← Home

@cowprotocol/events

24
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

fairlightethcowprotocol_devharisangfedgiacanxolin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a known implicit runtime dependency for TypeScript-compiled packages. ai
phantom-deps phantom-dep:@uniswap/sdk-core AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@web3-react/types AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation is a legitimate and more secure publish flow for this org. ai
phantom-deps phantom-dep:eventemitter3 AI (phantom-deps): Referenced in config files; phantom-dep heuristic false positive for this package. ai
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is superseded by Sigstore attestation for this package. ai
bogus-package bogus-package AI (bogus-package): Internal library package in a monorepo; sparse README and no keywords are expected for org-internal libs. ai

Versions (showing 24 of 24)

Version Deps Published
4.8.0 3 / 0
4.7.1 3 / 0
4.7.0 3 / 0
4.6.0 3 / 0
4.5.0 3 / 0
4.4.1 3 / 0
4.4.0 3 / 0
4.3.1 3 / 0
4.3.0 3 / 0
4.2.1 3 / 0
4.2.0 3 / 0
4.1.2 3 / 0
4.1.1 3 / 0
4.1.0 3 / 0
4.0.2 3 / 0
4.0.1 7 / 0
4.0.0 3 / 0
3.4.0 3 / 0
3.3.2 3 / 0
3.3.1 3 / 0
3.3.0 3 / 0
3.2.0 3 / 0
3.1.0 3 / 0
2.1.0 1 / 0

v4.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.