← Home

@reown/walletkit

25
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

cyberdrkreown-npm-org

Keywords

walletwalletconnectreownwalletkit

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@walletconnect/pay AI (dependencies): First-party WalletConnect/Reown org package, not third-party unvetted code. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is official WalletConnect package aligned with stated function. ai
maintainer-change maintainer-added AI (maintainer-change): Org rebrand (WalletConnect->Reown), stable publisher with strong track record. ai
maintainer-change maintainer-removed AI (maintainer-change): Consistent with org rebrand, not takeover; long-stable on npm. ai
provenance publisher-changed-stale AI (provenance): Analyzer itself notes 387d stability is inconsistent with takeover. ai
source-diff obfuscated-file:dist/index.cjs AI (source-diff): Rollup-minified dist bundle, not obfuscation; readable minified code. ai
source-diff encoded-string-file:dist/index.umd.js AI (source-diff): UMD bundle with license banner; minified build output. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): Rollup-minified ESM dist bundle. ai
phantom-deps phantom-dep:@walletconnect/utils AI (phantom-deps): Transitively used dep in monorepo build; stable FP. ai
phantom-deps phantom-dep:@walletconnect/jsonrpc-provider AI (phantom-deps): Legit WC dep, config-referenced; stable FP. ai

Versions (showing 25 of 25)

Version Deps Published
1.5.6 8 / 1
1.5.5 8 / 1
1.5.3 8 / 1
1.5.2 8 / 1
1.5.0 8 / 1
1.4.1 7 / 1
1.4.0 7 / 1
1.3.0 7 / 1
1.2.11 7 / 1
1.2.10 7 / 1
1.2.9 7 / 1
1.2.8 7 / 1
1.2.7 7 / 1
1.2.6 7 / 1
1.2.5 7 / 1
1.2.4 7 / 1
1.2.3 7 / 1
1.2.2 7 / 1
1.2.1 7 / 1
1.2.0 7 / 1
1.1.2 7 / 1
1.1.1 7 / 1
1.1.0 7 / 1
1.0.1 7 / 1
1.0.0 7 / 1

v1.5.6

5 findings
HIGH New obfuscated file: dist/index.cjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: dist/index.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH Long encoded string in modified file: dist/index.umd.js source-diff

Modified file contains 2 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: gancho_walletconnect → reown-npm-org (on 2026-06-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2026-06-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.5.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-10-30, now via trusted publisher with provenance) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-10-30, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.11

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-09-19, now via trusted publisher with provenance) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-09-19, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v1.2.10

2 findings
MEDIUM Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-08-07, unremoved on npm for 344d) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-08-07. It has since remained available on npm for 344 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.9

2 findings
MEDIUM Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-07-31, unremoved on npm for 351d) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-07-31. It has since remained available on npm for 351 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.8

2 findings
MEDIUM Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-06-25, unremoved on npm for 387d) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-06-25. It has since remained available on npm for 387 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.7

2 findings
MEDIUM Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-06-17, unremoved on npm for 395d) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-06-17. It has since remained available on npm for 395 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.6

2 findings
MEDIUM Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-06-09, unremoved on npm for 403d) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-06-09. It has since remained available on npm for 403 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.5

2 findings
MEDIUM Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-05-27, unremoved on npm for 416d) provenance

This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-05-27. It has since remained available on npm for 416 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.4

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: gancho_walletconnect → reown-npm-org (on 2025-05-01, unremoved on npm for 443d) provenance

[Accepted risk] This version was published by a different npm account (reown-npm-org) than the most recent previously approved version (gancho_walletconnect) on 2025-05-01. It has since remained available on npm for 443 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

v1.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.