← Home

@eth-optimism/common-ts

39
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

optibotkelvinfichter

Keywords

optimismethereumcommontypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:preinstall AI (install-scripts): only-allow pnpm enforcement, not arbitrary code execution. ai
provenance publisher-changed-stale AI (provenance): Long-stable publisher change, not consistent with account takeover. ai
phantom-deps phantom-dep:qs AI (phantom-deps): qs used for querystring handling in this Express-based package; likely used indirectly/config. ai
maintainer-change maintainer-added AI (maintainer-change): optibot is a trusted bulk-republish account with strong track record across many packages. ai
provenance no-provenance AI (provenance): Established Optimism monorepo package; lack of provenance is consistent across all versions and is not a security concern for this well-known project. ai

Versions (showing 39 of 39)

Version Deps Published
0.8.9 16 / 8
0.8.8 16 / 8
0.8.7 16 / 8
0.8.2 16 / 8
0.8.1 17 / 8
0.8.0 17 / 8
0.7.1 17 / 8
0.7.0 17 / 8
0.6.8 17 / 8
0.6.7 17 / 8
0.6.6 17 / 8
0.6.5 17 / 8
0.6.4 17 / 8
0.6.3 17 / 8
0.6.2 17 / 8
0.6.1 17 / 8
0.6.0 17 / 8
0.5.0 17 / 8
0.4.0 17 / 8
0.3.1 17 / 8
0.3.0 17 / 8
0.2.10 13 / 7
0.2.9 13 / 7
0.2.8 13 / 25
0.2.7 13 / 25
0.2.6 13 / 25
0.2.5 13 / 25
0.2.4 13 / 25
0.2.3 13 / 25
0.2.2 13 / 25
0.2.1 6 / 24
0.2.0 6 / 24
0.1.6 6 / 24
0.1.5 6 / 24
0.1.4 6 / 22
0.1.3 6 / 16
0.1.2 6 / 16
0.1.1 5 / 8
0.1.0 5 / 8

v0.8.8

2 findings
HIGH Package has 'preinstall' script install-scripts

Script: npx only-allow pnpm

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.8.7

4 findings
HIGH Package has 'preinstall' script install-scripts

Script: npx only-allow pnpm

HIGH Missing gitHead — previous versions had it provenance

This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: optibot.

MEDIUM Publisher changed: karlfloersch → optibot (on 2023-09-28, unremoved on npm for 1026d) provenance

This version was published by a different npm account (optibot) than the most recent previously approved version (karlfloersch) on 2023-09-28. It has since remained available on npm for 1026 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.2

2 findings
MEDIUM Publisher changed: karlfloersch → optibot (on 2023-06-20, unremoved on npm for 1127d) provenance

This version was published by a different npm account (optibot) than the most recent previously approved version (karlfloersch) on 2023-06-20. It has since remained available on npm for 1127 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.1

2 findings
MEDIUM Publisher changed: karlfloersch → optibot (on 2023-03-16, unremoved on npm for 1223d) provenance

This version was published by a different npm account (optibot) than the most recent previously approved version (karlfloersch) on 2023-03-16. It has since remained available on npm for 1223 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.8.0

2 findings
MEDIUM Publisher changed: karlfloersch → optibot (on 2023-02-15, unremoved on npm for 1252d) provenance

This version was published by a different npm account (optibot) than the most recent previously approved version (karlfloersch) on 2023-02-15. It has since remained available on npm for 1252 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.1

2 findings
MEDIUM Publisher changed: karlfloersch → optibot (on 2023-01-23, unremoved on npm for 1274d) provenance

This version was published by a different npm account (optibot) than the most recent previously approved version (karlfloersch) on 2023-01-23. It has since remained available on npm for 1274 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.7.0

2 findings
MEDIUM Publisher changed: karlfloersch → optibot (on 2023-01-04, unremoved on npm for 1293d) provenance

This version was published by a different npm account (optibot) than the most recent previously approved version (karlfloersch) on 2023-01-04. It has since remained available on npm for 1293 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.2.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.