@everymatrix/casino-challenges-overlay
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-a75f839f.js | AI (source-diff): Standard Stencil.js minified build output. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/index-7fdd1cbf.js | AI (source-diff): Standard Stencil.js runtime bundle; consistent with established @everymatrix widget pattern. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-e43b403e.js | AI (source-diff): Standard Stencil.js minified build output. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-e43b403e.js | AI (source-diff): Standard Stencil.js minified build output. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-75a7cbc9.js | AI (source-diff): Standard Stencil.js minified build output; ESM variant includes readable JSDoc, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-75a7cbc9.js | AI (source-diff): Minified Stencil bundle; content is component logic, no exfiltration or shell patterns. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-ac229a05.js | AI (source-diff): CJS counterpart of the same Stencil build; readable structure with JSDoc comments. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-eef46bdb.js | AI (source-diff): Standard Stencil.js minified build output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-2332b012.js | AI (source-diff): Standard Stencil.js minified build output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay_2.entry.js | AI (source-diff): Standard Stencil.js minified build output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay_2.entry.js | AI (source-diff): Standard Stencil.js minified build output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay_2.cjs.entry.js | AI (source-diff): Standard Stencil.js minified build output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/index-2be35f12.js | AI (source-diff): Standard Stencil.js runtime bundle; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-eef46bdb.js | AI (source-diff): Standard Stencil.js minified build output; consistent with this package's established build pattern. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-48b07cb1.js | AI (source-diff): Standard Rollup/Stencil minified build output for this widget package; consistent across all versions. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-48b07cb1.js | AI (source-diff): Standard Rollup/Stencil minified build output for this widget package; consistent across all versions. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-3f42bf67.js | AI (source-diff): Standard Rollup/Stencil minified build output for this widget package; consistent across all versions. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-78a3b5f9.js | AI (source-diff): Standard Stencil.js ESM minified bundle; no malicious patterns, readable source comments present. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-f1ed1c93.js | AI (source-diff): Standard Stencil.js CJS minified bundle; no malicious patterns, readable source comments present. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-78a3b5f9.js | AI (source-diff): Standard Stencil.js minified bundle output; consistent with @everymatrix widget build pattern. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-89a5469f.js | AI (source-diff): Minified widget bundle consistent with Stencil build pipeline used across this package family. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-77be149d.js | AI (source-diff): Standard Rollup/Stencil CJS bundle output; long lines are minified widget code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-89a5469f.js | AI (source-diff): Standard Rollup/Stencil ESM bundle output; same pattern as other @everymatrix widget packages. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-3f4dc422.js | AI (source-diff): Standard Rollup/Stencil minified build output; consistent with this widget package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-e801be58.js | AI (source-diff): Standard Rollup/Stencil minified build output; consistent with this widget package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/index-4cb6ae8e.js | AI (source-diff): Standard Stencil runtime bundle; minification pattern matches known Stencil output. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-e801be58.js | AI (source-diff): Standard Rollup/Stencil minified build output; consistent with this widget package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-be7f1691.js | AI (source-diff): Standard Stencil.js CJS minified bundle; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-68684fef.js | AI (source-diff): Standard Stencil.js ESM minified bundle; no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-68684fef.js | AI (source-diff): Standard Stencil.js minified bundle; consistent with all prior @everymatrix package builds. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-4b5f57a1.js | AI (source-diff): Standard minified Stencil build bundle; pattern is stable across all versions of this package. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-9bb4cca8.js | AI (source-diff): Standard minified Stencil build bundle; pattern is stable across all versions of this package. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-9bb4cca8.js | AI (source-diff): Standard minified Stencil build bundle; pattern is stable across all versions of this package. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-a5ae48f5.js | AI (source-diff): Standard Stencil.js minified ESM build artifact; consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-a5ae48f5.js | AI (source-diff): Standard Stencil.js minified bundle; consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-68ec1eb8.js | AI (source-diff): Standard Stencil.js minified build artifact; pattern is consistent across all versions of this widget package. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/index-be60b13e.js | AI (source-diff): Stencil.js runtime bundle (minified); consistent with package's build pipeline. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-5fcad42a.js | AI (source-diff): Standard Stencil minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-5fcad42a.js | AI (source-diff): Standard Stencil minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-365b73b3.js | AI (source-diff): Standard Stencil minified build output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-6f01489c.js | AI (source-diff): Standard Rollup/Stencil minified bundle output; consistent with this package's build pattern across all versions. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-fd6ae571.js | AI (source-diff): Standard Rollup/Stencil minified bundle output; consistent with this package's build pattern across all versions. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-fd6ae571.js | AI (source-diff): Standard Rollup/Stencil minified bundle output; consistent with this package's build pattern across all versions. | ai | |
| source-diff | obfuscated-file:dist/casino-challenges-overlay/casino-challenges-overlay-0ab4098a.js | AI (source-diff): Standard Stencil.js minified bundle output; consistent pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:dist/cjs/casino-challenges-overlay-9b3b30da.js | AI (source-diff): Readable CJS build artifact with comments; not obfuscated, just long lines from bundling. | ai | |
| source-diff | obfuscated-file:dist/esm/casino-challenges-overlay-0ab4098a.js | AI (source-diff): Readable ESM build artifact with comments; not obfuscated, just long lines from bundling. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped org widget package; no deps/description/keywords is normal for this component library pattern across 220 versions. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent across all versions of this org's widget packages; not a malice indicator here. | ai |
v0.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.