@tomo-inc/wallet-connect-kit
A lightweight React SDK for integrating crypto wallet connection functionality into your applications. It provides a configurable wallet list modal and basic account operations.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:viem | AI (phantom-deps): Bundled library; deps consumed via build output, not direct imports — stable FP for this package. | ai | |
| phantom-deps | phantom-dep:qrcode | AI (phantom-deps): Same bundled-library pattern; stable FP. | ai | |
| phantom-deps | phantom-dep:qr-code-styling | AI (phantom-deps): Same bundled-library pattern; stable FP. | ai | |
| phantom-deps | phantom-dep:@tomo-inc/tomo-ui | AI (phantom-deps): Same org scope, bundled output; stable FP. | ai | |
| phantom-deps | phantom-dep:copy-to-clipboard | AI (phantom-deps): Same bundled-library pattern; stable FP. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Same bundled-library pattern; stable FP. | ai | |
| phantom-deps | phantom-dep:@tomo-inc/wallet-adaptor-base | AI (phantom-deps): Same org scope, bundled output; stable FP. | ai | |
| phantom-deps | phantom-dep:@tomo-inc/embedded-wallet-providers | AI (phantom-deps): Same org scope, bundled output; stable FP. | ai |
Versions (showing 6 of 6)
| Version | Deps | Published |
|---|---|---|
| 0.0.20 | 8 / 27 | |
| 0.0.16 | 8 / 24 | |
| 0.0.13 | 8 / 24 | |
| 0.0.5 | 8 / 24 | |
| 0.0.2 | 8 / 24 | |
| 0.0.1 | 8 / 24 |
v0.0.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.