@audius/sp-actions
A utility for audius service providers to claim token rewards.
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Org transitioned to GitHub Actions CI publishing with SLSA attestation; legitimate automation pattern for AudiusProject. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Maintainers removed as part of org-wide shift to automated CI/CD publishing; consistent with publisher-changed finding. | ai | |
| dependencies | unvetted-dep:@truffle/hdwallet-provider | AI (dependencies): Well-known Truffle/Consensys HD wallet provider; expected dependency for a Web3/Ethereum-interacting package. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 1.0.32 | 5 / 0 | |
| 1.0.30 | 5 / 0 | |
| 1.0.29 | 5 / 0 | |
| 1.0.28 | 5 / 0 | |
| 1.0.27 | 5 / 0 | |
| 1.0.26 | 5 / 0 | |
| 1.0.25 | 5 / 0 | |
| 1.0.24 | 5 / 0 | |
| 1.0.23 | 5 / 0 | |
| 1.0.21 | 5 / 0 | |
| 1.0.19 | 5 / 0 | |
| 1.0.15 | 5 / 0 | |
| 1.0.14 | 5 / 0 | |
| 1.0.13 | 5 / 0 | |
| 1.0.12 | 5 / 0 | |
| 1.0.11 | 5 / 0 | |
| 1.0.10 | 5 / 0 | |
| 1.0.9 | 5 / 0 | |
| 1.0.8 | 5 / 0 | |
| 1.0.7 | 5 / 0 | |
| 1.0.5 | 5 / 0 | |
| 1.0.4 | 5 / 0 | |
| 1.0.3 | 5 / 0 | |
| 1.0.2 | 5 / 0 | |
| 1.0.1 | 5 / 0 |
v1.0.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.