@wallet-standard/app
This package defines functions to help apps support Wallets that implement the Wallet Standard.
4
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
jordansextonsteveluschermcintyre94
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Moved to GitHub Actions CI/CD publishing with SLSA provenance; stable for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Established scoped package with 1.1M downloads; low README detail is normal for monorepo sub-packages. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): @wallet-standard/app is a legitimate scoped package from Solana Foundation; Levenshtein match to 'yup' is a false positive with no plausible confusion vector. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): @wallet-standard/app is a legitimate scoped package from Solana Foundation; Levenshtein match to 'hapi' is a false positive with no plausible confusion vector. | ai | |
| dependencies | unvetted-dep:@wallet-standard/base | AI (dependencies): @wallet-standard/base is a sibling package in the same wallet-standard monorepo; dependency is expected and legitimate. | ai | |
| typosquat | typosquat.levenshtein:ajv | AI (typosquat): @wallet-standard/app is a legitimate scoped package from Solana Foundation; Levenshtein match to 'ajv' is a false positive with no plausible confusion vector. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): @wallet-standard/app is a legitimate scoped package from Solana Foundation; Levenshtein match to 'pg' is a false positive with no plausible confusion vector. | ai |
v1.0.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.