← Home

@dodoex/widgets

DODO Widgets

14
Versions
GPL-3.0-or-later
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

dodo-dev

Keywords

dodowidgetsinterfaces

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@dodoex/api AI (dependencies): First-party DODO ecosystem dep; consistent with package purpose across all versions. ai
dependencies unvetted-dep:@web3-react/walletconnect-v2 AI (dependencies): Well-known web3-react library; expected for a DeFi widget package. ai
dependencies unvetted-dep:@web3-react/metamask AI (dependencies): Well-known web3-react library; expected for a DeFi widget package. ai
dependencies unvetted-dep:@web3-react/eip1193 AI (dependencies): Well-known web3-react library; expected for a DeFi widget package. ai
dependencies unvetted-dep:@web3-react/core AI (dependencies): Well-known web3-react library; expected for a DeFi widget package. ai
dependencies unvetted-dep:@dodoex/dodo-contract-request AI (dependencies): First-party DODO ecosystem dep; stable pattern. ai
dependencies unvetted-dep:@dodoex/contract-request AI (dependencies): First-party DODO ecosystem dep; stable pattern. ai
dependencies unvetted-dep:@dodoex/components AI (dependencies): First-party DODO ecosystem dep; stable pattern. ai
dependencies unvetted-dep:@dodoex/icons AI (dependencies): First-party DODO ecosystem dep; stable pattern. ai
phantom-deps phantom-dep:semantic-release AI (phantom-deps): semantic-release is a dev/release tooling dep listed in package.json; not a runtime import concern for this package. ai
phantom-deps phantom-dep:@dodoex/icons AI (phantom-deps): Same-org scope; bundled into dist output. ai
phantom-deps phantom-dep:@ethersproject/contracts AI (phantom-deps): Web3 contract dep used via convention; stable false positive for this package. ai
phantom-deps phantom-dep:react-icons AI (phantom-deps): UI icon dep; stable false positive for this package. ai
phantom-deps phantom-dep:make-plural AI (phantom-deps): i18n plural support dep; stable false positive for this package. ai
phantom-deps phantom-dep:moment AI (phantom-deps): Likely used transitively or via config; stable false positive for this package. ai
phantom-deps phantom-dep:@reduxjs/toolkit AI (phantom-deps): State management dep used via config/convention; stable false positive for this package. ai
phantom-deps phantom-dep:@babel/runtime AI (phantom-deps): Framework-scoped package loaded by convention; stable false positive. ai
phantom-deps phantom-dep:@semantic-release/changelog AI (phantom-deps): Release tooling declared in deps by mistake; not a runtime concern. ai
phantom-deps phantom-dep:@semantic-release/git AI (phantom-deps): Release tooling declared in deps by mistake; not a runtime concern. ai
phantom-deps phantom-dep:@lingui/macro AI (phantom-deps): Build-time i18n macro; not a runtime import, stable false positive for this package. ai

Versions (showing 14 of 14)

Version Deps Published
3.19.0 44 / 42
3.15.0 44 / 42
3.11.0 44 / 43
3.10.7 44 / 43
3.10.6 44 / 43
3.10.5 44 / 43
3.10.4 44 / 43
3.10.1 44 / 43
3.7.0 44 / 43
3.6.0 44 / 43
3.3.0 44 / 43
3.1.3 45 / 43
3.1.2 45 / 43
3.1.1 45 / 43

v3.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.10.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.10.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.10.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.10.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.10.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.