← Home

@metamask/snap-simple-keyring-site

A snap simple keyring dapp used in MetaMask e2e tests.

1
Versions
(MIT-0 OR Apache-2.0)
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

danfinlaykumavismetamaskbot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:new-function-constructor AI (semgrep): Fires inside webpack-runtime bundle; standard webpack pattern, not attacker-controlled input. ai
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Fires inside partytown worker script; Reflect.get is idiomatic proxy pattern in partytown, not obfuscation. ai
phantom-deps phantom-dep:react AI (phantom-deps): Declared dep bundled by Gatsby into public/; phantom-dep heuristic doesn't handle build-time bundling. ai
phantom-deps phantom-dep:semver AI (phantom-deps): Declared dep used transitively in Gatsby build; false positive for bundled site packages. ai
phantom-deps phantom-dep:webpack AI (phantom-deps): Declared dep used by Gatsby build pipeline; false positive. ai
phantom-deps phantom-dep:react-is AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:react-icons AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:react-helmet AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:@mui/material AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:@emotion/react AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:@emotion/styled AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:crypto-browserify AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:styled-components AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:@metamask/providers AI (phantom-deps): Same-org dep bundled into the dapp; false positive. ai
phantom-deps phantom-dep:@mui/icons-material AI (phantom-deps): Declared dep bundled by Gatsby; false positive. ai
phantom-deps phantom-dep:@types/react-helmet AI (phantom-deps): Type-only dep used at build time; false positive. ai
phantom-deps phantom-dep:@metamask/keyring-api AI (phantom-deps): Same-org dep bundled into the dapp; false positive. ai

Versions (showing 1 of 1)

Version Deps Published
2.0.0 16 / 29

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.