@web3modal/core
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Monorepo release cadence explains gap; no malicious behavior found. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Consistent with legitimate maintainer handoff, package stable on npm 745d. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Long-standing publisher rotation within WalletConnect org, no takeover signal. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Expected from added first-party @web3modal/* deps and refactor. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): Deps are first-party siblings in the same monorepo/org. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Monorepo restructure across web3modal packages, not injected code. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): Scoped WalletConnect package; Levenshtein match to 'cors' is a false positive for this well-established ecosystem package. | ai | |
| phantom-deps | phantom-dep:valtio | AI (phantom-deps): valtio is a declared runtime dependency; phantom-dep heuristic misfires here. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 5.1.11 | 3 / 3 | |
| 5.0.11 | 3 / 2 | |
| 5.0.10 | 3 / 2 | |
| 5.0.9 | 3 / 2 | |
| 5.0.7 | 3 / 1 | |
| 5.0.6 | 3 / 1 | |
| 5.0.5 | 3 / 1 | |
| 5.0.4 | 3 / 1 | |
| 5.0.3 | 3 / 1 | |
| 5.0.2 | 3 / 1 | |
| 5.0.1 | 3 / 1 | |
| 5.0.0 | 3 / 1 | |
| 2.7.1 | 1 / 1 |
v5.0.11
2 findingsThis version was published by a different npm account (svenvoskamp) than the most recent previously approved version (iljadoesdev) on 2024-07-31. It has since remained available on npm for 717 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.10
2 findingsThis version was published by a different npm account (svenvoskamp) than the most recent previously approved version (iljadoesdev) on 2024-07-30. It has since remained available on npm for 718 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.9
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rocky-wc.
This version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-07-29. It has since remained available on npm for 719 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.7
2 findingsThis version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-07-17. It has since remained available on npm for 731 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.6
2 findingsThis version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-07-03. It has since remained available on npm for 745 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.5
2 findingsThis version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-07-03. It has since remained available on npm for 746 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.4
2 findingsThis version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-07-01. It has since remained available on npm for 747 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.3
2 findingsThis version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-06-20. It has since remained available on npm for 758 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.2
2 findingsThis version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-06-14. It has since remained available on npm for 764 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.1
2 findingsThis version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-06-12. It has since remained available on npm for 766 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
2 findingsThis version was published by a different npm account (svenvoskamp) than the most recent previously approved version (iljadoesdev) on 2024-06-12. It has since remained available on npm for 766 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.