@aave/types
2
Versions
—
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
sams_aavedonosonaumczukaavesomefranky_armengol_carmiguel-martinez-aavempsc0xlochieaxongrothemharshbhatt18cnaldia_paweljoshstevens19juangmnpm_avaralabs
v0.3.0
2 findings
HIGH
Provenance attestation missing — previous versions had it
provenance
This version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. The axios attack (March 2026) exhibited exactly this pattern.
INFO
Publisher changed: GitHub Actions → grothem (on 2026-07-08, known maintainer)
provenance
This version was published by a different npm account (grothem) than the most recent previously approved version (GitHub Actions) on 2026-07-08, but grothem is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.