← Home

@permaweb/aoconnect

19
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

nickj_arweavepermatom

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@dha-team/arbundles AI (dependencies): Legit Arweave bundling lib replacing warp-arbundles, matches package's stated function. ai
source-diff encoded-string-file:dist/browser.js AI (source-diff): Bundled/minified esbuild output, not obfuscation; stable across releases. ai
source-diff source-size-tripled AI (source-diff): Size increase from added dep + bundler polyfills, not injected payload. ai
phantom-deps phantom-dep:buffer AI (phantom-deps): Used via bundler polyfill config, stable false positive. ai
phantom-deps phantom-dep:axios AI (phantom-deps): axios is a declared runtime dep used transitively; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:mnemonist AI (phantom-deps): mnemonist is a declared runtime dep; phantom-dep heuristic fires on bundled dist output, not a real missing import. ai
phantom-deps phantom-dep:hyper-async AI (phantom-deps): hyper-async is a declared runtime dep; same bundled-dist false-positive pattern. ai

Versions (showing 19 of 19)

Version Deps Published
0.0.95 14 / 4
0.0.86 13 / 4
0.0.72 13 / 4
0.0.69 11 / 4
0.0.68 10 / 4
0.0.67 10 / 4
0.0.66 10 / 4
0.0.65 10 / 4
0.0.64 10 / 4
0.0.63 9 / 3
0.0.62 9 / 3
0.0.61 9 / 3
0.0.60 9 / 3
0.0.59 8 / 3
0.0.58 8 / 3
0.0.57 8 / 3
0.0.56 8 / 3
0.0.55 8 / 3
0.0.54 8 / 3

v0.0.86

2 findings
HIGH Long encoded string in modified file: dist/browser.js source-diff

Modified file contains 29 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.72

2 findings
HIGH Long encoded string in modified file: dist/browser.js source-diff

Modified file contains 22 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.69

2 findings
HIGH Long encoded string in modified file: dist/browser.js source-diff

Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.67

2 findings
HIGH Long encoded string in modified file: dist/browser.js source-diff

Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.66

2 findings
HIGH Long encoded string in modified file: dist/browser.js source-diff

Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.65

2 findings
HIGH Long encoded string in modified file: dist/browser.js source-diff

Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.64

2 findings
HIGH Long encoded string in modified file: dist/browser.js source-diff

Modified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.63

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.62

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.60

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.59

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.