@exodus/ethereum-api
Transaction monitors, fee monitors, RPC with the blockchain node, and other networking code for Ethereum and EVM-based blockchains
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:make-concurrent | AI (phantom-deps): make-concurrent is a declared runtime dep; phantom-dep heuristic is a false positive here. | ai | |
| dependencies | unvetted-dep:@exodus/crypto | AI (dependencies): First-party Exodus dependency; stable pattern across this package family. | ai | |
| dependencies | unvetted-dep:@exodus/simple-retry | AI (dependencies): First-party Exodus utility; stable pattern across this package family. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Decodes ERC-20 token name bytes from contract call response; not a malicious payload pattern. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): ws is a transitive dep of socket.io-client; phantom-dep false positive for this package. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 8.76.3 | 30 / 8 | |
| 8.76.1 | 30 / 8 | |
| 8.76.0 | 30 / 8 | |
| 8.73.1 | 29 / 7 | |
| 8.72.0 | 29 / 7 | |
| 8.71.3 | 29 / 7 | |
| 8.71.1 | 29 / 7 | |
| 8.61.3 | 28 / 7 | |
| 8.57.0 | 28 / 7 | |
| 8.56.0 | 28 / 7 | |
| 8.46.1 | 27 / 6 | |
| 8.46.0 | 27 / 6 | |
| 8.45.3 | 26 / 6 | |
| 8.45.0 | 26 / 6 | |
| 8.43.3 | 26 / 6 | |
| 8.43.1 | 26 / 6 | |
| 8.42.0 | 26 / 6 | |
| 8.41.0 | 26 / 6 | |
| 8.38.1 | 26 / 5 | |
| 8.38.0 | 26 / 5 | |
| 8.35.1 | 26 / 7 | |
| 8.35.0 | 26 / 7 | |
| 8.34.6 | 26 / 7 |
v8.76.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.76.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.76.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.73.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.72.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.71.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.61.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v8.57.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.56.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.46.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.46.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.45.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.45.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.43.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.43.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.42.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.41.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.38.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.38.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.35.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.35.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v8.34.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.