@everymatrix/casino-search-nd
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-DWGVT1W-.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-D5UzULjZ.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CkqjPCXl.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-gxj0m5Ug.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-C08ivhZo.cjs | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-C4Iw5E6k.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-s7FVjPDD.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-C19FnebP.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-Chg9wJ0R.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-LzHRfjmo.cjs | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-DMpN2Rsr.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established pattern across 400+ versions. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-CKbbtXF6.js | AI (source-diff): Standard minified Svelte component bundle; consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CLuKlqui.js | AI (source-diff): Standard minified build artifact; no malicious patterns detected. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-C9idzt1M.js | AI (source-diff): Standard minified build artifact; no malicious patterns detected. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-JoJQ3ksA.js | AI (source-diff): Standard minified Svelte component bundle; consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CO8grAZY.cjs | AI (source-diff): Standard minified build artifact with i18n strings; no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-BHc7Wabm.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-Dp6UKEuf.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-aXTwTqgM.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-BBL39_WX.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-BiVK2l1I.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-BPBPNapa.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-DtQwCzVc.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-DAwVkaRn.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-DDTj0iP4.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-5917qStv.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CkzkW1Yf.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-BJCS3YIW.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern across 400+ versions. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-D_Ier-i4.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-C_enZsu7.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped component library with no external deps; metadata flags are structural, not indicative of spam/malware. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-DAMmvp1T.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-BTJxIM3r.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-ChyjBXHw.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-B70HDs5Q.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai |
Versions (showing 6 of 254)
| Version | Deps | Published |
|---|---|---|
| 1.67.3 | 0 / 0 | |
| 1.67.0 | 0 / 0 | |
| 1.66.2 | 0 / 0 | |
| 1.66.1 | 0 / 0 | |
| 1.66.0 | 0 / 0 | |
| 1.65.3 | 0 / 0 |
v1.67.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.67.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.