← Home

@lifi/wallet-management

LI.FI Wallet Management solution.

94
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

lifi

Keywords

walletwallet-managementmetamaskwallet-connectcoinbaseeip1193ethereumENSweb3blockchainlifitron

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA provenance; consistent with org-level CI/CD adoption. ai
phantom-deps phantom-dep:@mui/system AI (phantom-deps): MUI system is a peer/config-level dep in a UI library; not directly imported but legitimately declared. ai
dependencies unvetted-dep:porto AI (dependencies): porto is a legitimate Paradigm/Wevm EIP-7702 wallet library; consistent with this package's existing viem dependency. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): Declared as a runtime dep for MUI/emotion theming; not directly imported but legitimately required. ai
phantom-deps phantom-dep:use-sync-external-store AI (phantom-deps): Declared as a runtime dep for zustand/React compatibility; stable false positive for this package. ai

Versions (showing 94 of 94)

Version Deps Published
4.1.2 11 / 0
4.1.1 11 / 0
4.1.0 11 / 0
4.0.0 11 / 0
3.22.8 17 / 0
3.22.7 17 / 0
3.22.6 17 / 0
3.22.5 17 / 0
3.22.4 17 / 0
3.22.3 17 / 0
3.22.2 17 / 0
3.22.1 17 / 0
3.22.0 17 / 0
3.21.0 17 / 0
3.20.1 17 / 0
3.20.0 17 / 0
3.19.3 17 / 0
3.19.2 17 / 0
3.19.1 17 / 0
3.19.0 17 / 0
3.18.1 17 / 0
3.18.0 17 / 0
3.17.3 17 / 0
3.17.2 17 / 0
3.17.1 18 / 0
3.17.0 18 / 0
3.16.7 17 / 0
3.16.6 17 / 0
3.16.5 17 / 0
3.16.4 17 / 0
3.16.3 17 / 0
3.16.2 17 / 0
3.16.1 17 / 0
3.16.0 17 / 0
3.15.1 17 / 0
3.15.0 17 / 0
3.14.7 17 / 0
3.14.6 17 / 0
3.14.5 17 / 0
3.14.4 17 / 0
3.14.3 17 / 0
3.14.2 17 / 0
3.14.1 17 / 0
3.14.0 17 / 0
3.13.0 17 / 0
3.12.1 17 / 0
3.12.0 17 / 0
3.11.1 17 / 0
3.11.0 17 / 0
3.10.0 17 / 0
3.9.2 17 / 0
3.9.1 17 / 0
3.9.0 17 / 0
3.8.2 16 / 0
3.8.1 16 / 0
3.8.0 16 / 0
3.7.6 16 / 0
3.7.5 16 / 0
3.7.4 16 / 0
3.7.3 16 / 0
3.7.2 16 / 0
3.7.1 17 / 0
3.7.0 17 / 0
3.6.2 17 / 0
3.6.1 17 / 0
3.6.0 17 / 0
3.5.2 18 / 0
3.5.1 19 / 0
3.5.0 19 / 0
3.4.7 22 / 0
3.4.6 22 / 0
3.4.5 22 / 0
3.4.4 22 / 0
3.4.3 22 / 0
3.4.2 22 / 0
3.4.1 22 / 0
3.4.0 22 / 0
3.3.1 22 / 0
3.3.0 24 / 0
3.1.7 5 / 0
3.1.6 5 / 0
3.1.5 5 / 0
3.1.4 5 / 0
3.1.3 5 / 0
3.1.2 5 / 0
3.1.1 5 / 0
3.1.0 5 / 0
3.0.6 5 / 0
3.0.5 5 / 0
3.0.4 5 / 0
3.0.3 5 / 0
3.0.2 5 / 0
3.0.1 5 / 0
3.0.0 5 / 0

v4.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.