@everymatrix/lottery-game-page
3
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
clokzeoleksandr.v.stepanovtaras.maksymivnatalya.anisimovaemfe_releaserayiispmariana.gheorgheadrian.priponandriizadvirnyiraulvasileemstefan.vladgoe.sutadarie.tisaianustefanaotong.woodtikarncatalinpoclidcristi.ungureanumaria.bumbar1liviuclement.everymatrixmihaibalanfrankie24
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/lottery-game-page/general-multi-select_17.entry.js | AI (source-diff): CSS URL fetch for widget theming; same benign pattern as other build targets. | ai | |
| source-diff | obfuscated-file:dist/esm/general-multi-select_17.entry.js | AI (source-diff): Same Stencil.js ESM build output; minified but not obfuscated. | ai | |
| source-diff | net-exec-file:dist/esm/general-multi-select_17.entry.js | AI (source-diff): Same CSS theming fetch pattern; benign for this widget package. | ai | |
| source-diff | obfuscated-file:dist/lottery-game-page/general-multi-select_17.entry.js | AI (source-diff): Minified Stencil component bundle; consistent with existing package distribution format. | ai | |
| source-diff | obfuscated-file:dist/cjs/general-multi-select_17.cjs.entry.js | AI (source-diff): Standard Stencil.js minified build output for a UI widget; long lines are bundled component code, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/cjs/general-multi-select_17.cjs.entry.js | AI (source-diff): Network call is a CSS URL fetch for client theming; no arbitrary code execution — innerHTML set to fetched stylesheet text only. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all @everymatrix component packages; not a malice indicator here. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across the entire @everymatrix package family; stable false positive. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established @everymatrix org with 521 versions; sparse metadata is a CI publishing pattern, not spam. | ai |
v1.54.12
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.11
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.10
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.