@gearbox-protocol/deploy-tools
Gearbox deploy tools
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | encoded-string-file:dist/index.mjs | AI (source-diff): Long hex strings are EVM bytecode constants bundled from viem; stable false positive for this Ethereum deploy-tools package. | ai | |
| phantom-deps | phantom-dep:viem-deal | AI (phantom-deps): viem-deal is a declared runtime dep used via config; phantom-dep heuristic fires because it's not directly imported in source. | ai |
Versions (showing 10 of 110)
| Version | Deps | Published |
|---|---|---|
| 5.57.6 | 0 / 32 | |
| 5.57.5 | 0 / 32 | |
| 5.57.4 | 0 / 32 | |
| 5.57.3 | 0 / 32 | |
| 5.57.2 | 0 / 32 | |
| 5.57.1 | 0 / 32 | |
| 5.57.0 | 0 / 32 | |
| 5.56.0 | 0 / 32 | |
| 5.55.0 | 0 / 32 | |
| 5.54.1 | 0 / 32 |
v5.57.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.57.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.57.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.57.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.57.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.57.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.57.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.56.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.55.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.54.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.