@crossmint/client-sdk-react-ui
React SDK for integrating [Crossmint Wallets](https://docs.crossmint.com) into your application. Provides providers, hooks, and built-in UI for wallet creation, signing, OTP verification, and passkey flows.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:react-jss | AI (phantom-deps): react-jss is a styling dependency used indirectly; stable false positive for this SDK package. | ai | |
| phantom-deps | phantom-dep:@crossmint/client-sdk-auth | AI (phantom-deps): Same-org monorepo package; declared as dep and used transitively, not a phantom. | ai | |
| phantom-deps | phantom-dep:@ethersproject/transactions | AI (phantom-deps): Referenced in config/type declarations; stable false positive for this wallet SDK. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 4.2.8 | 28 / 10 | |
| 4.2.7 | 28 / 10 | |
| 4.2.6 | 28 / 10 | |
| 4.2.5 | 28 / 10 | |
| 4.2.4 | 28 / 10 | |
| 4.2.3 | 28 / 10 | |
| 4.2.2 | 28 / 10 | |
| 4.2.1 | 28 / 10 | |
| 4.2.0 | 28 / 10 | |
| 2.6.18 | 29 / 10 | |
| 2.6.2 | 28 / 9 |
v4.2.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.6.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.