← Home

@reown/appkit

70
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

cyberdrkreown-npm-org

Keywords

appkitwalletonboardingreowndappsweb3wagmiethereumsolanabitcoin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@walletconnect/types AI (phantom-deps): Declared in dependencies; used transitively via @walletconnect/universal-provider. ai
phantom-deps phantom-dep:@walletconnect/utils AI (phantom-deps): Declared in dependencies; used transitively via @walletconnect/universal-provider. ai
maintainer-change maintainer-added AI (maintainer-change): Same org transition; reown-npm-org is the canonical publisher. ai
provenance publisher-changed AI (provenance): Legitimate rocky-wc→reown org transition, settled months ago; stable for this package. ai
publish-pattern new-deps-added AI (publish-pattern): semver is a well-established, widely-trusted package; addition is benign for this package. ai
maintainer-change maintainer-removed AI (maintainer-change): Reown org manages this package; single maintainer removal without suspicious additions in a large, active org is routine. ai
phantom-deps phantom-dep:@reown/appkit-polyfills AI (phantom-deps): Same-org sibling package legitimately listed as a runtime dependency; phantom-dep is a stable false positive for this aggregator package. ai
phantom-deps phantom-dep:valtio AI (phantom-deps): valtio is a legitimate runtime dependency of the appkit ecosystem; phantom-dep fires because it may be re-exported rather than directly imported at the top level. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall runs a version compatibility check script (appkit-version-check.js) — a standard monorepo pattern for @reown/appkit to verify sibling package version consistency. ai

Versions (showing 70 of 70)

Version Deps Published
1.8.22 13 / 12
1.8.20 13 / 12
1.8.19 13 / 12
1.8.18 13 / 12
1.8.17 13 / 12
1.8.16 13 / 12
1.8.15 13 / 12
1.8.14 13 / 12
1.8.13 13 / 12
1.8.9 13 / 12
1.8.8 13 / 12
1.8.4 13 / 12
1.8.3 13 / 12
1.8.2 13 / 12
1.8.1 13 / 12
1.8.0 13 / 12
1.7.19 13 / 12
1.7.18 13 / 12
1.7.17 13 / 12
1.7.16 14 / 10
1.7.14 14 / 12
1.7.11 14 / 12
1.7.10 13 / 12
1.7.9 13 / 12
1.7.8 13 / 12
1.7.7 13 / 12
1.7.6 13 / 12
1.7.5 13 / 12
1.7.4 13 / 12
1.7.3 12 / 12
1.7.2 12 / 12
1.7.1 12 / 11
1.7.0 12 / 11
1.6.9 13 / 11
1.6.8 13 / 11
1.6.7 13 / 11
1.6.6 13 / 11
1.6.5 14 / 10
1.6.4 14 / 10
1.6.3 14 / 10
1.6.2 14 / 10
1.6.1 14 / 10
1.6.0 14 / 10
1.5.3 14 / 10
1.5.2 14 / 10
1.5.1 13 / 11
1.5.0 14 / 10
1.4.1 14 / 10
1.4.0 14 / 10
1.3.2 14 / 10
1.3.1 14 / 10
1.3.0 13 / 10
1.2.1 13 / 10
1.2.0 13 / 10
1.1.8 13 / 10
1.1.7 13 / 10
1.1.6 13 / 10
1.1.5 13 / 10
1.1.4 13 / 10
1.1.3 13 / 10
1.1.2 13 / 10
1.1.0 13 / 10
1.0.7 12 / 10
1.0.6 12 / 10
1.0.5 12 / 10
1.0.4 12 / 20
1.0.3 12 / 20
1.0.2 12 / 20
1.0.1 12 / 20
1.0.0 12 / 20

v1.8.22

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.3

2 findings
HIGH Publisher changed: rocky-wc → reown-npm-org (on 2025-04-15) provenance

This version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.6.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.