@hyperlane-xyz/relayer
Hyperlane Message Relayer Service
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| maintainer-change | maintainer-added | AI (maintainer-change): Active org with CI publishing and SLSA provenance; maintainer rotation is expected in a large monorepo team. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Published via GitHub Actions with SLSA attestation; maintainer rotation in a monorepo CI context is expected. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): Declared runtime dep used as pino transport by convention, not directly imported in source. | ai | |
| phantom-deps | phantom-dep:zod-validation-error | AI (phantom-deps): Declared runtime dep used via config/convention, stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@google-cloud/pino-logging-gcp-config | AI (phantom-deps): Framework-scoped logging config package loaded by convention; explicitly excluded from bundle build. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 1.1.28 | 14 / 19 | |
| 1.1.26 | 14 / 19 | |
| 1.1.25 | 14 / 19 | |
| 1.1.24 | 14 / 19 | |
| 1.1.17 | 14 / 19 | |
| 1.1.15 | 14 / 19 | |
| 1.1.11 | 14 / 21 |
v1.1.28
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.