← Home

@keplr-wallet/hooks

15
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

chainapsis

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Chainapsis monorepo migrated to GitHub Actions CI publishing with SLSA attestation; stable pattern going forward. ai
bogus-package bogus-package AI (bogus-package): Monorepo sub-package; missing description/repo/keywords is consistent across all keplr-wallet packages. ai
npm-metadata no-description AI (npm-metadata): Monorepo sub-package pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@ethersproject/address AI (phantom-deps): Likely used transitively or in type-only imports; stable false positive for this package. ai
semgrep semgrep:hex-decode AI (semgrep): Hex decode is standard ETH address normalization (0x-prefix strip + lowercase + hex decode → Bech32); not malicious. ai
phantom-deps phantom-dep:long AI (phantom-deps): Protobuf-related dep used via config; stable false positive for this package. ai
phantom-deps phantom-dep:@keplr-wallet/background AI (phantom-deps): Same-org monorepo dep; phantom detection is a false positive for this package. ai
phantom-deps phantom-dep:@keplr-wallet/crypto AI (phantom-deps): Same-org monorepo dep; phantom detection is a false positive for this package. ai

Versions (showing 15 of 115)

Version Deps Published
0.12.245 16 / 0
0.12.244 16 / 0
0.12.243 16 / 0
0.12.242 16 / 0
0.12.241 16 / 0
0.12.240 16 / 0
0.12.239 16 / 0
0.12.238 16 / 0
0.12.237 16 / 0
0.12.236 16 / 0
0.12.235 16 / 0
0.12.234 16 / 0
0.12.233 16 / 0
0.12.232 16 / 0
0.12.231 16 / 0

v0.12.245

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.244

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.243

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.242

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.241

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.240

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.239

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.238

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.237

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.236

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.235

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.234

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.233

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.232

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.12.231

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.