@circle-fin/adapter-viem-v2
23
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
tomleicircleigaskin-circlecircle-npm-ci
Keywords
circlecircle-fincctpusdcstablecoinadaptersdktypescriptevmethereumviemcross-chainbridgebridge-kitapp-kitswap-kit
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| semgrep | semgrep:shady-links-raw-ip | AI (semgrep): Raw IP is 127.0.0.1:8545 in a JSDoc code example for local Anvil testnet — not a real network call. | ai | |
| phantom-deps | phantom-dep:@ethersproject/units | AI (phantom-deps): @ethersproject/units is a declared dep used transitively; phantom-dep heuristic fires as false positive here. | ai | |
| semgrep | semgrep:shady-links-tlds | AI (semgrep): Fires on blockchain RPC/explorer endpoint URLs in chain config data; not C2 infrastructure. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Legitimate bytes32-to-Solana address conversion using Buffer.from(hex,'hex') + bs58 encode; no malicious payload. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 1.14.0 | 10 / 0 | |
| 1.13.0 | 10 / 0 | |
| 1.12.1 | 9 / 0 | |
| 1.12.0 | 9 / 0 | |
| 1.11.2 | 7 / 0 | |
| 1.11.1 | 7 / 0 | |
| 1.11.0 | 7 / 0 | |
| 1.10.0 | 7 / 0 | |
| 1.9.0 | 7 / 0 | |
| 1.8.3 | 7 / 0 | |
| 1.8.2 | 7 / 0 | |
| 1.8.1 | 7 / 0 | |
| 1.8.0 | 7 / 0 | |
| 1.7.0 | 7 / 0 | |
| 1.6.0 | 7 / 0 | |
| 1.5.0 | 7 / 0 | |
| 1.4.0 | 7 / 0 | |
| 1.3.0 | 7 / 0 | |
| 1.2.0 | 7 / 0 | |
| 1.1.1 | 7 / 0 | |
| 1.1.0 | 7 / 0 | |
| 1.0.1 | 7 / 0 | |
| 1.0.0 | 7 / 0 |
v1.14.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.13.0
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.