@walletconnect/universal-provider
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file-transition:dist/index.cjs.js | AI (source-diff): Bundled rollup output; network targets are first-party walletconnect relay/rpc endpoints. | ai | |
| phantom-deps | phantom-dep:@walletconnect/jsonrpc-utils | AI (phantom-deps): Same-org util dependency, stable FP. | ai | |
| phantom-deps | phantom-dep:@walletconnect/jsonrpc-types | AI (phantom-deps): Same-org type dependency, stable FP. | ai | |
| source-diff | net-exec-file-transition:dist/index.es.js | AI (source-diff): Bundled rollup output; network targets are first-party walletconnect relay/rpc endpoints. | ai | |
| provenance | publisher-changed | AI (provenance): Legitimate WalletConnect→Reown org transition; publisher has clean track record. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): reown-npm-org is the known successor org for WalletConnect packages. | ai | |
| source-diff | encoded-string-file:dist/index.umd.js | AI (source-diff): Long string is rollup UMD build output; stable false positive for this package's dist bundle. | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): Rollup bundle output with source maps; standard for this package. | ai | |
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Rollup bundle output with source maps; standard for this package. | ai | |
| phantom-deps | phantom-dep:es-toolkit | AI (phantom-deps): es-toolkit is explicitly listed as a runtime dependency in package.json; the phantom-dep finding is a false positive likely due to build config references rather than direct imports. | ai | |
| dependencies | unvetted-dep:@walletconnect/jsonrpc-http-connection | AI (dependencies): @walletconnect/jsonrpc-http-connection is a first-party WalletConnect ecosystem package; its use here is expected and consistent across all versions of this package. | ai |
Versions (showing 51 of 103)
| Version | Deps | Published |
|---|---|---|
| 2.23.10 | 12 / 5 | |
| 2.23.9 | 12 / 5 | |
| 2.23.8 | 12 / 5 | |
| 2.23.7 | 12 / 5 | |
| 2.23.6 | 12 / 5 | |
| 2.23.5 | 12 / 5 | |
| 2.23.4 | 12 / 5 | |
| 2.23.3 | 12 / 5 | |
| 2.23.2 | 12 / 5 | |
| 2.23.1 | 12 / 5 | |
| 2.23.0 | 12 / 5 | |
| 2.22.4 | 12 / 5 | |
| 2.22.3 | 12 / 5 | |
| 2.22.2 | 12 / 5 | |
| 2.22.1 | 12 / 5 | |
| 2.22.0 | 12 / 5 | |
| 2.21.10 | 12 / 5 | |
| 2.21.9 | 12 / 5 | |
| 2.21.8 | 12 / 5 | |
| 2.21.7 | 12 / 5 | |
| 2.21.6 | 12 / 5 | |
| 2.21.5 | 12 / 5 | |
| 2.21.4 | 12 / 5 | |
| 2.21.3 | 12 / 5 | |
| 2.21.2 | 12 / 5 | |
| 2.21.1 | 12 / 5 | |
| 2.21.0 | 12 / 5 | |
| 2.20.3 | 12 / 5 | |
| 2.20.2 | 12 / 5 | |
| 2.20.1 | 12 / 5 | |
| 2.20.0 | 12 / 5 | |
| 2.19.4 | 12 / 5 | |
| 2.19.3 | 12 / 5 | |
| 2.19.2 | 12 / 5 | |
| 2.19.1 | 12 / 5 | |
| 2.19.0 | 12 / 5 | |
| 2.18.1 | 12 / 5 | |
| 2.18.0 | 12 / 5 | |
| 2.17.5 | 12 / 5 | |
| 2.17.4 | 12 / 5 | |
| 2.17.3 | 12 / 5 | |
| 2.17.2 | 12 / 5 | |
| 2.17.1 | 12 / 5 | |
| 2.11.3 | 9 / 5 | |
| 2.11.2 | 9 / 5 | |
| 2.11.1 | 9 / 5 | |
| 2.11.0 | 9 / 5 | |
| 2.10.6 | 9 / 5 | |
| 2.10.5 | 9 / 5 | |
| 2.10.4 | 9 / 5 | |
| 2.10.3 | 9 / 5 |
v2.20.0
2 findingsThis version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.4
2 findingsThis version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.3
2 findingsThis version was published by a different npm account than previous versions on 2025-04-15. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.5
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.4
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.3
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.2
2 findingsModified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.11.3
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.2
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.1
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.6
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.5
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.4
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.3
3 findingsThis file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.