← Home

@keplr-wallet/hooks-starknet

15
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

chainapsis

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from chainapsis account to GitHub Actions CI/CD with SLSA attestation; consistent repo URL and monorepo pattern. ai
phantom-deps phantom-dep:long AI (phantom-deps): Transitive/config-referenced dep in monorepo; stable false positive for this package. ai
phantom-deps phantom-dep:utility-types AI (phantom-deps): TypeScript utility types used in type declarations, not direct imports; stable false positive. ai
phantom-deps phantom-dep:@ethersproject/address AI (phantom-deps): Referenced in config/type context in monorepo; stable false positive. ai
phantom-deps phantom-dep:@ethersproject/providers AI (phantom-deps): Referenced in config/type context in monorepo; stable false positive. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decode is used for Starknet address validation (strip 0x, check 32-byte length); not a malicious payload pattern. ai
phantom-deps phantom-dep:@keplr-wallet/proto-types AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for monorepo peer/type usage. ai
phantom-deps phantom-dep:@keplr-wallet/background AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for monorepo peer/type usage. ai
phantom-deps phantom-dep:@keplr-wallet/stores-etc AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for monorepo peer/type usage. ai
phantom-deps phantom-dep:@keplr-wallet/stores-eth AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for monorepo peer/type usage. ai
phantom-deps phantom-dep:@keplr-wallet/crypto AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for monorepo peer/type usage. ai

Versions (showing 15 of 215)

Version Deps Published
0.12.148 17 / 0
0.12.147 17 / 0
0.12.146 17 / 0
0.12.145 17 / 0
0.12.144 17 / 0
0.12.143 17 / 0
0.12.142 17 / 0
0.12.141 17 / 0
0.12.140 17 / 0
0.12.139 17 / 0
0.12.138 17 / 0
0.12.137 17 / 0
0.12.136 17 / 0
0.12.135 17 / 0
0.12.133 17 / 0

v0.12.148

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.147

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.146

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.145

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.144

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.143

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.142

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.141

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.140

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.139

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.138

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.137

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.136

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.135

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.133

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.