@everymatrix/casino-search
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:sirv-cli | AI (phantom-deps): Used in start script, not source-imported; normal for CLI tooling deps. | ai | |
| phantom-deps | phantom-dep:cross-env | AI (phantom-deps): Used in build/dev scripts, not directly imported by design. | ai | |
| phantom-deps | phantom-dep:svelte | AI (phantom-deps): Referenced via svelte field/config, standard Svelte component setup. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-0cPu_cTV.cjs | AI (source-diff): Bundled build output (moment.js + rollup boilerplate), not obfuscation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Routine internal team rotation for EveryMatrix, no takeover indicators. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Routine internal team rotation for EveryMatrix, no takeover indicators. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-DPcvWdoQ.cjs | AI (source-diff): Bundled build output, matches standard bundler patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-TDEcfPzh.cjs | AI (source-diff): Bundled/minified Rollup output (moment.js bundle), not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-BhPK_XqJ.cjs | AI (source-diff): Bundled/minified Rollup output, not true obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-CHWKXbEA.js | AI (source-diff): Bundled component chunk, standard minified build output. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-CkmC9Ibv.js | AI (source-diff): Bundled component chunk, standard minified build output. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Dg4_Hdz9.js | AI (source-diff): Bundled component chunk, standard minified build output. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-DJkurJZy.js | AI (source-diff): Bundled component chunk, standard minified build output. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Long-established internal EveryMatrix component library, not spam. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-Bi5AHHzj.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; no malicious patterns in code samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-Be9Kkkrr.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; no malicious patterns in code samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-CCHaKGsz.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; no malicious patterns in code samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-BNm3Msnp.js | AI (source-diff): Standard Rollup/Vite minified build output for a UI component library; no malicious patterns in code samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-C6ZQ-wb3.js | AI (source-diff): Standard Rollup/Vite minified bundle output for a Stencil web component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-D8esX7vX.js | AI (source-diff): Standard Rollup/Vite minified bundle output for a Stencil web component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-G_e-1fOs.js | AI (source-diff): Standard Rollup/Vite minified bundle output for a Stencil web component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-B8gSdop-.js | AI (source-diff): Standard Rollup/Vite minified bundle output for a Stencil web component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-Bu9XPiUi.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output for a Stencil web component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-DXJvwA9Y.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output for a Stencil web component; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-wM3wq09s.js | AI (source-diff): Standard Rollup/Vite minified build output with hashed filenames; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnail-zq4x5KAZ.js | AI (source-diff): Standard Rollup/Vite minified build output with hashed filenames; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-BXPjf81G.js | AI (source-diff): Standard Rollup/Vite minified build output with hashed filenames; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoSearch-tIVOyy1y.js | AI (source-diff): Standard Rollup/Vite minified build output with hashed filenames; not malicious obfuscation. | ai |
Versions (showing 51 of 560)
| Version | Deps | Published |
|---|---|---|
| 1.94.81 | 0 / 0 | |
| 1.94.80 | 0 / 0 | |
| 1.94.79 | 0 / 0 | |
| 1.94.78 | 0 / 0 | |
| 1.94.77 | 0 / 0 | |
| 1.94.76 | 0 / 0 | |
| 1.94.75 | 0 / 0 | |
| 1.94.74 | 0 / 0 | |
| 1.94.73 | 0 / 0 | |
| 1.94.72 | 0 / 0 | |
| 1.94.71 | 0 / 0 | |
| 1.94.70 | 0 / 0 | |
| 1.94.69 | 0 / 0 | |
| 1.94.68 | 0 / 0 | |
| 1.94.67 | 0 / 0 | |
| 1.94.66 | 0 / 0 | |
| 1.94.65 | 0 / 0 | |
| 1.94.64 | 0 / 0 | |
| 1.94.63 | 0 / 0 | |
| 1.94.62 | 0 / 0 | |
| 1.94.61 | 0 / 0 | |
| 1.94.60 | 0 / 0 | |
| 1.94.59 | 0 / 0 | |
| 1.94.58 | 0 / 0 | |
| 1.94.57 | 0 / 0 | |
| 1.94.56 | 0 / 0 | |
| 1.94.55 | 0 / 0 | |
| 1.94.54 | 0 / 0 | |
| 1.94.53 | 0 / 0 | |
| 1.94.52 | 0 / 0 | |
| 1.94.51 | 0 / 0 | |
| 1.94.50 | 0 / 0 | |
| 1.94.49 | 0 / 0 | |
| 1.94.48 | 0 / 0 | |
| 1.94.47 | 0 / 0 | |
| 1.94.46 | 0 / 0 | |
| 1.94.45 | 0 / 0 | |
| 1.94.44 | 0 / 0 | |
| 1.94.43 | 0 / 0 | |
| 1.94.42 | 0 / 0 | |
| 1.94.41 | 0 / 0 | |
| 1.94.40 | 0 / 0 | |
| 1.94.39 | 0 / 0 | |
| 1.94.38 | 0 / 0 | |
| 1.94.37 | 0 / 0 | |
| 1.94.36 | 0 / 0 | |
| 1.94.35 | 0 / 0 | |
| 1.94.34 | 0 / 0 | |
| 1.94.33 | 0 / 0 | |
| 1.94.32 | 0 / 0 | |
| 1.94.31 | 0 / 0 |
v1.94.81
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.80
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.79
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.78
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.77
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.76
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.75
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.74
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.73
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.72
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.71
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.70
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.69
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.68
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.67
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.66
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.65
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.64
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.63
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.62
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.61
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.60
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.59
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.58
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.55
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.94.53
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.