← Home

@chainsafe/lodestar

Command line interface for lodestar

36
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

wemeetagainmatthewkeil

Keywords

ethereumeth-consensusbeaconblockchain

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher changed to GitHub Actions with SLSA provenance attestation, indicating a legitimate migration to automated CI/CD publishing for this established ChainSafe package. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy reflects prior manual publishing cadence; transition to GitHub Actions CI/CD with SLSA attestation confirms legitimate automated publishing, not account takeover. ai
phantom-deps phantom-dep:prom-client AI (phantom-deps): prom-client is a legitimate metrics library used by the lodestar ecosystem; phantom detection likely misses ESM/monorepo import patterns. ai
phantom-deps phantom-dep:@chainsafe/ssz AI (phantom-deps): Same-org dependency (@chainsafe/ssz) used throughout the lodestar ecosystem; phantom detection likely misses indirect ESM usage patterns. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): The flagged IP 127.0.0.1:9596 is a localhost default for connecting to a local beacon node — standard and expected for a validator CLI tool. ai

Versions (showing 36 of 36)

Version Deps Published
1.44.0 32 / 15
1.43.0 35 / 14
1.42.0 35 / 14
1.41.1 35 / 14
1.41.0 35 / 14
1.40.0 35 / 14
1.39.1 35 / 14
1.39.0 35 / 14
1.38.0 34 / 6
1.37.0 34 / 6
1.36.0 35 / 6
1.34.1 34 / 6
1.34.0 34 / 6
1.33.0 35 / 7
1.32.0 35 / 7
1.31.0 35 / 7
1.30.0 34 / 6
1.29.0 35 / 7
1.28.1 35 / 7
1.28.0 35 / 7
1.27.1 35 / 7
1.27.0 35 / 7
1.26.0 35 / 7
1.25.0 35 / 7
1.24.0 35 / 7
1.23.1 35 / 7
1.23.0 35 / 7
1.22.0 35 / 7
1.21.0 35 / 7
1.20.2 36 / 7
1.20.1 36 / 7
1.20.0 36 / 7
1.19.0 36 / 7
1.18.1 36 / 7
1.18.0 36 / 7
1.17.0 36 / 6

v1.44.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.29.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.28.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.28.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.26.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.25.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.24.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.