@wallet-standard/errors
4
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
jordansextonsteveluschermcintyre94
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | suspicious-initial-version | AI (npm-metadata): 0.0.0 is a monorepo placeholder version for an established, trusted package. | ai | |
| semgrep | semgrep:shady-links-tlds | AI (semgrep): Flagged URL (anza.xyz) appears only in test fixtures as a URL constructor argument. Anza is a legitimate Solana ecosystem company; this is not C2/exfiltration infrastructure. | ai | |
| provenance | no-provenance | AI (provenance): Absence of Sigstore provenance is common and not a disqualifier for this well-established Solana Foundation package. | ai |
v0.1.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.0.0
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.