← Home

@metamask/gator-permissions-snap

Grants 7715 permissions from a DeleGator smart account

17
Versions
(MIT-0 OR Apache-2.0)
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

kumavisfrederikboldingmetamaskbotgudahttmrtenmcmirenaugtur

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/bundle.js AI (source-diff): mm-snap bundles legitimate hex/bytes utility code that triggers long-string heuristics; stable false positive for this package. ai
phantom-deps phantom-dep:@metamask/utils AI (phantom-deps): Same org scope; used transitively in snap bundle context. ai
phantom-deps phantom-dep:@metamask/abi-utils AI (phantom-deps): Same org scope; used transitively in snap bundle context. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Snap bundle; zod likely bundled at build time, not directly imported in source. ai
phantom-deps phantom-dep:@metamask/delegation-core AI (phantom-deps): Same org scope; used transitively in snap bundle context. ai
phantom-deps phantom-dep:@metamask/profile-sync-controller AI (phantom-deps): Same org scope; used transitively in snap bundle context. ai
phantom-deps phantom-dep:@metamask/snaps-sdk AI (phantom-deps): Same org scope; used transitively in snap bundle context. ai

Versions (showing 17 of 17)

Version Deps Published
2.4.0 7 / 27
2.3.0 7 / 27
2.2.0 6 / 27
2.1.0 6 / 27
2.0.0 6 / 27
1.3.1 6 / 27
1.3.0 6 / 27
1.2.0 6 / 27
1.1.1 6 / 27
1.1.0 6 / 27
1.0.0 6 / 25
0.9.0 6 / 25
0.8.0 6 / 25
0.7.0 6 / 25
0.6.1 6 / 25
0.6.0 6 / 25
0.5.0 6 / 25

v2.4.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: metamaskbot → GitHub Actions (on 2026-07-15, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (metamaskbot) on 2026-07-15, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.