencies
17219.0 KB
Package Size
Published

React JSON Viewer Component, Extracted from redux-devtools

Maintainers

alexkuzchibicodegaearon

Keywords

reactjson viewer

Dependencies (3)

PackageConstraintRegistry Status
prop-types ^15.5.8 auto_approved
babel-runtime ^6.6.1 pending
react-base16-styling ^0.5.1 auto_approved

Dev Dependencies (26)

PackageConstraintRegistry Status
mocha ^2.4.5 auto_approved
react ^15.4.2 auto_approved
eslint ^2.8 auto_approved
expect ^1.18.0 auto_approved
rimraf ^2.5.2 auto_approved
isparta ^4.0.0 auto_approved
babel-cli ^6.7.7 auto_approved
react-dom ^15.4.2 auto_approved
babel-core ^6.7.7 auto_approved
pre-commit ^1.1.3 auto_approved
babel-eslint ^6.0.3 auto_approved
babel-loader ^6.2.4 pending
babel-preset-react ^6.5.0 auto_approved
babel-preset-es2015 ^6.6.0 auto_approved
eslint-plugin-babel ^3.2.0 auto_approved
eslint-plugin-react ^5.0.1 auto_approved
babel-preset-stage-0 ^6.5.0 auto_approved
eslint-config-airbnb ^8.0.0 auto_approved
eslint-plugin-import ^1.5.0 auto_approved
eslint-plugin-jsx-a11y ^1.0.2 auto_approved
react-addons-test-utils ^15.0.0 auto_approved
babel-preset-es2015-loose ^7.0.0 auto_approved
babel-plugin-transform-runtime ^6.7.5 auto_approved
babel-plugin-transform-decorators-legacy ^1.3.4 auto_approved
babel-plugin-transform-es3-property-literals ^6.5.0 auto_approved
babel-plugin-transform-es3-member-expression-literals ^6.5.0 auto_approved

Transitive Dependency Tree

11 transitive deps max depth 3
  ├─ babel-runtime ^6.6.1
  ├─ prop-types ^15.5.8 → 15.8.1
├─ react-base16-styling ^0.5.1 → 0.5.3
  ├─ base16 ^1.0.0 → 1.0.0
  ├─ lodash.curry ^4.0.1 → 4.1.1
  ├─ lodash.flow ^3.3.0 → 3.5.0
  ├─ loose-envify ^1.4.0 → 1.4.0
  ├─ object-assign ^4.1.1 → 4.1.1
  ├─ pure-color ^1.2.0 → 1.3.0
├─ react-is ^16.13.1 → 16.13.1
  ├─ js-tokens ^3.0.0 || ^4.0.0 → 4.0.0

Changes from v0.10.7

Dependency Changes

ChangePackageVersion
added prop-types ^15.5.8

File Changes

9976 added 0 removed 9 modified size delta: +48149.1 KB

SAST Findings (8)

HIGH Bundled binary files (5) npm-metadata

Package contains compiled binaries that could be backdoors: • packages/react-json-tree-demo-app/node_modules/fsevents/lib/binding/Release/node-v11-darwin-x64/fse.node • packages/react-json-tree-demo-app/node_modules/fsevents/lib/binding/Release/node-v46-darwin-x64/fse.node • packages/react-json-tree-demo-app/node_modules/fsevents/lib/binding/Release/node-v47-darwin-x64/fse.node • packages/react-json-tree-demo-app/node_modules/fsevents/lib/binding/Release/node-v48-darwin-x64/fse.node • packages/react-json-tree-demo-app/node_modules/fsevents/lib/binding/Release/node-v51-darwin-x64/fse.node

HIGH New obfuscated file: packages/react-json-tree-demo-app/node_modules/acorn/dist/acorn.es.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: packages/react-json-tree-demo-app/node_modules/acorn/dist/acorn.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New file with network + code execution: packages/react-json-tree-demo-app/node_modules/ajv/dist/ajv.bundle.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: packages/react-json-tree-demo-app/node_modules/ajv/dist/ajv.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: packages/react-json-tree-demo-app/node_modules/ajv/dist/nodent.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

HIGH New file with network + code execution: packages/react-json-tree-demo-app/node_modules/ajv/dist/regenerator.min.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

Review Summary

Risk score: 100 (capped from 198). Findings: 7 high (+175), 2 medium (+20), 1 low (+3), 1 info (+0).

Commit: 75fbc111920f Browse source

Published to npm: