@chain-registry/v2
Cosmos chain registry ⚛️
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-tlds | AI (semgrep): Chain registry is a data package containing blockchain RPC endpoint URLs. TLDs like .xyz are legitimate validator domains, not C2 infrastructure. This pattern will always fire on chain registry data files. | ai | |
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP addresses in chain registry files are legitimate blockchain validator node endpoints, not malicious network requests. This is expected data content for a chain registry package. | ai | |
| typosquat | typosquat.levenshtein:pg | AI (typosquat): Scoped package @chain-registry/v2 cannot reasonably be confused with pg (PostgreSQL client). Levenshtein match is spurious for scoped packages. | ai | |
| typosquat | typosquat.levenshtein:qs | AI (typosquat): Scoped package @chain-registry/v2 cannot reasonably be confused with qs (query string parser). Levenshtein match is spurious for scoped packages. | ai |
Versions (showing 99 of 399)
| Version | Deps | Published |
|---|---|---|
| 1.65.43 | 1 / 2 | |
| 1.65.42 | 1 / 2 | |
| 1.65.41 | 1 / 2 | |
| 1.65.40 | 1 / 2 | |
| 1.65.39 | 1 / 2 | |
| 1.65.38 | 1 / 2 | |
| 1.65.37 | 1 / 2 | |
| 1.65.36 | 1 / 2 | |
| 1.65.35 | 1 / 2 | |
| 1.65.34 | 1 / 2 | |
| 1.65.33 | 1 / 2 | |
| 1.65.32 | 1 / 2 | |
| 1.65.31 | 1 / 2 | |
| 1.65.30 | 1 / 2 | |
| 1.65.29 | 1 / 2 | |
| 1.65.28 | 1 / 2 | |
| 1.65.27 | 1 / 2 | |
| 1.65.26 | 1 / 2 | |
| 1.65.25 | 1 / 2 | |
| 1.65.24 | 1 / 2 | |
| 1.65.23 | 1 / 2 | |
| 1.65.22 | 1 / 2 | |
| 1.65.21 | 1 / 2 | |
| 1.65.20 | 1 / 2 | |
| 1.65.19 | 1 / 2 | |
| 1.65.18 | 1 / 2 | |
| 1.65.17 | 1 / 2 | |
| 1.65.16 | 1 / 2 | |
| 1.65.15 | 1 / 2 | |
| 1.65.14 | 1 / 2 | |
| 1.65.13 | 1 / 2 | |
| 1.65.12 | 1 / 2 | |
| 1.65.11 | 1 / 2 | |
| 1.65.10 | 1 / 2 | |
| 1.65.9 | 1 / 2 | |
| 1.65.8 | 1 / 2 | |
| 1.65.7 | 1 / 2 | |
| 1.65.6 | 1 / 2 | |
| 1.65.5 | 1 / 2 | |
| 1.65.4 | 1 / 2 | |
| 1.65.3 | 1 / 2 | |
| 1.65.2 | 1 / 2 | |
| 1.65.1 | 1 / 2 | |
| 1.65.0 | 1 / 2 | |
| 1.64.11 | 1 / 2 | |
| 1.64.10 | 1 / 2 | |
| 1.64.9 | 1 / 2 | |
| 1.64.8 | 1 / 2 | |
| 1.64.7 | 1 / 2 | |
| 1.64.6 | 1 / 2 | |
| 1.64.5 | 1 / 2 | |
| 1.64.4 | 1 / 2 | |
| 1.64.3 | 1 / 2 | |
| 1.64.2 | 1 / 2 | |
| 1.64.1 | 1 / 2 | |
| 1.64.0 | 1 / 2 | |
| 1.63.10 | 1 / 2 | |
| 1.63.9 | 1 / 2 | |
| 1.63.8 | 1 / 2 | |
| 1.63.7 | 1 / 2 | |
| 1.63.6 | 1 / 2 | |
| 1.63.5 | 1 / 2 | |
| 1.63.4 | 1 / 2 | |
| 1.63.3 | 1 / 2 | |
| 1.63.2 | 1 / 2 | |
| 1.63.1 | 1 / 2 | |
| 1.63.0 | 1 / 2 | |
| 1.62.0 | 1 / 2 | |
| 1.61.4 | 1 / 2 | |
| 1.61.3 | 1 / 2 | |
| 1.61.2 | 1 / 2 | |
| 1.61.1 | 1 / 2 | |
| 1.61.0 | 1 / 2 | |
| 1.60.0 | 1 / 2 | |
| 1.59.0 | 1 / 2 | |
| 1.58.0 | 1 / 2 | |
| 1.57.0 | 1 / 2 | |
| 1.56.0 | 1 / 2 | |
| 1.55.0 | 1 / 2 | |
| 1.54.0 | 1 / 2 | |
| 1.53.1 | 1 / 2 | |
| 1.53.0 | 1 / 2 | |
| 1.52.0 | 1 / 2 | |
| 1.51.0 | 1 / 2 | |
| 1.50.0 | 1 / 2 | |
| 1.49.2 | 1 / 2 | |
| 1.49.1 | 1 / 2 | |
| 1.49.0 | 1 / 2 | |
| 1.48.8 | 1 / 2 | |
| 1.48.7 | 1 / 2 | |
| 1.48.6 | 1 / 2 | |
| 1.48.5 | 1 / 2 | |
| 1.48.4 | 1 / 2 | |
| 1.48.3 | 1 / 2 | |
| 1.48.2 | 1 / 2 | |
| 1.48.1 | 1 / 2 | |
| 1.48.0 | 1 / 2 | |
| 1.47.0 | 1 / 2 | |
| 1.46.0 | 1 / 2 |
v1.65.43
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.42
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.41
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.40
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.39
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.38
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.37
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.36
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.35
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.34
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.33
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.32
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.65.31
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.30
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.29
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.28
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.27
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.26
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.25
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.24
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.23
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.22
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.21
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.20
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.19
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.12
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.65.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.11
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.64.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.63.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.62.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.61.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.61.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.61.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.61.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.61.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.60.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.59.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.58.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.57.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.56.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.55.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.54.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.53.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.52.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.51.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.50.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.49.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.8
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.48.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.47.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.