@web3modal/ui
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Known WalletConnect/Reown team maintainer rotation, recurring across versions. | ai | |
| source-diff | obfuscated-file:dist/esm/src/assets/svg/copy.js | AI (source-diff): Long line is SVG path data in a lit template, not obfuscated code. | ai | |
| source-diff | obfuscated-file:dist/esm/src/assets/svg/image.js | AI (source-diff): Long line is SVG path data in a lit template, not obfuscated code. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Publisher change stable for 766d on npm, consistent with legitimate team transfer. | ai | |
| typosquat | typosquat.levenshtein:yup | AI (typosquat): Scoped @web3modal/ui is not a typosquat of yup; Levenshtein match is spurious for scoped packages. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): Scoped @web3modal/ui is not a typosquat of uuid; Levenshtein match is spurious for scoped packages. | ai | |
| phantom-deps | phantom-dep:qrcode | AI (phantom-deps): qrcode is a declared runtime dep used in bundled output; phantom-dep heuristic misses bundled imports. | ai | |
| phantom-deps | phantom-dep:motion | AI (phantom-deps): motion is a declared runtime dep used in bundled output; phantom-dep heuristic misses bundled imports. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped @web3modal/ui is not a typosquat of pg; Levenshtein match is spurious for scoped packages. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped @web3modal/ui is not a typosquat of qs; Levenshtein match is spurious for scoped packages. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @web3modal/ui is not a typosquat of joi; Levenshtein match is spurious for scoped packages. | ai |
Versions (showing 8 of 8)
| Version | Deps | Published |
|---|---|---|
| 5.1.11 | 2 / 8 | |
| 5.0.10 | 2 / 6 | |
| 5.0.5 | 2 / 4 | |
| 5.0.4 | 2 / 4 | |
| 5.0.3 | 2 / 4 | |
| 5.0.1 | 2 / 4 | |
| 5.0.0 | 2 / 4 | |
| 2.7.1 | 4 / 3 |
v5.0.10
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (svenvoskamp) than the most recent previously approved version (iljadoesdev) on 2024-07-30. It has since remained available on npm for 718 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.5
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-07-03. It has since remained available on npm for 746 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.4
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-07-01. It has since remained available on npm for 747 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.3
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-06-20. It has since remained available on npm for 758 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.1
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (rocky-wc) than the most recent previously approved version (iljadoesdev) on 2024-06-12. It has since remained available on npm for 766 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.0.0
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
This version was published by a different npm account (svenvoskamp) than the most recent previously approved version (iljadoesdev) on 2024-06-12. It has since remained available on npm for 766 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.