@exodus/ethereum-plugin
Ethereum plugin for Exodus SDK powered wallets
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New deps are first-party @exodus/* packages or common small utils, part of a refactor. | ai | |
| dependencies | unvetted-dep:@exodus/ethereumjs-util | AI (dependencies): Official Exodus-scoped fork of ethereumjs-util, consistent with rest of dependency tree. | ai | |
| provenance | publisher-changed | AI (provenance): Exodus org migrated to GitHub Actions publishing; consistent with their CI/CD workflow across packages. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Paired with maintainer-added; org-level rotation, not a hostile takeover signal. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Exodus org team rotation; consistent with internal maintainer management across their package portfolio. | ai | |
| dependencies | unvetted-dep:@exodus/simple-retry | AI (dependencies): First-party @exodus scoped package; consistent with Exodus Movement's internal dependency pattern. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Scoped Exodus SDK package; sparse README/no keywords is a style choice, not spam. | ai | |
| provenance | no-provenance | AI (provenance): Provenance explicitly disabled in publishConfig; consistent across all Exodus packages. | ai |
Versions (showing 59 of 59)
| Version | Deps | Published |
|---|---|---|
| 2.33.1 | 11 / 10 | |
| 2.31.0 | 11 / 10 | |
| 2.30.4 | 11 / 10 | |
| 2.30.3 | 11 / 10 | |
| 2.30.2 | 11 / 10 | |
| 2.30.1 | 11 / 8 | |
| 2.30.0 | 11 / 8 | |
| 2.29.0 | 11 / 8 | |
| 2.28.1 | 11 / 8 | |
| 2.25.0 | 11 / 8 | |
| 2.24.0 | 10 / 8 | |
| 2.23.3 | 10 / 8 | |
| 2.23.1 | 9 / 8 | |
| 2.21.0 | 8 / 9 | |
| 2.20.1 | 8 / 9 | |
| 2.20.0 | 8 / 8 | |
| 2.19.3 | 8 / 8 | |
| 2.19.2 | 8 / 8 | |
| 2.19.0 | 8 / 8 | |
| 2.18.0 | 8 / 8 | |
| 2.17.1 | 8 / 8 | |
| 2.17.0 | 8 / 8 | |
| 2.16.4 | 8 / 8 | |
| 2.16.3 | 8 / 8 | |
| 2.16.2 | 8 / 8 | |
| 2.16.1 | 8 / 8 | |
| 2.16.0 | 8 / 8 | |
| 2.15.1 | 8 / 7 | |
| 2.15.0 | 8 / 7 | |
| 2.14.2 | 8 / 7 | |
| 2.14.1 | 8 / 7 | |
| 2.14.0 | 8 / 7 | |
| 2.13.0 | 8 / 7 | |
| 2.12.1 | 8 / 7 | |
| 2.12.0 | 8 / 7 | |
| 2.11.0 | 8 / 6 | |
| 2.10.1 | 8 / 6 | |
| 2.10.0 | 8 / 6 | |
| 2.9.0 | 8 / 6 | |
| 2.8.0 | 8 / 6 | |
| 2.7.6 | 8 / 6 | |
| 2.7.5 | 8 / 6 | |
| 2.7.4 | 8 / 5 | |
| 2.7.3 | 8 / 5 | |
| 2.7.2 | 8 / 3 | |
| 2.7.1 | 8 / 3 | |
| 2.7.0 | 8 / 3 | |
| 2.6.0 | 8 / 3 | |
| 2.5.0 | 9 / 3 | |
| 2.4.0 | 9 / 3 | |
| 2.3.0 | 5 / 6 | |
| 2.2.3 | 5 / 6 | |
| 2.2.2 | 5 / 6 | |
| 2.2.1 | 5 / 5 | |
| 2.2.0 | 5 / 5 | |
| 2.1.2 | 5 / 5 | |
| 2.1.1 | 5 / 5 | |
| 2.1.0 | 5 / 5 | |
| 2.0.0 | 4 / 5 |
v2.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.3
2 findingsThis version was published by a different npm account (GitHub Actions) than the most recent previously approved version (joshuabot) on 2025-10-20. It has since remained available on npm for 270 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.