@chain-registry/v2
Cosmos chain registry ⚛️
100
Versions
SEE LICENSE IN LICENSE
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
pyramationluca608zetazz
Keywords
chain-registryweb3cosmoscosmos-sdkinterchaintokens
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-tlds | AI (semgrep): Chain registry is a data package containing blockchain RPC endpoint URLs. TLDs like .xyz are legitimate validator domains, not C2 infrastructure. This pattern will always fire on chain registry data files. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP addresses in chain registry files are legitimate blockchain validator node endpoints, not malicious network requests. This is expected data content for a chain registry package. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @chain-registry/v2 cannot reasonably be confused with pg (PostgreSQL client). Levenshtein match is spurious for scoped packages. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @chain-registry/v2 cannot reasonably be confused with qs (query string parser). Levenshtein match is spurious for scoped packages. | ai |
Versions (showing 100 of 399)
Showing 100 of 399
Next page →