← Home

@1inch/cross-chain-sdk

Sdk for creating atomic swaps through 1inch

9
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

phantomydnkrboktv-inchsevenswen1inch-robot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:ecies-25519 AI (dependencies): ecies-25519 is a legitimate ECIES cryptography library; appropriate for a cross-chain swap SDK context. ai
phantom-deps phantom-dep:ws AI (phantom-deps): ws is a declared runtime dep used via config/indirect import; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:axios AI (phantom-deps): axios is a declared runtime dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit TypeScript runtime dep; stable false positive. ai
phantom-deps phantom-dep:ecies-25519 AI (phantom-deps): Declared runtime dep; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@types/bn.js AI (phantom-deps): Type-only package loaded by convention; stable false positive. ai

Versions (showing 9 of 9)

Version Deps Published
2.1.2 13 / 32
2.1.1 13 / 32
2.1.0 13 / 32
2.0.5 13 / 32
2.0.4 13 / 32
2.0.3 13 / 32
2.0.2 13 / 32
2.0.1 13 / 33
2.0.0 13 / 33

v2.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.