← Home

@wallet-standard/features

This package defines TypeScript types for **Standard Features** -- canonical, chain-agnostic features using the `standard` namespace of the Wallet Standard.

6
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

jordansextonsteveluschermcintyre94

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Legitimate CI/CD migration from individual publisher to GitHub Actions with SLSA provenance. ai
publish-pattern dormant-publish AI (publish-pattern): Mature, widely-depended-on package resuming publishing via CI/CD with provenance attestation. ai
bogus-package bogus-package AI (bogus-package): This is a legitimate monorepo sub-package from the Solana wallet-standard org. Sparse README and no keywords are typical for focused utility/type packages in this ecosystem. ai
provenance no-provenance AI (provenance): Package predates widespread Sigstore provenance adoption; no other risk signals present to make this a concern. ai

Versions (showing 6 of 6)

Version Deps Published
1.1.1 1 / 1
1.1.0 1 / 1
1.0.3 1 / 1
1.0.2 1 / 1
1.0.1 1 / 1
1.0.0 1 / 1

v1.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.