@walletconnect/ethereum-provider
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): WalletConnect→Reown rebrand; publisher well-established with clean track record. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Legitimate org handoff to reown-npm-org. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Prior WalletConnect maintainers removed as part of Reown org transition. | ai | |
| source-diff | encoded-string-file:dist/index.umd.js | AI (source-diff): Rollup UMD bundle output; benign minified build artifact for this package. | ai | |
| phantom-deps | phantom-dep:@walletconnect/logger | AI (phantom-deps): Monorepo transitive dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@walletconnect/jsonrpc-http-connection | AI (phantom-deps): Monorepo transitive dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@walletconnect/sign-client | AI (phantom-deps): Monorepo transitive dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@walletconnect/jsonrpc-utils | AI (phantom-deps): Monorepo transitive dependency; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@walletconnect/jsonrpc-provider | AI (phantom-deps): Monorepo transitive dependency; stable pattern for this package. | ai |
Versions (showing 37 of 37)
| Version | Deps | Published |
|---|---|---|
| 2.23.10 | 10 / 6 | |
| 2.23.9 | 12 / 5 | |
| 2.23.8 | 12 / 5 | |
| 2.23.7 | 12 / 5 | |
| 2.23.6 | 12 / 5 | |
| 2.23.5 | 12 / 5 | |
| 2.23.4 | 12 / 5 | |
| 2.23.3 | 12 / 5 | |
| 2.23.2 | 12 / 5 | |
| 2.23.1 | 12 / 5 | |
| 2.22.4 | 12 / 5 | |
| 2.19.4 | 11 / 4 | |
| 2.19.3 | 11 / 4 | |
| 2.19.2 | 11 / 4 | |
| 2.19.1 | 11 / 4 | |
| 2.19.0 | 11 / 4 | |
| 2.18.1 | 11 / 4 | |
| 2.18.0 | 11 / 4 | |
| 2.17.5 | 11 / 4 | |
| 2.17.4 | 11 / 4 | |
| 2.17.3 | 11 / 4 | |
| 2.17.2 | 11 / 4 | |
| 2.17.1 | 11 / 4 | |
| 2.17.0 | 10 / 4 | |
| 2.16.3 | 10 / 4 | |
| 2.16.2 | 10 / 4 | |
| 2.16.1 | 10 / 4 | |
| 2.16.0 | 10 / 4 | |
| 2.15.3 | 10 / 4 | |
| 2.15.2 | 10 / 4 | |
| 2.15.1 | 10 / 4 | |
| 2.15.0 | 10 / 4 | |
| 2.14.0 | 10 / 4 | |
| 2.13.3 | 10 / 4 | |
| 2.13.2 | 10 / 4 | |
| 2.13.1 | 10 / 4 | |
| 2.13.0 | 10 / 4 |
v2.23.8
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.7
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.6
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.5
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.4
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.3
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.2
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.23.1
2 findingsModified file contains 5 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.19.4
2 findingsThis version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.3
2 findingsThis version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.5
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.4
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.0
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.3
3 findingsThis version was published by a different npm account than previous versions on 2024-06-14. This could indicate a legitimate maintainer transition or an account compromise.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.2
3 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bkrem) than the most recent previously approved version (gancho_walletconnect) on 2024-06-10, but bkrem is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v2.13.1
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.