← Home

@metamask/bitcoin-wallet-snap

A Bitcoin wallet Snap.

20
Versions
(MIT-0 OR Apache-2.0)
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

kumavisfrederikboldingmetamaskbotgudahttmrtenmcmirenaugtur

Keywords

EthereumMetaMask

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition from metamaskbot to GitHub Actions CI with SLSA provenance; legitimate CI migration. ai
license uncommon-license:MIT-0 AI (license): MIT-0 is a recognized permissive license used by this package. ai
source-diff encoded-string-file:dist/bundle.js AI (source-diff): Webpack bundle with standard crypto utils; expected for a Snap package. ai
maintainer-change maintainer-removed AI (maintainer-change): MetaMask org maintainer rotation; publisher metamaskbot is the canonical bot account. ai

Versions (showing 20 of 20)

Version Deps Published
1.15.2 0 / 23
1.15.1 0 / 23
1.15.0 0 / 21
1.14.2 0 / 21
1.14.1 0 / 21
1.14.0 0 / 21
1.13.0 0 / 21
1.12.0 0 / 21
1.11.0 0 / 21
1.10.1 0 / 21
1.10.0 0 / 20
1.9.0 0 / 20
1.8.0 0 / 20
1.7.0 0 / 20
1.6.0 0 / 20
1.5.0 0 / 20
1.4.5 0 / 20
1.4.4 0 / 20
1.4.3 0 / 20
1.4.2 0 / 20

v1.15.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.15.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.14.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.