← Home

@everymatrix/general-registration-hsl

22
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

clokzeoleksandr.v.stepanovtaras.maksymivradu.besliu.emnatalya.anisimovaemfe_releasemariana.gheorgheadrian.priponandriizadvirnyiraulvasileemstrulea.sebastianstefan.vladdragos.bodeamaria.bumbarstefanaocatalinpoclidliviuclement.everymatrix

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/cjs/general-registration-hsl-34921616.js AI (source-diff): Standard Stencil.js minified bundle output; content is readable i18n strings and component logic, not obfuscation. ai
source-diff obfuscated-file:dist/general-registration-hsl/general-registration-hsl-e1d89023.js AI (source-diff): Minified web component bundle consistent with Stencil.js build output for this package family. ai
source-diff obfuscated-file:dist/esm/general-registration-hsl-e1d89023.js AI (source-diff): Standard Stencil.js minified ESM bundle; no malicious patterns in sampled content. ai
source-diff obfuscated-file:dist/general-registration-hsl/general-registration-hsl-4dbf0a6a.js AI (source-diff): Standard Vite/Rollup minified bundle output; readable error strings and DOM helpers confirm legitimate build artifact. ai
source-diff obfuscated-file:dist/cjs/PlayerConsents-Duni8Aqx-1d0f4f21.js AI (source-diff): Standard minified CJS bundle; Svelte runtime patterns visible in sample, no obfuscation indicators. ai
source-diff obfuscated-file:dist/esm/PlayerConsents-Duni8Aqx-dd7cf325.js AI (source-diff): Standard minified ESM bundle; same Svelte runtime pattern as CJS counterpart. ai
source-diff obfuscated-file:dist/general-registration-hsl/PlayerConsents-Duni8Aqx-dd7cf325.js AI (source-diff): Standard minified bundle; readable DOM/event helper functions confirm legitimate build output. ai
source-diff obfuscated-file:dist/esm/PlayerConsents-BtzEjirY-52f88049.js AI (source-diff): Standard minified Svelte/Vite build output; not obfuscated malware. ai
source-diff obfuscated-file:dist/general-registration-hsl/PlayerConsents-BtzEjirY-52f88049.js AI (source-diff): Standard minified Svelte/Vite build output; not obfuscated malware. ai
source-diff obfuscated-file:dist/general-registration-hsl/general-registration-hsl-aa81d758.js AI (source-diff): Standard minified bundle with readable i18n error strings; not obfuscated malware. ai
source-diff obfuscated-file:dist/cjs/PlayerConsents-BtzEjirY-0870c312.js AI (source-diff): Standard minified Svelte/Vite build output; not obfuscated malware. ai
npm-metadata no-description AI (npm-metadata): Consistent pattern across the @everymatrix package family; not a malware indicator here. ai
provenance no-provenance AI (provenance): Internal corporate package published to JFrog Artifactory; provenance attestation not expected. ai
bogus-package bogus-package AI (bogus-package): Established @everymatrix scoped package family with 265 versions; stub/placeholder releases are normal for this publisher's widget pipeline. ai

Versions (showing 22 of 229)

Version Deps Published
0.3.3 0 / 0
0.3.2 0 / 0
0.3.1 0 / 0
0.3.0 0 / 0
0.2.10 0 / 0
0.2.9 0 / 0
0.2.8 0 / 0
0.2.7 0 / 0
0.2.6 0 / 0
0.2.5 0 / 0
0.2.4 0 / 0
0.2.3 0 / 0
0.2.1 0 / 0
0.2.0 0 / 0
0.1.1 0 / 0
0.1.0 0 / 0
0.0.7 0 / 0
0.0.5 0 / 0
0.0.4 0 / 0
0.0.3 0 / 0
0.0.2 0 / 0
0.0.1 0 / 0

v0.3.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.