← Home

@everymatrix/lottery-tipping-page

31
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

clokzeoleksandr.v.stepanovtaras.maksymivnatalya.anisimovaemfe_releaserayiispmariana.gheorgheadrian.priponandriizadvirnyiraulvasileemstefan.vladgoe.sutadarie.tisaianustefanaotong.woodtikarncatalinpoclidcristi.ungureanumaria.bumbar1liviuclement.everymatrixmihaibalanfrankie24

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cjs/app-tooltip_21.cjs.entry.js AI (source-diff): Stencil.js bundled/minified component output, not obfuscation. ai
maintainer-change maintainer-removed AI (maintainer-change): Same org transition, not a takeover pattern. ai
maintainer-change maintainer-added AI (maintainer-change): Internal EveryMatrix org maintainer rotation, provenance unchanged. ai
source-diff obfuscated-file:dist/lottery-tipping-page/lottery-tipping-page-54ab9176.js AI (source-diff): Minified component bundle; fetch is for client CSS only. ai
source-diff obfuscated-file:dist/lottery-tipping-page/index-de792262.js AI (source-diff): Stencil core runtime, minified not obfuscated. ai
source-diff net-exec-file:dist/lottery-tipping-page/app-tooltip_21.entry.js AI (source-diff): Benign fetch for styling, not malicious. ai
source-diff obfuscated-file:dist/lottery-tipping-page/app-tooltip_21.entry.js AI (source-diff): Minified bundle, matches other build targets. ai
source-diff net-exec-file:dist/esm/app-tooltip_21.entry.js AI (source-diff): Same benign fetch-for-styling pattern. ai
source-diff obfuscated-file:dist/esm/app-tooltip_21.entry.js AI (source-diff): Same bundled Stencil output as cjs variant. ai
source-diff net-exec-file:dist/cjs/app-tooltip_21.cjs.entry.js AI (source-diff): fetch used for client styling CSS, no dropper/exfil behavior. ai
source-diff obfuscated-file:dist/lottery-tipping-page/lottery-tipping-page-b611e76d.js AI (source-diff): Standard Stencil build output; minified but readable, no malicious patterns. Stable for this package family. ai
source-diff net-exec-file:dist/esm/general-multi-select_15.entry.js AI (source-diff): Same pattern as CJS variant; Stencil framework calls, not dropper behavior. ai
source-diff net-exec-file:dist/lottery-tipping-page/general-multi-select_15.entry.js AI (source-diff): Same Stencil component pattern; getAssetPath/setClientStyling are UI framework calls, not malware. ai
source-diff obfuscated-file:dist/lottery-tipping-page/general-multi-select_15.entry.js AI (source-diff): Third build target of the same Stencil component; minified but readable UI logic visible in sample. ai
source-diff obfuscated-file:dist/cjs/general-multi-select_15.cjs.entry.js AI (source-diff): Stencil.js minified build artifact; long lines are minified CSS strings and component logic, not obfuscation. ai
source-diff obfuscated-file:dist/esm/general-multi-select_15.entry.js AI (source-diff): Same Stencil ESM build artifact; minified CSS strings trigger long-line heuristic, not actual obfuscation. ai
source-diff net-exec-file:dist/cjs/general-multi-select_15.cjs.entry.js AI (source-diff): Network calls are styling/stream subscriptions; dynamic code execution is Stencil registerInstance — standard component framework pattern. ai
source-diff obfuscated-file:dist/lottery-tipping-page/lottery-tipping-page-92169e63.js AI (source-diff): Minified Stencil/Rollup build artifact; pattern is consistent across all versions of this package. ai
npm-metadata no-description AI (npm-metadata): Stable pattern across all versions of this everymatrix widget package. ai
provenance no-provenance AI (provenance): No provenance is consistent across this package's publishing history; low risk for an internal widget library. ai
bogus-package bogus-package AI (bogus-package): Scoped monorepo widget package; sparse metadata and empty entry point are consistent with 255-version CI publishing pattern. ai

Versions (showing 31 of 332)

Version Deps Published
1.80.0 0 / 0
1.77.32 0 / 0
1.77.31 0 / 0
1.77.30 0 / 0
1.77.29 0 / 0
1.77.28 0 / 0
1.77.27 0 / 0
1.77.26 0 / 0
1.77.25 0 / 0
1.77.24 0 / 0
1.77.23 0 / 0
1.77.22 0 / 0
1.77.21 0 / 0
1.77.20 0 / 0
1.77.19 0 / 0
1.77.18 0 / 0
1.77.17 0 / 0
1.77.16 0 / 0
1.77.15 0 / 0
1.77.14 0 / 0
1.77.13 0 / 0
1.77.12 0 / 0
1.77.11 0 / 0
1.77.10 0 / 0
1.77.9 0 / 0
1.77.8 0 / 0
1.77.7 0 / 0
1.77.6 0 / 0
1.77.5 0 / 0
1.77.4 0 / 0
1.77.3 0 / 0

v1.80.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.28

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.27

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.25

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.24

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.23

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.77.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.