← Home

@cartridge/controller

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

tarrencevbroodyc7e-steeb

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/policies-CIjnh8g_.js AI (source-diff): Bundled/minified Vite output, not obfuscation; consistent across releases. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): tsup bundle output with readable source, not true obfuscation. ai
source-diff source-size-tripled AI (source-diff): Explained by new features/deps, no malicious payload found. ai
source-diff large-new-source-files AI (source-diff): Expected from new session/telegram feature modules and bundler output. ai
source-diff obfuscated-file:dist/controller.cjs AI (source-diff): tsup bundle output, not obfuscation; readable source with comments. ai
source-diff obfuscated-file:dist/session/index.cjs AI (source-diff): tsup bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): tsup bundle output, not obfuscation. ai
source-diff obfuscated-file:dist/provider.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/session/index.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/icon.js AI (source-diff): base64 image data inflates line length, not obfuscated code. ai
source-diff obfuscated-file:dist/controller.js AI (source-diff): tsup bundle output with readable source comments, not obfuscation. ai
source-diff obfuscated-file:dist/telegram/provider.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/session/provider.js AI (source-diff): tsup bundle output, readable source. ai
source-diff obfuscated-file:dist/provider-BN3lM6-S.js AI (source-diff): Vite/rollup bundled chunk, not obfuscated. ai
source-diff obfuscated-file:dist/provider-CyO7_h7r.js AI (source-diff): Bundled/minified vite build output. ai
source-diff obfuscated-file:dist/provider-Dr912mPw.js AI (source-diff): Bundled build output, not obfuscation. ai
source-diff obfuscated-file:dist/node/index.js AI (source-diff): Bundled build output, readable ESM source. ai
source-diff obfuscated-file:dist/node/index.cjs AI (source-diff): Bundled tsup/vite output, not obfuscation; matches readable src. ai
semgrep semgrep:base64-decode AI (semgrep): Standard Solana tx deserialization, not payload hiding. ai
source-diff obfuscated-file:dist/icon.d.ts AI (source-diff): Base64 PNG data URI, not code obfuscation. ai
source-diff obfuscated-file:dist/provider-CH2PlazB.js AI (source-diff): Minified vite chunk, not true obfuscation. ai
source-diff obfuscated-file:src/icon.ts AI (source-diff): Same base64 icon asset in source form. ai
phantom-deps phantom-dep:fast-deep-equal AI (phantom-deps): Used via config/build tooling, stable false positive. ai
source-diff obfuscated-file:dist/policies-zfnBVwh-.js AI (source-diff): Bundler-minified output with readable logic, not true obfuscation; matches known package behavior. ai
phantom-deps phantom-dep:query-string AI (phantom-deps): Config-only usage, stable false positive. ai
dependencies unvetted-dep:@cartridge/account-wasm AI (dependencies): Same-org first-party dep, version-pinned to match this package. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party sibling package, not an external supply-chain risk. ai
phantom-deps phantom-dep:base64url AI (phantom-deps): Config-only usage, stable false positive. ai
phantom-deps phantom-dep:@cartridge/account-wasm AI (phantom-deps): Same org scope, config-referenced. ai
source-diff obfuscated-file:dist/policies-C7KnWtOU.js AI (source-diff): Minified bundler output, readable variable/module structure, no malicious behavior. ai
source-diff obfuscated-file:dist/react/index.js AI (source-diff): Minified bundler output (Vite), not true obfuscation; imports are legible. ai
source-diff obfuscated-file:dist/provider-Bsw_spHR.js AI (source-diff): Vite/Rollup minified bundle output; readable code with starknet imports, not obfuscated malware. ai
source-diff obfuscated-file:dist/index-C7KGk-LM.js AI (source-diff): Standard Vite bundle output; sample shows readable, non-malicious code. Long lines are minification artifacts. ai
source-diff obfuscated-file:dist/provider-NKp7_oNj.js AI (source-diff): Standard Vite/Rollup bundle output; readable code with no obfuscation or encoded payloads. ai
source-diff obfuscated-file:dist/provider-DSqqvDee.js AI (source-diff): Standard Vite/Rollup bundle output with hashed filename; readable code, not malicious obfuscation. ai
source-diff obfuscated-file:dist/provider-B8OiOgBt.js AI (source-diff): Standard Vite/Rollup minified bundle output; content is readable and benign for this package. ai
source-diff obfuscated-file:dist/provider-BgBI_LQl.js AI (source-diff): Standard Vite/Rollup minified bundle output; sample shows readable starknet business logic, not obfuscation. ai
source-diff obfuscated-file:dist/provider-bC9cKItb.js AI (source-diff): Standard Vite/Rollup minified bundle; sample shows readable starknet imports, not obfuscation. ai
source-diff obfuscated-file:dist/provider-D-5qL7QC.js AI (source-diff): Standard Vite/Rollup minified bundle output; content is readable and benign for this wallet controller package. ai
source-diff obfuscated-file:dist/provider-PftcmETC.js AI (source-diff): Standard Vite/rollup minified bundle output; readable code with starknet imports, not malicious obfuscation. ai
source-diff obfuscated-file:dist/provider-CN6AecRF.js AI (source-diff): Standard Vite/Rollup minified bundle output; readable code, no actual obfuscation or malicious patterns. ai
source-diff obfuscated-file:dist/provider-DSw1EyU9.js AI (source-diff): Standard Vite/Rollup minified bundle; code is readable and matches package functionality. ai
source-diff obfuscated-file:dist/provider-S-IvFw23.js AI (source-diff): Standard Vite/Rollup minified ESM bundle output; content is readable and matches package functionality. ai
source-diff obfuscated-file:dist/provider-CznCrt4b.js AI (source-diff): Standard Vite/Rollup minified bundle output; readable code with no obfuscation indicators. ai
source-diff obfuscated-file:dist/index-CJNujYxo.js AI (source-diff): Standard Vite/rollup minified bundle output; readable identifiers, no encoding or obfuscation techniques present. ai
source-diff obfuscated-file:dist/provider-BQFas4CN.js AI (source-diff): Standard Vite/Rollup minified bundle output; content is readable and matches expected package functionality. ai
source-diff obfuscated-file:dist/index-BdTFKueB.js AI (source-diff): Standard Vite/rollup minified bundle output; sample shows readable starknet imports and enum patterns, not obfuscation. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publisher with SLSA provenance attestation; legitimate automation pattern. ai
source-diff obfuscated-file:dist/index-CYAUAqql.js AI (source-diff): Standard Vite/Rollup minified bundle output; readable identifiers, no suspicious payloads. ai
source-diff obfuscated-file:dist/provider-s-80NdXp.js AI (source-diff): Standard Vite/rollup minified bundle output; not obfuscated malware. Stable pattern for this package. ai
source-diff obfuscated-file:dist/index-BBfUA93L.js AI (source-diff): Vite/Rollup build output; sample shows readable starknet code, not actual obfuscation. Stable pattern for this package. ai
phantom-deps phantom-dep:@cartridge/utils AI (phantom-deps): Same-org sibling package in monorepo; phantom-dep is a stable false positive for this package. ai
phantom-deps phantom-dep:open AI (phantom-deps): Likely used in Node.js build/config path; phantom-dep heuristic misses config-file imports. ai
phantom-deps phantom-dep:@walletconnect/ethereum-provider AI (phantom-deps): Likely used in browser bundle path; phantom-dep heuristic misses config-file imports. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decode is standard Solana transaction serialization in utils/solana — no obfuscation concern. ai
phantom-deps phantom-dep:@turnkey/sdk-browser AI (phantom-deps): Likely used in browser bundle path; phantom-dep heuristic misses config-file imports. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): Raw IP is 127.0.0.1 in a test file validating iframe URL security — not a real network call. ai
phantom-deps phantom-dep:cbor-x AI (phantom-deps): Likely used in Node.js build/config path; phantom-dep heuristic misses config-file imports. ai

Versions (showing 51 of 83)

View all versions
Version Deps Published
0.13.15 14 / 24
0.13.14 14 / 24
0.13.13 14 / 24
0.13.12 13 / 15
0.13.11 13 / 15
0.13.10 13 / 15
0.13.9 14 / 15
0.13.7 14 / 15
0.13.6 14 / 15
0.13.5 14 / 15
0.13.4 13 / 15
0.13.3 13 / 15
0.12.2 13 / 15
0.12.1 13 / 15
0.12.0 13 / 15
0.11.3 13 / 15
0.11.2 13 / 15
0.11.1 13 / 15
0.10.7 13 / 15
0.10.6 13 / 15
0.10.5 13 / 15
0.10.4 13 / 15
0.10.3 13 / 15
0.10.2 13 / 15
0.10.1 13 / 15
0.10.0 13 / 15
0.9.3 9 / 15
0.9.2 9 / 15
0.9.1 9 / 15
0.9.0 9 / 15
0.8.0 9 / 15
0.7.13 10 / 14
0.7.12 6 / 14
0.7.11 6 / 14
0.7.10 6 / 14
0.7.9 6 / 14
0.7.8 7 / 8
0.7.7 7 / 8
0.7.6 7 / 8
0.7.5 7 / 8
0.7.4 7 / 8
0.7.3 7 / 8
0.7.2 7 / 8
0.7.1 7 / 8
0.7.0 7 / 8
0.6.0 8 / 6
0.5.9 9 / 6
0.5.8 9 / 3
0.5.7 9 / 3
0.5.6 9 / 3
0.5.5 9 / 3

v0.13.15

2 findings
HIGH New obfuscated file: dist/policies-CIjnh8g_.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.14

2 findings
HIGH New obfuscated file: dist/policies-zfnBVwh-.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.13

3 findings
HIGH New obfuscated file: dist/react/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/policies-C7KnWtOU.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.12

7 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-BN3lM6-S.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2025-04-17, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2025-04-17, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.11

6 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-CyO7_h7r.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.10

6 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-Dr912mPw.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.9

6 findings
HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider-CH2PlazB.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.8

4 findings
HIGH New obfuscated file: dist/controller.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.6

9 findings
HIGH New obfuscated file: dist/controller.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/controller.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/node/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.5

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: broody → tarrencev (on 2025-03-12, known maintainer) provenance

This version was published by a different npm account (tarrencev) than the most recent previously approved version (broody) on 2025-03-12, but tarrencev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tarrencev → broody (on 2025-03-03, known maintainer) provenance

This version was published by a different npm account (broody) than the most recent previously approved version (tarrencev) on 2025-03-03, but broody is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v0.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.6

9 findings
HIGH New obfuscated file: dist/controller.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/session/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/telegram/provider.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/icon.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/icon.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.