← Home

@exodus/ethereum-plugin

Ethereum plugin for Exodus SDK powered wallets

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

joshuabot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps are first-party @exodus/* packages or common small utils, part of a refactor. ai
dependencies unvetted-dep:@exodus/ethereumjs-util AI (dependencies): Official Exodus-scoped fork of ethereumjs-util, consistent with rest of dependency tree. ai
provenance publisher-changed AI (provenance): Exodus org migrated to GitHub Actions publishing; consistent with their CI/CD workflow across packages. ai
maintainer-change maintainer-removed AI (maintainer-change): Paired with maintainer-added; org-level rotation, not a hostile takeover signal. ai
maintainer-change maintainer-added AI (maintainer-change): Exodus org team rotation; consistent with internal maintainer management across their package portfolio. ai
dependencies unvetted-dep:@exodus/simple-retry AI (dependencies): First-party @exodus scoped package; consistent with Exodus Movement's internal dependency pattern. ai
bogus-package bogus-package AI (bogus-package): Scoped Exodus SDK package; sparse README/no keywords is a style choice, not spam. ai
provenance no-provenance AI (provenance): Provenance explicitly disabled in publishConfig; consistent across all Exodus packages. ai

Versions (showing 51 of 59)

View all versions
Version Deps Published
2.33.1 11 / 10
2.31.0 11 / 10
2.30.4 11 / 10
2.30.3 11 / 10
2.30.2 11 / 10
2.30.1 11 / 8
2.30.0 11 / 8
2.29.0 11 / 8
2.28.1 11 / 8
2.25.0 11 / 8
2.24.0 10 / 8
2.23.3 10 / 8
2.23.1 9 / 8
2.21.0 8 / 9
2.20.1 8 / 9
2.20.0 8 / 8
2.19.3 8 / 8
2.19.2 8 / 8
2.19.0 8 / 8
2.18.0 8 / 8
2.17.1 8 / 8
2.17.0 8 / 8
2.16.4 8 / 8
2.16.3 8 / 8
2.16.2 8 / 8
2.16.1 8 / 8
2.16.0 8 / 8
2.15.1 8 / 7
2.15.0 8 / 7
2.14.2 8 / 7
2.14.1 8 / 7
2.14.0 8 / 7
2.13.0 8 / 7
2.12.1 8 / 7
2.12.0 8 / 7
2.11.0 8 / 6
2.10.1 8 / 6
2.10.0 8 / 6
2.9.0 8 / 6
2.8.0 8 / 6
2.7.6 8 / 6
2.7.5 8 / 6
2.7.4 8 / 5
2.7.3 8 / 5
2.7.2 8 / 3
2.7.1 8 / 3
2.7.0 8 / 3
2.6.0 8 / 3
2.5.0 9 / 3
2.4.0 9 / 3
2.3.0 5 / 6

v2.33.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.31.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.30.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.30.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.30.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.29.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.17.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.16.3

2 findings
MEDIUM Publisher changed: joshuabot → GitHub Actions (on 2025-10-20, unremoved on npm for 270d) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (joshuabot) on 2025-10-20. It has since remained available on npm for 270 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.16.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.15.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.14.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.13.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.12.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.11.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.10.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.9.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.7.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.6.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.