@metamask/multichain-api-middleware
JSON-RPC methods and middleware to support the MetaMask Multichain API
12
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
gitHead linked
Maintainers
kumavisfrederikboldingmetamaskbotgudahttmrtenmcmirenaugtur
Keywords
EthereumMetaMask
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Migration from metamaskbot to GitHub Actions CI; consistent with MetaMask org's CI/CD practices. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Known MetaMask contributors added as maintainers on official @metamask scoped package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): MetaMask core monorepo; release cadence gaps are normal for this package family. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): MetaMask org manages maintainers centrally via metamaskbot; individual removal is routine org hygiene. | ai | |
| provenance | no-provenance | AI (provenance): MetaMask monorepo packages consistently publish without Sigstore provenance; not a risk signal for this publisher. | ai | |
| phantom-deps | phantom-dep:@open-rpc/meta-schema | AI (phantom-deps): Declared as runtime dep and used in config/schema validation; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 4.0.0 | 13 / 12 | |
| 3.1.5 | 13 / 12 | |
| 3.1.4 | 13 / 12 | |
| 3.1.3 | 13 / 12 | |
| 3.1.2 | 13 / 12 | |
| 3.1.1 | 13 / 12 | |
| 3.1.0 | 13 / 12 | |
| 3.0.0 | 13 / 12 | |
| 2.0.0 | 11 / 12 | |
| 1.2.7 | 11 / 12 | |
| 1.2.6 | 11 / 12 | |
| 1.2.5 | 11 / 12 |
v4.0.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v3.1.5
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.