@metamask/sdk-install-modal-web
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/cjs/mm-install-modal_3.cjs.entry.js | AI (source-diff): Stencil-compiled bundle output; long lines are minified SVG/component code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/sdk-install-modal-web/p-8da49516.entry.js | AI (source-diff): Stencil minified entry bundle; benign. | ai | |
| source-diff | obfuscated-file:dist/esm/mm-install-modal_3.entry.js | AI (source-diff): Stencil ESM bundle output; benign minification. | ai | |
| phantom-deps | phantom-dep:qr-code-styling | AI (phantom-deps): Used in bundled webpack build; not scannable via static import. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Used in bundled webpack build; not scannable via static import. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): Used in bundled webpack build; not scannable via static import. | ai | |
| source-diff | obfuscated-file:dist/sdk-install-modal-web/p-031fdccc.entry.js | AI (source-diff): Stencil lazy-load bundle output. | ai | |
| source-diff | obfuscated-file:dist/sdk-install-modal-web/p-3b4412f2.js | AI (source-diff): Stencil lazy-load bundle output. | ai | |
| source-diff | obfuscated-file:dist/sdk-install-modal-web/p-4739b8e2.js | AI (source-diff): Stencil lazy-load bundle output. | ai | |
| source-diff | obfuscated-file:dist/sdk-install-modal-web/p-9ed177f3.js | AI (source-diff): Stencil lazy-load bundle output. | ai | |
| source-diff | obfuscated-file:dist/sdk-install-modal-web/p-c91b6be2.entry.js | AI (source-diff): Stencil lazy-load bundle output. | ai | |
| source-diff | obfuscated-file:dist/esm/mm-select-modal.entry.js | AI (source-diff): Stencil ESM build output. | ai | |
| source-diff | obfuscated-file:dist/cjs/mm-pending-modal.cjs.entry.js | AI (source-diff): Stencil build output with inline CSS/SVG. | ai | |
| source-diff | obfuscated-file:dist/cjs/mm-select-modal.cjs.entry.js | AI (source-diff): Stencil build output, SVG paths. | ai | |
| source-diff | obfuscated-file:dist/collection/components/misc/Logo.js | AI (source-diff): SVG logo component, long path data. | ai | |
| source-diff | obfuscated-file:dist/collection/components/misc/MetamaskExtensionImage.js | AI (source-diff): SVG image component, long path data. | ai | |
| source-diff | obfuscated-file:dist/esm/mm-pending-modal.entry.js | AI (source-diff): Stencil ESM build output. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Stencil dist regeneration produces many entry files; expected. | ai | |
| source-diff | obfuscated-file:dist/esm/mm-install-modal.entry.js | AI (source-diff): Stencil build output; readable JSX/SVG, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/mm-install-modal.cjs.entry.js | AI (source-diff): Stencil build output; readable JSX/SVG, not obfuscation. | ai | |
| source-diff | net-exec-file:dist/esm/polyfills/core-js.js | AI (source-diff): core-js polyfill feature-detection, not a dropper; stable build artifact. | ai | |
| source-diff | obfuscated-file:dist/esm/polyfills/core-js.js | AI (source-diff): Minified core-js polyfill from Stencil build; benign for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Stencil web component package; empty main and sparse README are expected for this build artifact pattern. | ai |
Versions (showing 24 of 24)
| Version | Deps | Published |
|---|---|---|
| 0.32.1 | 1 / 25 | |
| 0.32.0 | 1 / 25 | |
| 0.31.5 | 1 / 25 | |
| 0.31.2 | 1 / 25 | |
| 0.31.1 | 1 / 25 | |
| 0.31.0 | 1 / 25 | |
| 0.30.2 | 1 / 35 | |
| 0.30.0 | 1 / 35 | |
| 0.29.2 | 1 / 35 | |
| 0.29.1 | 1 / 35 | |
| 0.28.1 | 1 / 35 | |
| 0.26.5 | 1 / 35 | |
| 0.26.4 | 1 / 35 | |
| 0.26.0 | 1 / 36 | |
| 0.20.4 | 1 / 36 | |
| 0.20.2 | 1 / 36 | |
| 0.18.5 | 1 / 36 | |
| 0.17.0 | 1 / 36 | |
| 0.16.0 | 1 / 36 | |
| 0.15.0 | 7 / 27 | |
| 0.6.0 | 5 / 24 | |
| 0.2.1 | 4 / 22 | |
| 0.2.0 | 4 / 22 | |
| 0.1.0 | 2 / 22 |
v0.32.0
7 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.5
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.2
15 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.1
14 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.31.0
18 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.30.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.29.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.28.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.20.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.20.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.18.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.