← Home

@cowprotocol/iframe-transport

23
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

fairlightethcowprotocol_devharisangfedgiacanxolin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:index.cjs AI (source-diff): index.cjs is a standard minified CJS bundle; content is readable iframe/postMessage transport logic with no malicious patterns. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher is confirmed by SLSA provenance attestation; consistent with org-level CI migration. ai
phantom-deps phantom-dep:tslib AI (phantom-deps): tslib is a well-known implicit TypeScript runtime dep; stable false positive for TS packages. ai
phantom-deps phantom-dep:@uniswap/sdk-core AI (phantom-deps): Peer/type dependency referenced in config; not a direct import pattern is expected. ai
phantom-deps phantom-dep:@cowprotocol/cow-sdk AI (phantom-deps): Same-org dependency; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@cowprotocol/sdk-bridging AI (phantom-deps): Same-org dependency; phantom-dep heuristic unreliable for monorepo packages. ai
phantom-deps phantom-dep:@web3-react/types AI (phantom-deps): Types-only dependency; phantom-dep false positive for type packages. ai
provenance missing-githead AI (provenance): SLSA attestation present; gitHead absence is cosmetic and doesn't undermine supply chain integrity for this package. ai
bogus-package bogus-package AI (bogus-package): Part of cowprotocol/cowswap monorepo; sparse README and missing keywords are typical for internal library packages. ai

Versions (showing 23 of 23)

Version Deps Published
2.3.2 2 / 0
2.3.1 2 / 0
2.3.0 2 / 0
2.2.6 2 / 0
2.2.5 2 / 0
2.2.4 2 / 0
2.2.3 2 / 0
2.2.2 2 / 0
2.2.1 2 / 0
2.1.0 2 / 0
2.0.13 2 / 0
2.0.12 2 / 0
2.0.11 2 / 0
2.0.10 2 / 0
2.0.9 7 / 0
2.0.8 2 / 0
2.0.7 2 / 0
2.0.6 2 / 0
2.0.5 2 / 0
2.0.4 2 / 0
2.0.3 2 / 0
2.0.2 2 / 0
1.2.0 0 / 0

v2.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.