← Home

@x402/paywall

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

carsonroscoe_cberik_cb

Keywords

x402paywallpaymenthttp-402

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): CI/CD publish environment change, offset by SLSA provenance attestation. ai
source-diff obfuscated-file:dist/cjs/avm/index.cjs AI (source-diff): Standard esbuild CJS bundle output with inlined HTML templates; not obfuscation. ai
source-diff net-exec-file:dist/esm/avm/index.js AI (source-diff): Bundled blockchain SDK code; network calls + dynamic patterns are from wallet/chain libs. ai
source-diff net-exec-file:dist/cjs/avm/index.cjs AI (source-diff): Bundled blockchain SDK code; network calls + dynamic patterns are from wallet/chain libs. ai
source-diff obfuscated-file:dist/esm/avm/index.js AI (source-diff): Standard esbuild ESM bundle output with inlined HTML templates; not obfuscation. ai
source-diff obfuscated-file:dist/esm/svm/index.js AI (source-diff): tsup/esbuild bundle output; long lines are inlined HTML/CSS templates. ai
source-diff obfuscated-file:dist/esm/index.js AI (source-diff): tsup/esbuild bundle output; long lines are inlined HTML/CSS templates. ai
source-diff obfuscated-file:dist/esm/evm/index.js AI (source-diff): tsup/esbuild bundle output; long lines are inlined HTML/CSS templates. ai
source-diff obfuscated-file:dist/cjs/svm/index.cjs AI (source-diff): tsup/esbuild bundle output; long lines are inlined HTML/CSS templates. ai
source-diff obfuscated-file:dist/cjs/evm/index.cjs AI (source-diff): tsup/esbuild bundle output with readable boilerplate and inlined HTML templates, not obfuscation. ai
source-diff obfuscated-file:dist/cjs/index.cjs AI (source-diff): tsup/esbuild bundle output; long lines are inlined HTML/CSS templates. ai
source-diff net-exec-file:dist/esm/index.js AI (source-diff): Wallet/blockchain SDK bundle naturally contains network calls; no malicious exec patterns. ai
source-diff net-exec-file:dist/esm/evm/index.js AI (source-diff): Wallet/blockchain SDK bundle naturally contains network calls; no malicious exec patterns. ai
source-diff net-exec-file:dist/cjs/index.cjs AI (source-diff): Wallet/blockchain SDK bundle naturally contains network calls; no malicious exec patterns. ai
source-diff net-exec-file:dist/cjs/evm/index.cjs AI (source-diff): Wallet/blockchain SDK bundle naturally contains network calls; no malicious exec patterns. ai
source-diff encoded-string-file:dist/esm/svm/index.js AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
source-diff encoded-string-file:dist/cjs/avm/index.cjs AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
source-diff encoded-string-file:dist/cjs/evm/index.cjs AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
source-diff encoded-string-file:dist/cjs/index.cjs AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
source-diff encoded-string-file:dist/cjs/svm/index.cjs AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
source-diff encoded-string-file:dist/esm/avm/index.js AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
source-diff encoded-string-file:dist/esm/evm/index.js AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
source-diff encoded-string-file:dist/esm/index.js AI (source-diff): Long strings are inlined HTML/CSS paywall templates, not obfuscated payloads — stable pattern for this package. ai
phantom-deps phantom-dep:viem AI (phantom-deps): Peer/optional wallet dep pattern; stable false positive for this paywall UI package. ai
phantom-deps phantom-dep:@solana/wallet-standard-features AI (phantom-deps): Peer/optional wallet dep pattern; stable false positive for this paywall UI package. ai
phantom-deps phantom-dep:@algorandfoundation/algokit-utils AI (phantom-deps): Peer/optional wallet dep pattern; stable false positive for this paywall UI package. ai
bogus-package bogus-package AI (bogus-package): Early-stage Coinbase SDK stub; tiny payload and sparse metadata are expected for v0.0.1 placeholder in the x402 protocol suite. ai
phantom-deps phantom-dep:@perawallet/connect AI (phantom-deps): Algorand Pera wallet connector; expected for AVM paywall support. ai
phantom-deps phantom-dep:@txnlab/use-wallet AI (phantom-deps): Algorand wallet integration dep; expected for AVM paywall support. ai
phantom-deps phantom-dep:@wagmi/connectors AI (phantom-deps): EVM wallet connector dep; expected for paywall UI. ai
phantom-deps phantom-dep:lute-connect AI (phantom-deps): Algorand wallet connector; expected for AVM paywall support. ai
phantom-deps phantom-dep:@wagmi/core AI (phantom-deps): EVM wallet integration dep; expected for paywall UI. ai
phantom-deps phantom-dep:@solana/kit AI (phantom-deps): Solana integration dep; expected for SVM paywall support. ai
phantom-deps phantom-dep:@scure/base AI (phantom-deps): Crypto utility dep; legitimately declared for multi-chain paywall. ai
phantom-deps phantom-dep:@x402/core AI (phantom-deps): Same-org sibling package; stable false positive for this package. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Legitimately declared runtime dep for a multi-chain paywall UI; referenced in build/config files. ai
phantom-deps phantom-dep:wagmi AI (phantom-deps): EVM wallet integration dep; expected for paywall UI supporting multiple chains. ai
phantom-deps phantom-dep:@solana-program/token-2022 AI (phantom-deps): Solana token-2022 program dep; expected for SVM paywall support. ai
phantom-deps phantom-dep:@walletconnect/sign-client AI (phantom-deps): WalletConnect integration dep; expected for multi-chain paywall. ai
phantom-deps phantom-dep:@solana-program/compute-budget AI (phantom-deps): Solana compute budget dep; expected for SVM paywall support. ai
phantom-deps phantom-dep:@solana/transaction-confirmation AI (phantom-deps): Solana transaction dep; expected for SVM paywall support. ai
phantom-deps phantom-dep:@wallet-standard/features AI (phantom-deps): Wallet standard dep; expected for multi-chain paywall. ai
phantom-deps phantom-dep:@blockshake/defly-connect AI (phantom-deps): Algorand Defly wallet connector; expected for AVM paywall support. ai
phantom-deps phantom-dep:@wallet-standard/base AI (phantom-deps): Wallet standard dep; expected for multi-chain paywall. ai
phantom-deps phantom-dep:@tanstack/react-query AI (phantom-deps): React data-fetching dep; expected for paywall UI. ai
phantom-deps phantom-dep:@wallet-standard/app AI (phantom-deps): Wallet standard dep; expected for multi-chain paywall. ai
phantom-deps phantom-dep:@solana-program/token AI (phantom-deps): Solana token program dep; expected for SVM paywall support. ai

Versions (showing 20 of 20)

Version Deps Published
2.18.0 22 / 25
2.17.0 22 / 25
2.16.0 22 / 25
2.15.0 22 / 25
2.14.0 22 / 25
2.13.0 22 / 25
2.12.0 22 / 25
2.11.0 23 / 25
2.10.0 23 / 25
2.9.0 17 / 24
2.8.0 17 / 24
2.7.0 17 / 24
2.6.0 17 / 24
2.5.0 17 / 24
2.4.0 17 / 24
2.3.0 17 / 24
2.2.0 17 / 24
2.1.0 17 / 24
2.0.0 17 / 24
0.0.1 0 / 0

v2.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.8.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2026-03-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2026-03-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.7.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2026-03-16, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2026-03-16, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.6.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2026-03-06, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2026-03-06, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.5.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2026-02-26, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2026-02-26, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.4.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2026-02-20, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2026-02-20, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.3.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2026-02-05, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2026-02-05, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.2.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2026-01-09, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2026-01-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.1.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2025-12-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2025-12-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v2.0.0

3 findings
HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: GitHub Actions.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: carsonroscoe_cb → GitHub Actions (on 2025-12-11, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (carsonroscoe_cb) on 2025-12-11, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.