web3-shh
2
Versions
—
License
Yes
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
luu-alexmpetrunicjdevcsgregthegreek
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| install-scripts | install-script:postinstall | AI (install-scripts): Postinstall is a harmless deprecation warning echo statement with no code execution, network access, or file system changes. Safe for this package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Templated name pattern reflects the web3.js monorepo convention (web3-* packages); not spam. No keywords is minor and consistent with monorepo sub-packages. | ai |
v1.10.4
2 findings
HIGH
Package has 'postinstall' script
install-scripts
Script: echo "WARNING: the web3-shh api will be deprecated in the next version"
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.10.3
2 findings
HIGH
Package has 'postinstall' script
install-scripts
Script: echo "WARNING: the web3-shh api will be deprecated in the next version"
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.