← Home

@hyperlane-xyz/relayer

Hyperlane Message Relayer Service

7
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

nambrotyorhodestkporterpaulbalaji

Keywords

blockchainhyperlaneinterchainmessagerelayer

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Active org with CI publishing and SLSA provenance; maintainer rotation is expected in a large monorepo team. ai
maintainer-change maintainer-removed AI (maintainer-change): Published via GitHub Actions with SLSA attestation; maintainer rotation in a monorepo CI context is expected. ai
phantom-deps phantom-dep:pino-pretty AI (phantom-deps): Declared runtime dep used as pino transport by convention, not directly imported in source. ai
phantom-deps phantom-dep:zod-validation-error AI (phantom-deps): Declared runtime dep used via config/convention, stable false positive for this package. ai
phantom-deps phantom-dep:@google-cloud/pino-logging-gcp-config AI (phantom-deps): Framework-scoped logging config package loaded by convention; explicitly excluded from bundle build. ai

Versions (showing 7 of 7)

Version Deps Published
1.1.28 14 / 19
1.1.26 14 / 19
1.1.25 14 / 19
1.1.24 14 / 19
1.1.17 14 / 19
1.1.15 14 / 19
1.1.11 14 / 21

v1.1.28

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.26

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.25

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.24

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.17

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.15

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.