@everymatrix/pam-player-profile-controller
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/esm/pam-player-profile-controller-8e8773cf.js | AI (source-diff): Standard Stencil.js minified build artifact; samples show legitimate widget code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/pam-player-profile-controller-d399eec2.js | AI (source-diff): Standard Stencil.js minified build artifact; samples show legitimate widget code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/pam-player-profile-controller/pam-player-profile-controller-8e8773cf.js | AI (source-diff): Standard Stencil.js minified build artifact; samples show legitimate widget code, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/pam-player-profile-controller/pam-player-profile-controller-0d279063.js | AI (source-diff): Standard Stencil.js minified bundle; same pattern as other @everymatrix packages. | ai | |
| source-diff | obfuscated-file:dist/esm/pam-player-profile-controller-0d279063.js | AI (source-diff): Standard Stencil.js minified ESM bundle; long lines are bundled/minified output, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/cjs/pam-player-profile-controller-cb48c67b.js | AI (source-diff): Standard Stencil.js minified CJS bundle; long lines are bundled/minified output, not obfuscation. | ai | |
| provenance | publisher-changed | AI (provenance): New publisher adrian.pripon has 11k+ approved packages in the same @everymatrix org; consistent with internal team transition. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent with the @everymatrix component library publishing pattern across all versions. | ai | |
| provenance | no-provenance | AI (provenance): No provenance is consistent across all 284 versions; not a per-version risk signal for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Enterprise scoped component package with 284 versions; sparse metadata is a consistent pattern across the entire package family. | ai |
Versions (showing 35 of 243)
| Version | Deps | Published |
|---|---|---|
| 1.76.14 | 0 / 0 | |
| 1.76.13 | 0 / 0 | |
| 1.76.12 | 0 / 0 | |
| 1.76.11 | 0 / 0 | |
| 1.76.10 | 0 / 0 | |
| 1.76.9 | 0 / 0 | |
| 1.76.8 | 0 / 0 | |
| 1.76.7 | 0 / 0 | |
| 1.76.6 | 0 / 0 | |
| 1.76.5 | 0 / 0 | |
| 1.76.4 | 0 / 0 | |
| 1.76.3 | 0 / 0 | |
| 1.76.1 | 0 / 0 | |
| 1.76.0 | 0 / 0 | |
| 1.75.1 | 0 / 0 | |
| 1.75.0 | 0 / 0 | |
| 1.74.10 | 0 / 0 | |
| 1.74.8 | 0 / 0 | |
| 1.74.7 | 0 / 0 | |
| 1.74.6 | 0 / 0 | |
| 1.74.5 | 0 / 0 | |
| 1.74.4 | 0 / 0 | |
| 1.74.3 | 0 / 0 | |
| 1.74.2 | 0 / 0 | |
| 1.74.1 | 0 / 0 | |
| 1.74.0 | 0 / 0 | |
| 1.73.2 | 0 / 0 | |
| 1.73.1 | 0 / 0 | |
| 1.73.0 | 0 / 0 | |
| 1.72.2 | 0 / 0 | |
| 1.72.1 | 0 / 0 | |
| 1.72.0 | 0 / 0 | |
| 1.71.1 | 0 / 0 | |
| 1.71.0 | 0 / 0 | |
| 1.70.1 | 0 / 0 |
v1.76.14
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.13
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.12
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.11
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.9
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.76.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.75.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.10
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.8
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.74.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.73.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.72.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.71.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.70.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.