@metamask/smart-accounts-kit
Toolkit for managing and interacting with MetaMask Smart Accounts, built on Viem
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Known MetaMask org maintainers; provenance attests CI/CD publish, not compromise. | ai | |
| source-diff | bulk-obfuscated-files:dist | AI (source-diff): tsup build output/type declarations, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-DUJmm8Wz.d.ts | AI (source-diff): TypeScript declaration file with long lines from bundled type signatures; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-X7Qn3JTg.d.cts | AI (source-diff): TypeScript declaration file (.d.cts) with long lines from bundled type signatures; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-DfDAuvr5.d.cts | AI (source-diff): TypeScript declaration file with long lines from bundled type exports; standard tsup build artifact for this package. | ai | |
| source-diff | obfuscated-file:dist/index-G78z6nwi.d.ts | AI (source-diff): TypeScript declaration file with long lines from bundled type exports; standard tsup build artifact for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are dist artifacts (sourcemaps, declaration files) consistent with build output growth for this package. | ai | |
| source-diff | obfuscated-file:dist/index-BToRQKyJ.d.cts | AI (source-diff): TypeScript declaration file with long lines from bundled type unions; not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-Cg-JakqA.d.ts | AI (source-diff): TypeScript declaration file with long lines from bundled type unions; not obfuscated code. | ai | |
| dependencies | unvetted-dep:ox | AI (dependencies): ox is a well-known Ethereum utility library from the Viem/Wevm ecosystem; appropriate dependency for this MetaMask smart accounts toolkit. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): buffer is declared in dependencies and referenced in lavamoat allowScripts config; stable false positive for this package. | ai | |
| license | uncommon-license:MIT-0 | AI (license): MIT-0 OR Apache-2.0 is a permissive dual-license; stable for this MetaMask package. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 1.7.0 | 7 / 29 | |
| 1.6.0 | 7 / 29 | |
| 1.5.0 | 6 / 29 | |
| 1.4.0 | 6 / 29 | |
| 1.3.0 | 6 / 29 | |
| 1.2.0 | 6 / 29 | |
| 1.1.0 | 6 / 28 | |
| 1.0.0 | 6 / 28 | |
| 0.3.0 | 6 / 23 | |
| 0.2.0 | 6 / 23 | |
| 0.1.0 | 6 / 23 |
v1.7.0
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (metamaskbot) on 2026-07-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.