← Home

@bosonprotocol/react-kit

React toolkit with smart components and hooks for building on top of the Boson Protocol.

2
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

bosonprotocoladminlevalleuxludo

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Standard Proxy/Reflect pattern for connector delegation; not obfuscation. ai
semgrep semgrep:base64-decode AI (semgrep): Decodes image data URLs (data:image/...;base64,) — benign media handling. ai
phantom-deps phantom-dep:i AI (phantom-deps): Large React toolkit; phantom-dep heuristic fires on config-referenced deps. ai
phantom-deps phantom-dep:viem AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:stylis AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:nanoclone AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:lodash.merge AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:@svgr/webpack AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:valid-data-url AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:use-async-effect AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:eth-revert-reason AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:@ethersproject/units AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:react-error-boundary AI (phantom-deps): Stable false positive for this package's build config pattern. ai
phantom-deps phantom-dep:babel-plugin-styled-components AI (phantom-deps): Stable false positive for this package's build config pattern. ai

Versions (showing 2 of 2)

Version Deps Published
0.42.2 73 / 50
0.42.1 73 / 50

v0.42.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.42.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.