@everymatrix/casino-search-nd
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-DWGVT1W-.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-D5UzULjZ.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CkqjPCXl.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-gxj0m5Ug.js | AI (source-diff): Standard minified Stencil/Svelte build output; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-C08ivhZo.cjs | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-C4Iw5E6k.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-s7FVjPDD.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-C19FnebP.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-Chg9wJ0R.js | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-LzHRfjmo.cjs | AI (source-diff): Standard minified Stencil/Svelte build artifact; no malicious payload in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-DMpN2Rsr.cjs | AI (source-diff): Standard minified Svelte/Stencil build output; consistent with this package's established pattern across 400+ versions. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-CKbbtXF6.js | AI (source-diff): Standard minified Svelte component bundle; consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CLuKlqui.js | AI (source-diff): Standard minified build artifact; no malicious patterns detected. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-C9idzt1M.js | AI (source-diff): Standard minified build artifact; no malicious patterns detected. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-JoJQ3ksA.js | AI (source-diff): Standard minified Svelte component bundle; consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CO8grAZY.cjs | AI (source-diff): Standard minified build artifact with i18n strings; no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-BHc7Wabm.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-Dp6UKEuf.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-aXTwTqgM.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-BBL39_WX.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-BiVK2l1I.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-BPBPNapa.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent pattern across all @everymatrix releases. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-DtQwCzVc.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-DAwVkaRn.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-DDTj0iP4.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-5917qStv.js | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-CkzkW1Yf.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-BJCS3YIW.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; consistent with this package's build pattern across 400+ versions. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-D_Ier-i4.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-C_enZsu7.cjs | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped component library with no external deps; metadata flags are structural, not indicative of spam/malware. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-DAMmvp1T.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoSearchNd-BTJxIM3r.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-ChyjBXHw.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai | |
| source-diff | obfuscated-file:components/CasinoGameThumbnailNd-B70HDs5Q.js | AI (source-diff): Standard minified Svelte/Stencil bundle output; consistent across all versions of this component package. | ai |
Versions (showing 100 of 253)
| Version | Deps | Published |
|---|---|---|
| 1.83.2 | 0 / 0 | |
| 1.83.1 | 0 / 0 | |
| 1.83.0 | 0 / 0 | |
| 1.82.0 | 0 / 0 | |
| 1.81.2 | 0 / 0 | |
| 1.81.1 | 0 / 0 | |
| 1.81.0 | 0 / 0 | |
| 1.80.19 | 0 / 0 | |
| 1.80.18 | 0 / 0 | |
| 1.80.17 | 0 / 0 | |
| 1.80.16 | 0 / 0 | |
| 1.80.15 | 0 / 0 | |
| 1.80.14 | 0 / 0 | |
| 1.80.13 | 0 / 0 | |
| 1.80.12 | 0 / 0 | |
| 1.80.11 | 0 / 0 | |
| 1.80.10 | 0 / 0 | |
| 1.80.9 | 0 / 0 | |
| 1.80.8 | 0 / 0 | |
| 1.80.7 | 0 / 0 | |
| 1.80.6 | 0 / 0 | |
| 1.80.5 | 0 / 0 | |
| 1.80.4 | 0 / 0 | |
| 1.80.3 | 0 / 0 | |
| 1.80.2 | 0 / 0 | |
| 1.80.1 | 0 / 0 | |
| 1.80.0 | 0 / 0 | |
| 1.77.32 | 0 / 0 | |
| 1.77.31 | 0 / 0 | |
| 1.77.30 | 0 / 0 | |
| 1.77.29 | 0 / 0 | |
| 1.77.28 | 0 / 0 | |
| 1.77.27 | 0 / 0 | |
| 1.77.26 | 0 / 0 | |
| 1.77.25 | 0 / 0 | |
| 1.77.24 | 0 / 0 | |
| 1.77.23 | 0 / 0 | |
| 1.77.22 | 0 / 0 | |
| 1.77.21 | 0 / 0 | |
| 1.77.20 | 0 / 0 | |
| 1.77.19 | 0 / 0 | |
| 1.77.18 | 0 / 0 | |
| 1.77.17 | 0 / 0 | |
| 1.77.16 | 0 / 0 | |
| 1.77.15 | 0 / 0 | |
| 1.77.14 | 0 / 0 | |
| 1.77.13 | 0 / 0 | |
| 1.77.12 | 0 / 0 | |
| 1.77.11 | 0 / 0 | |
| 1.77.10 | 0 / 0 | |
| 1.77.9 | 0 / 0 | |
| 1.77.8 | 0 / 0 | |
| 1.77.7 | 0 / 0 | |
| 1.77.6 | 0 / 0 | |
| 1.77.5 | 0 / 0 | |
| 1.77.4 | 0 / 0 | |
| 1.77.3 | 0 / 0 | |
| 1.77.2 | 0 / 0 | |
| 1.77.1 | 0 / 0 | |
| 1.77.0 | 0 / 0 | |
| 1.76.14 | 0 / 0 | |
| 1.76.13 | 0 / 0 | |
| 1.76.12 | 0 / 0 | |
| 1.76.11 | 0 / 0 | |
| 1.76.10 | 0 / 0 | |
| 1.76.9 | 0 / 0 | |
| 1.76.8 | 0 / 0 | |
| 1.76.7 | 0 / 0 | |
| 1.76.6 | 0 / 0 | |
| 1.76.5 | 0 / 0 | |
| 1.76.4 | 0 / 0 | |
| 1.76.3 | 0 / 0 | |
| 1.76.1 | 0 / 0 | |
| 1.76.0 | 0 / 0 | |
| 1.75.1 | 0 / 0 | |
| 1.75.0 | 0 / 0 | |
| 1.74.10 | 0 / 0 | |
| 1.74.8 | 0 / 0 | |
| 1.74.7 | 0 / 0 | |
| 1.74.6 | 0 / 0 | |
| 1.74.5 | 0 / 0 | |
| 1.74.4 | 0 / 0 | |
| 1.74.3 | 0 / 0 | |
| 1.74.2 | 0 / 0 | |
| 1.74.1 | 0 / 0 | |
| 1.74.0 | 0 / 0 | |
| 1.73.2 | 0 / 0 | |
| 1.73.1 | 0 / 0 | |
| 1.73.0 | 0 / 0 | |
| 1.72.2 | 0 / 0 | |
| 1.72.1 | 0 / 0 | |
| 1.72.0 | 0 / 0 | |
| 1.71.1 | 0 / 0 | |
| 1.71.0 | 0 / 0 | |
| 1.70.1 | 0 / 0 | |
| 1.70.0 | 0 / 0 | |
| 1.69.3 | 0 / 0 | |
| 1.69.2 | 0 / 0 | |
| 1.69.0 | 0 / 0 | |
| 1.68.0 | 0 / 0 |
v1.77.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.68.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.