@everymatrix/casino-coinroyale-container
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CasinoCoinroyaleContainer-CPd0TjE4.js | AI (source-diff): Standard Vite/Rollup minified build output; no malicious patterns present. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleContainer-DkwAxPBK.js | AI (source-diff): Standard Vite/Rollup minified build output; no malicious patterns present. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleDetails-CeP-jQ8H.js | AI (source-diff): Standard minified build output with data URIs; no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleDetails-DpKf3GZ_.js | AI (source-diff): Standard minified build output; no malicious patterns present. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleList-Cf9ppWXB.js | AI (source-diff): Standard minified build output with SVG data URIs; no malicious patterns. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleList-CqfW_iN9.js | AI (source-diff): Standard minified build output; no malicious patterns present. | ai | |
| source-diff | obfuscated-file:components/CasinoMysteryChestModal-BoOM96Bb.js | AI (source-diff): Minified JS with embedded GIF data URI; consistent with UI component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoMysteryChestModal-DsDtwCGt.js | AI (source-diff): Minified JS with embedded GIF data URI; consistent with UI component bundle. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped internal casino UI component library; no repo/keywords/deps is normal for this package type. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleContainer---NT4fF4.js | AI (source-diff): Standard Vite/Rollup minified bundle; readable Svelte framework code, not malicious obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): No provenance across all 303 versions; stable characteristic of this package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Established scoped internal package; missing description is a stable characteristic. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleContainer-DJJ0of7y.js | AI (source-diff): Standard Vite/Rollup minified bundle; readable framework code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleDetails-D5aDdbCH.js | AI (source-diff): Standard Vite/Rollup minified bundle; readable framework code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleDetails-DFU106n2.js | AI (source-diff): Standard Vite/Rollup minified bundle; readable framework code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleList-DCCl8nwB.js | AI (source-diff): Standard Vite/Rollup minified bundle; readable framework code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoCoinroyaleList-u5LNaYTW.js | AI (source-diff): Standard Vite/Rollup minified bundle; readable framework code, not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoMysteryChestModal-DsFiuw_B.js | AI (source-diff): Standard Vite/Rollup minified bundle with embedded base64 image assets; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:components/CasinoMysteryChestModal-DVfXrSjz.js | AI (source-diff): Standard Vite/Rollup minified bundle with embedded base64 image assets; not malicious obfuscation. | ai |
Versions (showing 38 of 242)
| Version | Deps | Published |
|---|---|---|
| 1.77.1 | 0 / 0 | |
| 1.77.0 | 0 / 0 | |
| 1.76.14 | 0 / 0 | |
| 1.76.13 | 0 / 0 | |
| 1.76.12 | 0 / 0 | |
| 1.76.11 | 0 / 0 | |
| 1.76.10 | 0 / 0 | |
| 1.76.9 | 0 / 0 | |
| 1.76.8 | 0 / 0 | |
| 1.76.7 | 0 / 0 | |
| 1.76.6 | 0 / 0 | |
| 1.76.5 | 0 / 0 | |
| 1.76.4 | 0 / 0 | |
| 1.76.3 | 0 / 0 | |
| 1.76.1 | 0 / 0 | |
| 1.76.0 | 0 / 0 | |
| 1.75.1 | 0 / 0 | |
| 1.75.0 | 0 / 0 | |
| 1.74.10 | 0 / 0 | |
| 1.74.8 | 0 / 0 | |
| 1.74.7 | 0 / 0 | |
| 1.74.6 | 0 / 0 | |
| 1.74.5 | 0 / 0 | |
| 1.74.4 | 0 / 0 | |
| 1.74.3 | 0 / 0 | |
| 1.74.2 | 0 / 0 | |
| 1.74.1 | 0 / 0 | |
| 1.74.0 | 0 / 0 | |
| 1.73.2 | 0 / 0 | |
| 1.73.1 | 0 / 0 | |
| 1.73.0 | 0 / 0 | |
| 1.72.2 | 0 / 0 | |
| 1.72.1 | 0 / 0 | |
| 1.72.0 | 0 / 0 | |
| 1.71.1 | 0 / 0 | |
| 1.71.0 | 0 / 0 | |
| 1.70.1 | 0 / 0 | |
| 1.70.0 | 0 / 0 |
v1.77.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.77.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.