@everymatrix/cashier-methods-list
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CashierMethodsList-CroX4WQT.js | AI (source-diff): Standard ESM build output for a Svelte component; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BQKiNww3.cjs | AI (source-diff): Standard minified CJS build output for a Svelte component; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-Dxqvras0.js | AI (source-diff): Standard ESM build output for a Svelte component; stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DwMW2sMX.js | AI (source-diff): Standard Vite/Rollup ESM bundle output for Svelte component; not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BqKh2TPE.js | AI (source-diff): Standard Vite/Rollup ESM bundle output for Svelte component; not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BSLTlsYM.cjs | AI (source-diff): Standard Vite/Rollup CJS bundle output for Svelte component; not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CuP1ojFe.cjs | AI (source-diff): Standard minified Svelte bundle output; stable pattern for this component library package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-eM03HNfY.js | AI (source-diff): Standard minified Svelte bundle output; stable pattern for this component library package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-C846UBGU.js | AI (source-diff): Standard minified Svelte bundle output; stable pattern for this component library package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-qbUUs4Yf.cjs | AI (source-diff): Standard Svelte/Rollup minified bundle output; not malicious obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-GpRa3Xd7.js | AI (source-diff): Standard Svelte/Rollup minified bundle output; not malicious obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-TXDO2H7v.js | AI (source-diff): Standard Svelte/Rollup minified bundle output; not malicious obfuscation. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CK_Lhegp.js | AI (source-diff): Standard build output for Svelte component; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DzSYVD19.cjs | AI (source-diff): Standard minified build output for Svelte component; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CFZZOKpc.js | AI (source-diff): Standard build output for Svelte component; stable pattern across versions. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-Vzg-wLI3.js | AI (source-diff): Standard minified Svelte bundle output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-JWFVpzR9.js | AI (source-diff): Standard minified Svelte bundle output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BNO_3M_F.cjs | AI (source-diff): Standard minified Svelte bundle output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DN_phmYs.cjs | AI (source-diff): Standard CJS bundle of Svelte component; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-DgKemLH6.js | AI (source-diff): Standard ESM bundle of Svelte component; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-CofeGxcF.js | AI (source-diff): Standard ESM bundle of Svelte component; minified build output, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BeS3VCSB.js | AI (source-diff): Standard minified Svelte component bundle; pattern repeats across every version of this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-WXyddtkn.js | AI (source-diff): Standard minified Svelte component bundle; pattern repeats across every version of this package. | ai | |
| source-diff | obfuscated-file:components/CashierMethodsList-BJj9LVwd.cjs | AI (source-diff): Standard minified Svelte component bundle; pattern repeats across every version of this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Stable pattern for this internal component package across all versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Internal scoped component library; no description/repo/deps is consistent across 502 published versions. | ai |
Versions (showing 52 of 255)
| Version | Deps | Published |
|---|---|---|
| 1.77.5 | 0 / 0 | |
| 1.77.4 | 0 / 0 | |
| 1.77.3 | 0 / 0 | |
| 1.77.2 | 0 / 0 | |
| 1.77.1 | 0 / 0 | |
| 1.77.0 | 0 / 0 | |
| 1.76.14 | 0 / 0 | |
| 1.76.13 | 0 / 0 | |
| 1.76.12 | 0 / 0 | |
| 1.76.11 | 0 / 0 | |
| 1.76.10 | 0 / 0 | |
| 1.76.9 | 0 / 0 | |
| 1.76.8 | 0 / 0 | |
| 1.76.7 | 0 / 0 | |
| 1.76.6 | 0 / 0 | |
| 1.76.5 | 0 / 0 | |
| 1.76.4 | 0 / 0 | |
| 1.76.3 | 0 / 0 | |
| 1.76.1 | 0 / 0 | |
| 1.76.0 | 0 / 0 | |
| 1.75.1 | 0 / 0 | |
| 1.75.0 | 0 / 0 | |
| 1.74.10 | 0 / 0 | |
| 1.74.8 | 0 / 0 | |
| 1.74.7 | 0 / 0 | |
| 1.74.6 | 0 / 0 | |
| 1.74.5 | 0 / 0 | |
| 1.74.4 | 0 / 0 | |
| 1.74.3 | 0 / 0 | |
| 1.74.2 | 0 / 0 | |
| 1.74.1 | 0 / 0 | |
| 1.74.0 | 0 / 0 | |
| 1.73.2 | 0 / 0 | |
| 1.73.1 | 0 / 0 | |
| 1.73.0 | 0 / 0 | |
| 1.72.2 | 0 / 0 | |
| 1.72.1 | 0 / 0 | |
| 1.72.0 | 0 / 0 | |
| 1.71.1 | 0 / 0 | |
| 1.71.0 | 0 / 0 | |
| 1.70.1 | 0 / 0 | |
| 1.70.0 | 0 / 0 | |
| 1.69.3 | 0 / 0 | |
| 1.69.2 | 0 / 0 | |
| 1.69.0 | 0 / 0 | |
| 1.68.0 | 0 / 0 | |
| 1.67.3 | 0 / 0 | |
| 1.67.0 | 0 / 0 | |
| 1.66.2 | 0 / 0 | |
| 1.66.1 | 0 / 0 | |
| 1.66.0 | 0 / 0 | |
| 1.65.3 | 0 / 0 |
v1.77.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.68.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.67.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.67.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.