← Home

permissionless

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

plusminushalfkristofgazsomouseless-eth

Keywords

ethereumerc-4337eip-4337paymasterbundler

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:accounts/kernel/toKernelSmartAccount.ts AI (source-diff): Hex EVM calldata for ERC-4337 module install, not an encoded payload. ai
source-diff encoded-string-file:_esm/accounts/kernel/toKernelSmartAccount.js AI (source-diff): Hex EVM calldata for ERC-4337 module install, not an encoded payload. ai
source-diff encoded-string-file:_cjs/accounts/kernel/toKernelSmartAccount.js AI (source-diff): Hex EVM calldata for ERC-4337 module install, not an encoded payload. ai
source-diff encoded-string-file:actions/public/getSenderAddress.ts AI (source-diff): Hex is legitimate EVM contract bytecode for ERC-4337 sender-address helper. ai
source-diff encoded-string-file:_esm/actions/public/getSenderAddress.js AI (source-diff): Same source-linked contract bytecode in ESM build; stable FP. ai
source-diff encoded-string-file:_cjs/actions/public/getSenderAddress.js AI (source-diff): Hex is EVM contract bytecode inherent to this ERC-4337 lib; stable FP. ai
source-diff encoded-string-file:accounts/biconomy/toBiconomySmartAccount.ts AI (source-diff): Hex string is on-chain proxy creation bytecode, standard for AA smart-account libs. ai
source-diff encoded-string-file:_esm/accounts/biconomy/toBiconomySmartAccount.js AI (source-diff): Hex string is on-chain proxy creation bytecode, standard for AA smart-account libs. ai
source-diff encoded-string-file:_cjs/accounts/biconomy/toBiconomySmartAccount.js AI (source-diff): Hex string is on-chain proxy creation bytecode, standard for AA smart-account libs. ai
source-diff encoded-string-file:_cjs/accounts/biconomy/signerToBiconomySmartAccount.js AI (source-diff): Long hex string is Biconomy proxy creation bytecode, inherent to an ERC-4337 lib. ai
source-diff encoded-string-file:_esm/accounts/biconomy/signerToBiconomySmartAccount.js AI (source-diff): Same EVM bytecode constant in the ESM build output; benign. ai

Versions (showing 51 of 151)

View all versions
Version Deps Published
0.3.7 0 / 0
0.3.6 0 / 0
0.3.5 0 / 0
0.3.4 0 / 0
0.3.3 0 / 0
0.3.2 0 / 0
0.3.1 0 / 0
0.3.0 0 / 0
0.2.57 0 / 0
0.2.56 0 / 0
0.2.55 0 / 0
0.2.54 0 / 0
0.2.53 0 / 0
0.2.52 0 / 0
0.2.51 0 / 0
0.2.50 0 / 0
0.2.49 0 / 0
0.2.48 0 / 0
0.2.47 0 / 0
0.2.46 0 / 0
0.2.45 0 / 0
0.2.44 0 / 0
0.2.43 0 / 0
0.2.42 0 / 0
0.2.41 0 / 0
0.2.40 0 / 0
0.2.39 0 / 0
0.2.38 0 / 0
0.2.37 0 / 0
0.2.36 0 / 0
0.2.35 0 / 0
0.2.34 0 / 0
0.2.33 0 / 0
0.2.32 0 / 0
0.2.31 0 / 0
0.2.30 0 / 0
0.2.29 0 / 0
0.2.28 0 / 0
0.2.27 0 / 0
0.2.26 0 / 0
0.2.25 0 / 0
0.2.24 0 / 0
0.2.23 0 / 0
0.2.22 0 / 0
0.2.21 0 / 0
0.2.20 0 / 0
0.2.19 0 / 0
0.2.18 0 / 0
0.2.17 0 / 0
0.2.16 0 / 0
0.2.15 0 / 0

v0.3.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.2.43

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.42

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.41

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.40

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.39

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.38

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.37

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.36

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.35

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.34

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.33

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.32

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.31

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.30

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.29

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.28

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.27

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.26

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.25

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.24

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.23

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.22

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.21

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.20

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.19

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.18

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.17

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.16

3 findings
HIGH Long encoded string in modified file: _cjs/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: _esm/actions/public/getSenderAddress.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.