@everymatrix/player-account-self-exclusion-nd
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-Etoj2zHF.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte bundle; consistent with package's build pattern across 458 versions. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-CwKFn-hz.js | AI (source-diff): dayjs IIFE + UI fetch calls; no dropper pattern in samples. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-CwKFn-hz.js | AI (source-diff): Standard Rollup/Vite minified Svelte bundle. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-C55APf7j.js | AI (source-diff): dayjs IIFE + UI fetch calls; no dropper pattern in samples. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-C55APf7j.js | AI (source-diff): Standard Rollup/Vite minified Svelte bundle. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-CysDvEVs.js | AI (source-diff): Standard Rollup/Vite minified Svelte bundle. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-BhWXlUGl.js | AI (source-diff): Standard Rollup/Vite minified Svelte bundle. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-CpvCou0X.cjs | AI (source-diff): dayjs IIFE + UI fetch calls; no dropper pattern in samples. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-CpvCou0X.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte bundle. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountModal-B4RimlKX.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte bundle. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-B2WMzy8n.js | AI (source-diff): Standard Svelte/Stencil minified build output; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-CxOHrccG.js | AI (source-diff): Standard Svelte/Stencil minified build output; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-D6pHeviu.js | AI (source-diff): Standard Svelte/Stencil minified build output; not obfuscated malware. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-B2WMzy8n.js | AI (source-diff): Network calls and dynamic execution are part of Svelte runtime and Vaadin dev-mode detector, not dropper behavior. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-CwhjKirR.js | AI (source-diff): Standard Svelte/Stencil minified build output; not obfuscated malware. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-CwhjKirR.js | AI (source-diff): Network calls and dynamic execution are part of Svelte runtime and Vaadin dev-mode detector, not dropper behavior. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-BKUjf33f.js | AI (source-diff): Standard Vite minified Svelte ESM bundle; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-CZORI_Y2.js | AI (source-diff): Standard Vite minified Svelte ESM bundle; consistent with this package's build pattern. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountSelfExclusionNd-C4c5dNKZ.cjs | AI (source-diff): Standard Rollup/Vite minified Svelte bundle; consistent with prior versions of this package. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-BKUjf33f.js | AI (source-diff): Same pattern as CJS counterpart; Svelte runtime + API calls in a UI widget. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-C4c5dNKZ.cjs | AI (source-diff): Network calls are API fetches in a UI component; dynamic execution is Svelte runtime + vaadin dev-mode detector, not dropper behavior. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-Bjxp-nSE.js | AI (source-diff): Minified Svelte component ESM bundle; no malicious indicators in sample. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-B-omrzpl.js | AI (source-diff): Minified Svelte component ESM bundle; no malicious indicators in sample. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountModal-BgHeCL8Q.cjs | AI (source-diff): Minified Svelte modal component CJS bundle; no malicious indicators in sample. | ai | |
| source-diff | net-exec-file:components/PlayerAccountSelfExclusionNd-CZORI_Y2.js | AI (source-diff): Same pattern as other ESM bundles; Svelte runtime + API calls in a UI widget. | ai | |
| source-diff | obfuscated-file:components/PlayerAccountGeneralConfirmationModal-DRcat6O7.cjs | AI (source-diff): Minified Svelte component CJS bundle; no malicious indicators in sample. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped UI component bundle; missing metadata is typical for internal/private org packages published publicly. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): Fires inside vaadin-development-mode-detector, a known third-party utility; stable false positive for this package. | ai |
Versions (showing 54 of 354)
| Version | Deps | Published |
|---|---|---|
| 1.54.12 | 0 / 0 | |
| 1.54.11 | 0 / 0 | |
| 1.54.10 | 0 / 0 | |
| 1.54.9 | 0 / 0 | |
| 1.54.8 | 0 / 0 | |
| 1.54.7 | 0 / 0 | |
| 1.54.6 | 0 / 0 | |
| 1.54.5 | 0 / 0 | |
| 1.54.4 | 0 / 0 | |
| 1.54.2 | 0 / 0 | |
| 1.54.0 | 0 / 0 | |
| 1.53.12 | 0 / 0 | |
| 1.53.11 | 0 / 0 | |
| 1.53.10 | 0 / 0 | |
| 1.53.0 | 0 / 0 | |
| 1.52.6 | 0 / 0 | |
| 1.52.5 | 0 / 0 | |
| 1.52.4 | 0 / 0 | |
| 1.52.3 | 0 / 0 | |
| 1.52.2 | 0 / 0 | |
| 1.52.1 | 0 / 0 | |
| 1.52.0 | 0 / 0 | |
| 1.51.0 | 0 / 0 | |
| 1.50.1 | 0 / 0 | |
| 1.50.0 | 0 / 0 | |
| 1.49.2 | 0 / 0 | |
| 1.49.1 | 0 / 0 | |
| 1.49.0 | 0 / 0 | |
| 1.48.2 | 0 / 0 | |
| 1.48.1 | 0 / 0 | |
| 1.48.0 | 0 / 0 | |
| 1.47.3 | 0 / 0 | |
| 1.47.2 | 0 / 0 | |
| 1.47.1 | 0 / 0 | |
| 1.47.0 | 0 / 0 | |
| 1.46.1 | 0 / 0 | |
| 1.46.0 | 0 / 0 | |
| 1.45.14 | 0 / 0 | |
| 1.45.13 | 0 / 0 | |
| 1.45.11 | 0 / 0 | |
| 1.45.10 | 0 / 0 | |
| 1.45.9 | 0 / 0 | |
| 1.45.8 | 0 / 0 | |
| 1.45.7 | 0 / 0 | |
| 1.45.6 | 0 / 0 | |
| 1.45.5 | 0 / 0 | |
| 1.45.4 | 0 / 0 | |
| 1.45.3 | 0 / 0 | |
| 1.45.2 | 0 / 0 | |
| 1.45.0 | 0 / 0 | |
| 1.0.72 | 0 / 0 | |
| 1.0.71 | 0 / 0 | |
| 1.0.70 | 0 / 0 | |
| 1.0.69 | 0 / 0 |
v1.54.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.51.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.72
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.71
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.70
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.69
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.