← Home

@reown/appkit-wallet

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cyberdrkreown-npm-org

Keywords

appkitwalletonboardingreowndappsweb3wagmiethereumsolanabitcoin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Legitimate org consolidation to reown-npm-org; established publisher with clean track record. ai
maintainer-change maintainer-added AI (maintainer-change): reown-npm-org is the official org account for the appkit monorepo. ai
maintainer-change maintainer-removed AI (maintainer-change): Individual devs replaced by org account during transfer; benign. ai
license uncommon-license:SEE LICENSE IN LICENSE.md AI (license): This is a standard SPDX expression used by projects with custom license files; consistent across all Reown AppKit packages and not a security concern. ai

Versions (showing 51 of 81)

View all versions
Version Deps Published
1.8.23 4 / 3
1.8.22 4 / 3
1.8.21 4 / 3
1.8.20 4 / 3
1.8.19 4 / 3
1.8.18 4 / 3
1.8.17 4 / 3
1.8.16 4 / 3
1.8.15 4 / 3
1.8.14 4 / 3
1.8.13 4 / 3
1.8.12 4 / 3
1.8.11 4 / 3
1.8.10 4 / 3
1.8.9 4 / 3
1.8.8 4 / 3
1.8.7 4 / 3
1.8.6 4 / 3
1.8.5 4 / 3
1.8.4 4 / 3
1.8.3 4 / 3
1.8.2 4 / 3
1.8.1 4 / 3
1.8.0 4 / 3
1.7.20 4 / 3
1.7.19 4 / 3
1.7.18 4 / 3
1.7.17 4 / 3
1.7.16 4 / 3
1.7.15 4 / 3
1.7.14 4 / 3
1.7.13 4 / 3
1.7.12 4 / 3
1.7.11 4 / 3
1.7.10 4 / 3
1.7.9 4 / 3
1.7.8 4 / 3
1.7.7 4 / 3
1.7.6 4 / 3
1.7.5 4 / 3
1.7.4 4 / 3
1.7.3 4 / 3
1.7.2 4 / 3
1.7.1 4 / 3
1.7.0 4 / 3
1.6.9 4 / 3
1.6.8 4 / 3
1.6.7 4 / 3
1.6.6 4 / 3
1.6.5 4 / 3
1.6.4 4 / 3

v1.8.23

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.3

2 findings
HIGH Publisher changed: rocky-wc → reown-npm-org (on 2025-04-15) provenance

This version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.