@aave/react
The official React bindings for the Aave Protocol
23
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
sams_aavedonosonaumczukaavesomemiguel-martinez-aavempsc0xlochieaxongrothemnpm_avaralabs
Keywords
aaveaave-sdkaave-kitaave-protocolreacthooksdefide-fi
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation is a documented supply-chain improvement, not a compromise. | ai | |
| source-diff | obfuscated-file:dist/viem/index.cjs | AI (source-diff): Standard minified bundle output; sample shows normal React hooks and Aave SDK logic with no malicious patterns. | ai | |
| source-diff | obfuscated-file:dist/viem/index.js | AI (source-diff): Standard minified ESM bundle; sample shows normal Aave SDK imports and viem integration, no malicious patterns. | ai | |
| provenance | no-provenance | AI (provenance): Established Aave SDK package; lack of provenance is common and not a risk signal here. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 6.2.1 | 5 / 14 | |
| 6.2.0 | 5 / 14 | |
| 6.1.0 | 5 / 14 | |
| 4.1.1 | 5 / 14 | |
| 4.1.0 | 5 / 14 | |
| 4.0.4 | 5 / 14 | |
| 4.0.3 | 5 / 14 | |
| 4.0.2 | 5 / 14 | |
| 4.0.1 | 5 / 14 | |
| 4.0.0 | 5 / 14 | |
| 0.8.3 | 4 / 13 | |
| 0.8.2 | 4 / 13 | |
| 0.8.1 | 4 / 13 | |
| 0.8.0 | 4 / 13 | |
| 0.7.1 | 4 / 13 | |
| 0.6.1 | 4 / 13 | |
| 0.6.0 | 4 / 13 | |
| 0.5.0 | 4 / 12 | |
| 0.4.0 | 4 / 12 | |
| 0.3.1 | 4 / 12 | |
| 0.3.0 | 4 / 12 | |
| 0.2.0 | 4 / 12 | |
| 0.1.0 | 4 / 12 |
v6.2.1
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v6.2.0
1 finding
INFO
Has SLSA provenance attestation
provenance
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.