← Home

@solana-mobile/mobile-wallet-adapter-protocol-web3js

A convenience wrapper that enables you to call Solana Mobile Stack protocol methods using objects from @solana/web3.js

21
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

michaelsulistiofunkatronics_solstevenlaverankur2136olivier.goutay

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): Publish-env change only; no material code diff, trusted official publisher. ai
bogus-package bogus-package AI (bogus-package): Part of the official Solana Mobile monorepo; sparse README and missing keywords are cosmetic issues common in SDK sub-packages, not spam indicators. ai
dependencies unvetted-dep:@solana-mobile/mobile-wallet-adapter-protocol AI (dependencies): Sibling package from the same official Solana Mobile monorepo; a natural and expected dependency for this wrapper package. ai

Versions (showing 21 of 21)

Version Deps Published
2.2.9 1 / 4
2.2.8 3 / 4
2.2.7 3 / 4
2.2.6 3 / 4
2.2.5 3 / 4
2.2.4 3 / 4
2.2.3 3 / 4
2.2.2 3 / 4
2.2.0 3 / 4
2.1.8 3 / 4
2.1.7 3 / 4
2.1.5 3 / 4
2.1.4 3 / 4
2.1.3 3 / 4
2.1.2 3 / 4
2.1.1 3 / 4
2.1.0 3 / 4
2.0.3 3 / 2
2.0.2 3 / 2
2.0.1 3 / 2
2.0.0 3 / 2

v2.1.8

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: michaelsulistio.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: funkatronics_sol → michaelsulistio (on 2025-04-22, known maintainer) provenance

This version was published by a different npm account (michaelsulistio) than the most recent previously approved version (funkatronics_sol) on 2025-04-22, but michaelsulistio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.7

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: michaelsulistio.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: funkatronics_sol → michaelsulistio (on 2025-04-21, known maintainer) provenance

This version was published by a different npm account (michaelsulistio) than the most recent previously approved version (funkatronics_sol) on 2025-04-21, but michaelsulistio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.1.3

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: michaelsulistio → funkatronics_sol (on 2024-04-24, known maintainer) provenance

This version was published by a different npm account (funkatronics_sol) than the most recent previously approved version (michaelsulistio) on 2024-04-24, but funkatronics_sol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.2

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: michaelsulistio → funkatronics_sol (on 2024-02-20, known maintainer) provenance

This version was published by a different npm account (funkatronics_sol) than the most recent previously approved version (michaelsulistio) on 2024-02-20, but funkatronics_sol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.1

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: michaelsulistio → funkatronics_sol (on 2024-01-23, known maintainer) provenance

This version was published by a different npm account (funkatronics_sol) than the most recent previously approved version (michaelsulistio) on 2024-01-23, but funkatronics_sol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.1.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: michaelsulistio → funkatronics_sol (on 2024-01-19, known maintainer) provenance

This version was published by a different npm account (funkatronics_sol) than the most recent previously approved version (michaelsulistio) on 2024-01-19, but funkatronics_sol is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.0.3

2 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: funkatronics_sol.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.2

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: funkatronics_sol → michaelsulistio (on 2023-09-25, known maintainer) provenance

This version was published by a different npm account (michaelsulistio) than the most recent previously approved version (funkatronics_sol) on 2023-09-25, but michaelsulistio is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v2.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.