@chain-registry/workflows
Chain Registry Workflows
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:schema-typescript | AI (dependencies): schema-typescript is a companion tooling package in the same ecosystem; consistent with the package's TypeScript code generation workflow. | ai | |
| dependencies | unvetted-dep:json-schema-patch | AI (dependencies): json-schema-patch is a pinned utility dependency used in chain-registry workflows; no security concerns identified. | ai | |
| dependencies | unvetted-dep:file-ts | AI (dependencies): file-ts appears to be a companion package in the same ecosystem by the same publisher (pyramation); stable tooling dependency for chain-registry workflows. | ai | |
| dependencies | unvetted-dep:strfy-js | AI (dependencies): strfy-js is a utility package consistent with the chain-registry build toolchain by the same publisher; no malicious signals. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): bignumber.js is declared in package.json dependencies; phantom flag reflects config-driven usage pattern typical of this package. | ai | |
| phantom-deps | phantom-dep:sha.js | AI (phantom-deps): sha.js is declared in package.json dependencies; phantom flag is a static analysis artifact for this workflow/build-tooling package. | ai | |
| phantom-deps | phantom-dep:file-ts | AI (phantom-deps): file-ts is declared in package.json dependencies; phantom flag reflects config-driven usage pattern typical of this package. | ai | |
| phantom-deps | phantom-dep:minimatch | AI (phantom-deps): minimatch is declared in package.json dependencies; phantom flag is a static analysis artifact for this workflow/build-tooling package. | ai | |
| dependencies | unvetted-dep:@chain-registry/interfaces | AI (dependencies): First-party dependency from the same chain-registry monorepo; not a third-party risk. | ai | |
| provenance | no-provenance | AI (provenance): Established publisher with 4093 approved versions; lack of provenance is consistent across the entire chain-registry ecosystem and is not a meaningful risk signal here. | ai |
Versions (showing 51 of 544)
| Version | Deps | Published |
|---|---|---|
| 1.53.389 | 13 / 2 | |
| 1.53.388 | 13 / 2 | |
| 1.53.387 | 13 / 2 | |
| 1.53.386 | 13 / 2 | |
| 1.53.385 | 13 / 2 | |
| 1.53.384 | 13 / 2 | |
| 1.53.383 | 13 / 2 | |
| 1.53.382 | 13 / 2 | |
| 1.53.381 | 13 / 2 | |
| 1.53.380 | 13 / 2 | |
| 1.53.379 | 13 / 2 | |
| 1.53.378 | 13 / 2 | |
| 1.53.377 | 13 / 2 | |
| 1.53.376 | 13 / 2 | |
| 1.53.375 | 13 / 2 | |
| 1.53.374 | 13 / 2 | |
| 1.53.373 | 13 / 2 | |
| 1.53.372 | 13 / 2 | |
| 1.53.371 | 13 / 2 | |
| 1.53.370 | 13 / 2 | |
| 1.53.369 | 13 / 2 | |
| 1.53.368 | 13 / 2 | |
| 1.53.367 | 13 / 2 | |
| 1.53.366 | 13 / 2 | |
| 1.53.365 | 13 / 2 | |
| 1.53.364 | 13 / 2 | |
| 1.53.363 | 13 / 2 | |
| 1.53.362 | 13 / 2 | |
| 1.53.361 | 13 / 2 | |
| 1.53.360 | 13 / 2 | |
| 1.53.359 | 13 / 2 | |
| 1.53.358 | 13 / 2 | |
| 1.53.357 | 13 / 2 | |
| 1.53.356 | 13 / 2 | |
| 1.53.355 | 13 / 2 | |
| 1.53.354 | 13 / 2 | |
| 1.53.353 | 13 / 2 | |
| 1.53.352 | 13 / 2 | |
| 1.53.351 | 13 / 2 | |
| 1.53.350 | 13 / 2 | |
| 1.53.349 | 13 / 2 | |
| 1.53.348 | 13 / 2 | |
| 1.53.347 | 13 / 2 | |
| 1.53.346 | 13 / 2 | |
| 1.53.345 | 13 / 2 | |
| 1.53.344 | 13 / 2 | |
| 1.53.343 | 13 / 2 | |
| 1.53.342 | 13 / 2 | |
| 1.53.341 | 13 / 2 | |
| 1.53.340 | 13 / 2 | |
| 1.53.339 | 13 / 2 |
v1.53.389
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.388
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.387
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.386
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.385
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.384
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.383
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.382
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.381
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.380
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.379
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.378
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.377
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.376
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.375
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.374
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.373
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.372
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.53.371
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.