← Home

@blockrun/clawrouter

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

killerqueenandy1bcmax

Keywords

llmroutersmart-routingaiopenclawblockrunx402usdccost-optimizationopenaianthropicgeminideepseekusdc-hackathon-winneragentic-commerce

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Growth matches bundling of newly added Polymarket/x402/viem deps. ai
source-diff encoded-string-file:dist/cli.js AI (source-diff): Long hex strings are EVM bytecode constants from viem library (deployless call, multicall3); not obfuscated payloads. ai
source-diff encoded-string-file:dist/index.js AI (source-diff): Same viem EVM bytecode constants; stable false positive for this blockchain routing package. ai
phantom-deps phantom-dep:@x402/core AI (phantom-deps): Part of the @x402 micropayment suite; referenced in config/plugin files. Stable false positive for this package's architecture. ai
phantom-deps phantom-dep:@solana/kit AI (phantom-deps): Config-referenced dep for Solana payment support; stable false positive for this package. ai
phantom-deps phantom-dep:@scure/bip32 AI (phantom-deps): Config-referenced cryptographic dep; stable false positive for this package. ai
phantom-deps phantom-dep:viem AI (phantom-deps): viem is an EVM library used in config/plugin context; stable false positive for this package. ai
phantom-deps phantom-dep:@scure/bip39 AI (phantom-deps): Config-referenced cryptographic dep; stable false positive for this package. ai
phantom-deps phantom-dep:@x402/evm AI (phantom-deps): Deps are referenced in config/plugin files for dynamic loading in the openclaw plugin architecture; not a real phantom dep for this package. ai
phantom-deps phantom-dep:@x402/svm AI (phantom-deps): Same as @x402/evm — config-referenced dep for plugin architecture, stable false positive. ai
phantom-deps phantom-dep:@x402/fetch AI (phantom-deps): Config-referenced dep for x402 payment protocol integration; stable false positive for this package. ai
dependencies unvetted-peer-dep:openclaw AI (dependencies): openclaw is an optional peer dep from the same BlockRun ecosystem; it's also a devDependency, indicating intentional use. Stable false positive for this package. ai

Versions (showing 51 of 408)

View all versions
Version Deps Published
0.12.232 16 / 9
0.12.231 16 / 9
0.12.230 16 / 9
0.12.229 16 / 9
0.12.228 16 / 9
0.12.227 16 / 9
0.12.226 16 / 9
0.12.225 16 / 9
0.12.224 16 / 9
0.12.223 16 / 9
0.12.222 16 / 9
0.12.221 16 / 9
0.12.220 16 / 9
0.12.219 10 / 9
0.12.218 10 / 9
0.12.217 10 / 9
0.12.216 10 / 9
0.12.215 9 / 9
0.12.214 9 / 9
0.12.213 9 / 9
0.12.212 9 / 9
0.12.211 9 / 9
0.12.210 9 / 9
0.12.209 9 / 9
0.12.208 9 / 9
0.12.207 9 / 9
0.12.206 9 / 9
0.12.205 8 / 9
0.12.204 8 / 9
0.12.203 8 / 9
0.12.202 8 / 9
0.12.201 8 / 9
0.12.200 8 / 9
0.12.199 8 / 9
0.12.198 8 / 9
0.12.197 8 / 9
0.12.196 8 / 9
0.12.195 8 / 9
0.12.194 8 / 9
0.12.193 8 / 9
0.12.192 8 / 9
0.12.191 8 / 9
0.12.190 8 / 9
0.12.189 8 / 9
0.12.188 8 / 9
0.12.187 8 / 9
0.12.186 8 / 9
0.12.185 8 / 9
0.12.184 8 / 9
0.12.183 8 / 9
0.12.182 8 / 9

v0.12.232

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.231

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.230

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.229

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.228

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.227

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.226

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.225

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.224

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.223

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.222

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.221

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.220

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.219

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.218

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.217

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.216

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.215

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.12.214

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.