@metamask/test-dapp-tron
A test dapp for tron
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/assets/SwapController-CqMtTatH.js | AI (source-diff): Standard Vite minified build output for a test dapp; samples show legitimate swap UI logic. | ai | |
| source-diff | obfuscated-file:dist/assets/copy-Bf0HAal6.js | AI (source-diff): Vite-minified SVG icon component; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/assets/dollar-CJ0ov18I.js | AI (source-diff): Vite-minified SVG icon component; no malicious content. | ai | |
| source-diff | obfuscated-file:dist/assets/embedded-wallet-K18HaM1v.js | AI (source-diff): Vite-minified wallet UI component; samples show standard web component patterns. | ai | |
| source-diff | obfuscated-file:dist/assets/features-D6f1jFLM.js | AI (source-diff): Vite-minified SIWE/auth feature code; no malicious content. | ai | |
| phantom-deps | phantom-dep:vite-plugin-node-polyfills | AI (phantom-deps): Vite plugin referenced in vite.config; config-file reference, not a missing import. | ai | |
| phantom-deps | phantom-dep:@tronweb3/tronwallet-adapters | AI (phantom-deps): Tron wallet adapter; config-file reference pattern, stable false positive for this dapp. | ai | |
| phantom-deps | phantom-dep:react | AI (phantom-deps): React is a frontend dep referenced in vite/tsconfig; phantom-dep heuristic false positive for this dapp package. | ai | |
| phantom-deps | phantom-dep:@tronweb3/tronwallet-adapter-react-hooks | AI (phantom-deps): Tron wallet adapter hooks; config-file reference pattern, stable false positive. | ai | |
| phantom-deps | phantom-dep:@tronweb3/tronwallet-adapter-react-ui | AI (phantom-deps): Tron wallet adapter UI; config-file reference pattern, stable false positive. | ai | |
| phantom-deps | phantom-dep:react-dom | AI (phantom-deps): Same as react — frontend dapp bundle, config-file reference only. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Node polyfill for browser bundle; referenced in vite config, not a missing import. | ai | |
| phantom-deps | phantom-dep:tronweb | AI (phantom-deps): Tron SDK used in dapp; config-file reference pattern, stable false positive. | ai | |
| phantom-deps | phantom-dep:@metamask/connect-tron | AI (phantom-deps): Same-org dep; phantom-dep heuristic false positive. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 0.4.0 | 0 / 26 | |
| 0.3.1 | 0 / 26 | |
| 0.3.0 | 9 / 17 | |
| 0.2.2 | 9 / 17 | |
| 0.2.0 | 9 / 17 | |
| 0.1.0 | 8 / 17 |
v0.4.0
6 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.