← Home

@maticnetwork/maticjs

Javascript developer library for interacting with Matic Network

9
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

devops-polygon.technologyjminfantepolygonmaximushaximusmtwardzickiagupta1411py-zoid

Keywords

ethereumweb3ethersmatic

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/matic.js AI (source-diff): Encoded string is base64 alphabet in BN.js/webpack bundle; stable false positive for this package. ai
phantom-deps phantom-dep:buffer AI (phantom-deps): Polyfill for Web3 library; stable pattern for this package. ai
phantom-deps phantom-dep:@ethereumjs/trie AI (phantom-deps): Transitive ethereumjs dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@ethereumjs/util AI (phantom-deps): Transitive ethereumjs dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@ethereumjs/block AI (phantom-deps): Transitive ethereumjs dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@ethereumjs/common AI (phantom-deps): Direct dependency for Ethereum chain config; stable pattern for this package. ai
phantom-deps phantom-dep:rlp AI (phantom-deps): Transitive ethereumjs dependency; stable pattern for this package. ai
phantom-deps phantom-dep:bn.js AI (phantom-deps): Transitive ethereumjs dependency; stable pattern for this package. ai
phantom-deps phantom-dep:node-fetch AI (phantom-deps): Transitive dependency; stable pattern for this package. ai
phantom-deps phantom-dep:safe-buffer AI (phantom-deps): Polyfill for browser compatibility; stable pattern in this package. ai
phantom-deps phantom-dep:ethereum-cryptography AI (phantom-deps): Transitive dependency of @ethereumjs packages; used indirectly. ai
phantom-deps phantom-dep:assert AI (phantom-deps): Polyfill for browser compatibility; stable pattern in this package. ai
phantom-deps phantom-dep:stream AI (phantom-deps): Polyfill for browser compatibility; stable pattern in this package. ai

Versions (showing 9 of 9)

Version Deps Published
3.9.11 12 / 9
3.9.10 12 / 9
3.9.9 12 / 9
3.9.8 12 / 9
3.9.7 10 / 12
3.9.6 10 / 12
3.9.5 10 / 12
3.9.4 10 / 12
3.9.3 10 / 12

v3.9.10

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.9.8

2 findings
HIGH Long encoded string in modified file: dist/matic.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.9.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.9.6

2 findings
HIGH Long encoded string in modified file: dist/matic.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.9.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.9.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v3.9.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.