@everymatrix/general-player-register-form-nd
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-Bgg7T7Lv.js | AI (source-diff): ESM bundle variant; standard minified output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-DptTxBzO.js | AI (source-diff): ESM bundle variant; standard minified output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-ByBdXbSl.js | AI (source-diff): ESM bundle of same Svelte component; standard output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-DhROcW7M.js | AI (source-diff): ESM bundle variant; standard minified output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerSmsVerificationForm-Z1Mm3jPc.cjs | AI (source-diff): Bundled SMS verification component; standard minification. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-C6wOkitS.js | AI (source-diff): ESM bundle of step3 component; standard output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-C4I4NaZN.js | AI (source-diff): ESM bundle variant; standard minified output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-B5Ev1nCT.js | AI (source-diff): ESM bundle of step2 component; standard output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-7ywB3IuB.js | AI (source-diff): ESM bundle of step1 component; standard output. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-BWApDyOk.cjs | AI (source-diff): Bundled Svelte component output; standard minification, not obfuscation. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-B9qtNXdE.cjs | AI (source-diff): Bundled component with i18n strings; standard minification. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-CLUW1_Ss.cjs | AI (source-diff): Bundled component with date-fns; standard minification. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-DuQiMg8u.cjs | AI (source-diff): Bundled component with i18n strings; standard minification. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Scoped corporate package; missing description is stable pattern. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-CIqQiJZi.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-AdY-ygv5.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library; consistent across all versions. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-BXBM8-6A.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-ClIjcJ8l.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-b1rbNBze.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerSmsVerificationForm-Bx7lBTRi.cjs | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-BNU8-hxb.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-Cmu-fwTG.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-dUJTbKi2.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-IbpEhuja.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-jv0Zt0Bp.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-BY2vb5X8.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-CZAxmL2d.js | AI (source-diff): Standard Rollup/Vite minified bundle output for this UI component library. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-CuyeIBrC.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Private org UI component library; no repo/deps/keywords is expected for this distribution pattern. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-VO_FBZTh.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep3-DY3-D4fI.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-BD0zNjPW.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep2-B3n9uQOv.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-D5gOjdkF.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormStep1-Ba-9pF62.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai | |
| source-diff | obfuscated-file:components/GeneralPlayerRegisterFormNd-j7To8dVU.js | AI (source-diff): Standard Vite/Rollup minified bundle output for a Svelte component; no malicious patterns in samples. | ai |
Versions (showing 27 of 234)
| Version | Deps | Published |
|---|---|---|
| 1.74.6 | 0 / 0 | |
| 1.74.5 | 0 / 0 | |
| 1.74.4 | 0 / 0 | |
| 1.74.3 | 0 / 0 | |
| 1.74.2 | 0 / 0 | |
| 1.74.1 | 0 / 0 | |
| 1.74.0 | 0 / 0 | |
| 1.73.2 | 0 / 0 | |
| 1.73.1 | 0 / 0 | |
| 1.73.0 | 0 / 0 | |
| 1.72.2 | 0 / 0 | |
| 1.72.1 | 0 / 0 | |
| 1.72.0 | 0 / 0 | |
| 1.71.1 | 0 / 0 | |
| 1.71.0 | 0 / 0 | |
| 1.70.1 | 0 / 0 | |
| 1.70.0 | 0 / 0 | |
| 1.69.3 | 0 / 0 | |
| 1.69.2 | 0 / 0 | |
| 1.69.0 | 0 / 0 | |
| 1.68.0 | 0 / 0 | |
| 1.67.3 | 0 / 0 | |
| 1.67.0 | 0 / 0 | |
| 1.66.2 | 0 / 0 | |
| 1.66.1 | 0 / 0 | |
| 1.66.0 | 0 / 0 | |
| 1.65.3 | 0 / 0 |
v1.74.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.69.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.68.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.67.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.67.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.66.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.