← Home

@solana-mobile/mobile-wallet-adapter-protocol

An implementation of the Solana Mobile Mobile Wallet Adapter protocol. Use this to open a session with a mobile wallet app, and to issue API calls to it.

22
Versions
Apache-2.0
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

michaelsulistiofunkatronics_solstevenlaverankur2136olivier.goutay

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance present; gitHead absence is a minor metadata gap, not a security concern. ai
publish-pattern new-deps-added AI (publish-pattern): @solana/kit is the canonical Solana SDK; replaces prior granular Solana deps. ai
dependencies unvetted-dep:@solana/wallet-standard-util AI (dependencies): Part of the official Solana wallet-standard ecosystem; consistent with other @solana/* deps in this package. Legitimate dependency for this Solana Mobile package. ai

Versions (showing 22 of 22)

Version Deps Published
2.2.9 4 / 5
2.2.8 5 / 5
2.2.7 5 / 5
2.2.6 5 / 5
2.2.5 5 / 5
2.2.4 4 / 5
2.2.3 4 / 5
2.2.2 4 / 5
2.2.1 4 / 5
2.2.0 4 / 5
2.1.8 4 / 5
2.1.7 4 / 5
2.1.6 4 / 5
2.1.5 4 / 5
2.1.4 4 / 5
2.1.3 4 / 5
2.1.2 4 / 5
2.1.1 4 / 5
2.1.0 4 / 5
2.0.2 2 / 6
2.0.1 0 / 4
2.0.0 0 / 4

v2.1.8

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: michaelsulistio.

v2.1.7

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: michaelsulistio.

v2.1.6

3 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: michaelsulistio.

INFO Publisher changed: funkatronics_sol → michaelsulistio (on 2025-04-21, known maintainer) provenance

This version was published by a different npm account (michaelsulistio) than the most recent previously approved version (funkatronics_sol) on 2025-04-21, but michaelsulistio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

v2.1.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

v2.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

v2.0.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.