@permaweb/aoconnect
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@dha-team/arbundles | AI (dependencies): Legit Arweave bundling lib replacing warp-arbundles, matches package's stated function. | ai | |
| source-diff | encoded-string-file:dist/browser.js | AI (source-diff): Bundled/minified esbuild output, not obfuscation; stable across releases. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase from added dep + bundler polyfills, not injected payload. | ai | |
| phantom-deps | phantom-dep:buffer | AI (phantom-deps): Used via bundler polyfill config, stable false positive. | ai | |
| phantom-deps | phantom-dep:axios | AI (phantom-deps): axios is a declared runtime dep used transitively; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:mnemonist | AI (phantom-deps): mnemonist is a declared runtime dep; phantom-dep heuristic fires on bundled dist output, not a real missing import. | ai | |
| phantom-deps | phantom-dep:hyper-async | AI (phantom-deps): hyper-async is a declared runtime dep; same bundled-dist false-positive pattern. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 0.0.95 | 14 / 4 | |
| 0.0.86 | 13 / 4 | |
| 0.0.72 | 13 / 4 | |
| 0.0.69 | 11 / 4 | |
| 0.0.68 | 10 / 4 | |
| 0.0.67 | 10 / 4 | |
| 0.0.66 | 10 / 4 | |
| 0.0.65 | 10 / 4 | |
| 0.0.64 | 10 / 4 | |
| 0.0.63 | 9 / 3 | |
| 0.0.62 | 9 / 3 | |
| 0.0.61 | 9 / 3 | |
| 0.0.60 | 9 / 3 | |
| 0.0.59 | 8 / 3 | |
| 0.0.58 | 8 / 3 | |
| 0.0.57 | 8 / 3 | |
| 0.0.56 | 8 / 3 | |
| 0.0.55 | 8 / 3 | |
| 0.0.54 | 8 / 3 |
v0.0.86
2 findingsModified file contains 29 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.72
2 findingsModified file contains 22 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.69
2 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.67
2 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.66
2 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.65
2 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.64
2 findingsModified file contains 21 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.63
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.62
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.61
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.60
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.59
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.58
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.57
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.55
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.54
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.