@web3-onboard/core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/Index-2cf0e913.js | AI (source-diff): Bundled rollup/svelte output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-65f5b343.js | AI (source-diff): Bundled rollup output with license headers, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Index-838ea599.js | AI (source-diff): Bundled rollup/svelte output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-8eb0493f.js | AI (source-diff): Same bundled Svelte output pattern. | ai | |
| source-diff | obfuscated-file:dist/Index-6c094240.js | AI (source-diff): Same bundled Svelte output pattern. | ai | |
| source-diff | obfuscated-file:dist/Index-64ac63ff.js | AI (source-diff): Rollup/svelte bundle output, long minified lines are build artifacts not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Index-652aeb8c.js | AI (source-diff): Rollup/svelte bundled output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-da42639e.js | AI (source-diff): Rollup/svelte bundled output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Index-c419311f.js | AI (source-diff): Rollup/svelte bundled output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Index-a4a1058e.js | AI (source-diff): Bundled rollup/svelte build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/index-323aef78.js | AI (source-diff): Bundled rollup/svelte build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Index-8adb4124.js | AI (source-diff): Bundled rollup/svelte build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/icons/poweredByThirdweb.d.ts | AI (source-diff): Long single-line SVG string in .d.ts, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/icons/thirdweb-icon.d.ts | AI (source-diff): Long single-line SVG string in .d.ts, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/icons/snax.d.ts | AI (source-diff): Long single-line SVG string in .d.ts, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/index-10054806.js | AI (source-diff): Bundled rollup output with legible imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Index-fb68189d.js | AI (source-diff): Bundled svelte component output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Index-bf757f44.js | AI (source-diff): Bundled svelte component output, not obfuscation. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped Blocknative monorepo package; not a typosquat of 'cors'. Stable false positive for this package. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 2.24.1 | 12 / 24 | |
| 2.24.0 | 12 / 24 | |
| 2.23.1 | 12 / 24 | |
| 2.23.0 | 12 / 24 | |
| 2.22.3 | 12 / 24 | |
| 2.22.2 | 12 / 25 | |
| 2.22.1 | 12 / 25 | |
| 2.22.0 | 12 / 25 |
v2.24.0
9 findingsAll previous maintainers (aaronbarnard1, cmeisl) were replaced by new maintainers (jakeloo, joaquim-verges). This is a strong signal of a potential package hijack and requires careful review.
This version was published by a different npm account than previous versions on 2025-01-15. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.1
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.0
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.3
5 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.2
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.22.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.