@everymatrix/casino-promotions-nd
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/CasinoPromotionsNd-C5DMyqhN.js | AI (source-diff): Standard Vite/Svelte minified bundle output; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-CGaKBRPQ.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DEDfGcCx.js | AI (source-diff): Standard Vite/Svelte minified bundle output; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-EtmwLYu8.js | AI (source-diff): ESM version of the same component bundle. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DbINkDsn.cjs | AI (source-diff): Standard minified Svelte/Stencil component bundle output for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-BOnhYATT.js | AI (source-diff): ESM version of the same component bundle. | ai | |
| source-diff | obfuscated-file:stencil/ui-skeleton-ed169f8f-CpiCXJrP.cjs | AI (source-diff): UI skeleton component with CSS; standard build output. | ai | |
| source-diff | obfuscated-file:stencil/index-b2193545-9K-aI7zC.cjs | AI (source-diff): Stencil runtime CJS bundle; minified but not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DB1oDErp.js | AI (source-diff): Vite-bundled ESM output; minified but readable structure, no malicious indicators. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-CXPvA0xD.cjs | AI (source-diff): Standard Stencil/Vite minified build output; long lines are bundled JS, not obfuscation. | ai | |
| source-diff | obfuscated-file:stencil/index-b2193545-YW9b062G.cjs | AI (source-diff): Standard Stencil runtime bundle; content matches known Stencil patterns. | ai | |
| source-diff | obfuscated-file:stencil/ui-skeleton-ae35c6f2-xLf3HyeB.cjs | AI (source-diff): Stencil component bundle with CSS-in-JS; not obfuscated. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DJfYThbo.js | AI (source-diff): Vite-bundled ESM output; standard build artifact for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-EaNbzUGB.cjs | AI (source-diff): Standard Vite/Svelte minified bundle output; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-oZQ8b9QM.js | AI (source-diff): Standard Vite/Svelte minified bundle output; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-B5Rz-3zH.js | AI (source-diff): Standard Vite/Svelte minified bundle output; not obfuscated malware. Stable pattern for this package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-BR8-U9oH.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output; consistent with prior releases of this UI component package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped internal UI component package in a monorepo; no repo/deps/keywords is expected for this type of package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-DxI-IFg2.js | AI (source-diff): Standard Rollup/Vite minified bundle output; consistent with prior releases of this UI component package. | ai | |
| source-diff | obfuscated-file:components/CasinoPromotionsNd-BXMZjt_D.js | AI (source-diff): Standard Rollup/Vite minified bundle output; consistent with prior releases of this UI component package. | ai |
Versions (showing 6 of 107)
| Version | Deps | Published |
|---|---|---|
| 1.68.0 | 0 / 0 | |
| 1.67.0 | 0 / 0 | |
| 1.66.2 | 0 / 0 | |
| 1.66.1 | 0 / 0 | |
| 1.66.0 | 0 / 0 | |
| 1.65.3 | 0 / 0 |
v1.68.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.67.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.66.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.66.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.