@exodus/ethereum-api
Transaction monitors, fee monitors, RPC with the blockchain node, and other networking code for Ethereum and EVM-based blockchains
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@exodus/key-utils | AI (phantom-deps): Same-org internal dep, likely used indirectly; not suspicious. | ai | |
| dependencies | unvetted-dep:@exodus/ethereumjs-util | AI (dependencies): First-party Exodus fork dependency, standard for this org. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Publisher is a known long-standing Exodus maintainer, not an unknown takeover. | ai | |
| phantom-deps | phantom-dep:make-concurrent | AI (phantom-deps): make-concurrent is a declared runtime dep; phantom-dep heuristic is a false positive here. | ai | |
| dependencies | unvetted-dep:@exodus/simple-retry | AI (dependencies): First-party Exodus utility; stable pattern across this package family. | ai | |
| dependencies | unvetted-dep:@exodus/crypto | AI (dependencies): First-party Exodus dependency; stable pattern across this package family. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Decodes ERC-20 token name bytes from contract call response; not a malicious payload pattern. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a transitive dep of socket.io-client; phantom-dep false positive for this package. | ai |
Versions (showing 28 of 28)
| Version | Deps | Published |
|---|---|---|
| 8.76.3 | 30 / 8 | |
| 8.76.1 | 30 / 8 | |
| 8.76.0 | 30 / 8 | |
| 8.73.1 | 29 / 7 | |
| 8.72.0 | 29 / 7 | |
| 8.71.3 | 29 / 7 | |
| 8.71.1 | 29 / 7 | |
| 8.61.3 | 28 / 7 | |
| 8.57.0 | 28 / 7 | |
| 8.56.0 | 28 / 7 | |
| 8.46.1 | 27 / 6 | |
| 8.46.0 | 27 / 6 | |
| 8.45.3 | 26 / 6 | |
| 8.45.0 | 26 / 6 | |
| 8.43.3 | 26 / 6 | |
| 8.43.1 | 26 / 6 | |
| 8.42.0 | 26 / 6 | |
| 8.41.0 | 26 / 6 | |
| 8.38.1 | 26 / 5 | |
| 8.38.0 | 26 / 5 | |
| 8.35.1 | 26 / 7 | |
| 8.35.0 | 26 / 7 | |
| 8.34.7 | 26 / 7 | |
| 8.34.6 | 26 / 7 | |
| 8.9.0 | 27 / 9 | |
| 8.7.1 | 26 / 10 | |
| 8.4.2 | 26 / 10 | |
| 8.4.1 | 26 / 10 |
v8.34.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (fboucquez) than the most recent previously approved version (joshuabot) on 2025-06-11, but fboucquez is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v8.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.7.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.4.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.