← Home

@reown/appkit-adapter-bitcoin

54
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cyberdrkreown-npm-org

Keywords

appkitwalletonboardingreowndappsweb3wagmiethereumsolanabitcoin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Org-wide publisher migration to reown-npm-org, stable across the package family. ai
provenance publisher-changed-stale AI (provenance): Long-stable publisher change inconsistent with takeover; already flagged by analyzer as such. ai
phantom-deps phantom-dep:bitcoinjs-lib AI (phantom-deps): bitcoinjs-lib is used via type/config references, common false positive in this monorepo. ai

Versions (showing 54 of 54)

Version Deps Published
1.8.23 11 / 5
1.8.22 11 / 5
1.8.21 11 / 5
1.8.20 11 / 5
1.8.19 11 / 5
1.8.18 11 / 5
1.8.17 11 / 5
1.8.16 11 / 5
1.8.15 11 / 5
1.8.14 11 / 5
1.8.13 11 / 5
1.8.12 11 / 5
1.8.11 11 / 5
1.8.10 11 / 5
1.8.9 11 / 5
1.8.8 11 / 5
1.8.7 11 / 5
1.8.6 11 / 5
1.8.5 11 / 5
1.8.4 11 / 5
1.8.3 11 / 5
1.8.2 11 / 5
1.8.1 11 / 5
1.8.0 11 / 5
1.7.20 11 / 5
1.7.19 11 / 5
1.7.18 11 / 5
1.7.17 11 / 5
1.7.16 11 / 5
1.7.15 11 / 5
1.7.14 11 / 5
1.7.13 11 / 5
1.7.12 11 / 5
1.7.11 11 / 5
1.7.10 11 / 5
1.7.9 11 / 5
1.7.8 11 / 5
1.7.7 11 / 5
1.7.6 11 / 5
1.7.5 11 / 5
1.7.4 11 / 5
1.7.3 11 / 5
1.7.2 10 / 5
1.7.1 10 / 5
1.7.0 10 / 5
1.6.9 10 / 5
1.6.8 9 / 5
1.6.7 9 / 5
1.6.6 9 / 5
1.6.5 9 / 5
1.6.4 9 / 5
1.6.3 9 / 5
1.6.2 9 / 5
1.6.1 9 / 5

v1.8.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.3

2 findings
MEDIUM Publisher changed: rocky-wc → reown-npm-org (on 2025-04-15, unremoved on npm for 458d) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (rocky-wc) on 2025-04-15. It has since remained available on npm for 458 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.