@imtbl/dex-sdk
DEX Provider package for the Immutable SDK
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation; consistent with org-wide CI/CD migration for Immutable SDK. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): platform-sa removal accompanies GitHub Actions takeover with SLSA provenance; legitimate CI migration pattern. | ai | |
| source-diff | encoded-string-file:dist/node/index.cjs | AI (source-diff): Long strings are ABI selectors and minified Uniswap SDK code; no obfuscation or malicious payload. | ai | |
| source-diff | encoded-string-file:dist/browser/index.js | AI (source-diff): Same pattern — ABI selectors in minified DEX bundle; benign for this package. | ai | |
| source-diff | encoded-string-file:dist/node/index.js | AI (source-diff): Same pattern — ABI selectors in minified DEX bundle; benign for this package. | ai | |
| phantom-deps | phantom-dep:@uniswap/swap-router-contracts | AI (phantom-deps): Used for ABI/type references at build time, not a runtime import; stable false positive for this package. | ai |
Versions (showing 74 of 74)
| Version | Deps | Published |
|---|---|---|
| 2.23.0 | 5 / 12 | |
| 2.22.0 | 5 / 12 | |
| 2.21.0 | 5 / 12 | |
| 2.20.2 | 5 / 12 | |
| 2.20.1 | 5 / 12 | |
| 2.20.0 | 5 / 12 | |
| 2.19.0 | 5 / 12 | |
| 2.18.0 | 5 / 12 | |
| 2.17.1 | 5 / 12 | |
| 2.17.0 | 5 / 12 | |
| 2.16.0 | 5 / 12 | |
| 2.15.0 | 5 / 12 | |
| 2.14.3 | 5 / 12 | |
| 2.14.0 | 5 / 12 | |
| 2.13.0 | 5 / 12 | |
| 2.12.7 | 5 / 12 | |
| 2.12.6 | 5 / 12 | |
| 2.12.5 | 5 / 12 | |
| 2.12.4 | 5 / 12 | |
| 2.12.3 | 5 / 12 | |
| 2.12.2 | 5 / 12 | |
| 2.12.1 | 5 / 12 | |
| 2.12.0 | 5 / 12 | |
| 2.11.0 | 5 / 12 | |
| 2.10.6 | 5 / 12 | |
| 2.10.5 | 5 / 12 | |
| 2.10.4 | 5 / 12 | |
| 2.10.3 | 5 / 12 | |
| 2.10.2 | 5 / 12 | |
| 2.10.1 | 5 / 12 | |
| 2.10.0 | 5 / 12 | |
| 2.8.0 | 5 / 12 | |
| 2.7.4 | 5 / 12 | |
| 2.7.3 | 5 / 12 | |
| 2.7.2 | 5 / 12 | |
| 2.7.0 | 5 / 12 | |
| 2.6.0 | 5 / 12 | |
| 2.4.14 | 5 / 12 | |
| 2.4.13 | 5 / 12 | |
| 2.4.11 | 5 / 12 | |
| 2.4.10 | 5 / 12 | |
| 2.4.9 | 5 / 12 | |
| 2.4.8 | 5 / 12 | |
| 2.4.7 | 5 / 12 | |
| 2.4.6 | 5 / 12 | |
| 2.4.5 | 5 / 12 | |
| 2.4.4 | 5 / 12 | |
| 2.4.3 | 5 / 12 | |
| 2.4.2 | 5 / 12 | |
| 2.4.1 | 5 / 12 | |
| 2.4.0 | 5 / 12 | |
| 2.3.3 | 5 / 12 | |
| 2.3.2 | 5 / 12 | |
| 2.3.0 | 5 / 12 | |
| 2.2.4 | 5 / 12 | |
| 2.2.3 | 5 / 12 | |
| 2.2.0 | 5 / 12 | |
| 2.1.16 | 5 / 12 | |
| 2.1.15 | 5 / 12 | |
| 2.1.11 | 5 / 12 | |
| 2.1.9 | 5 / 12 | |
| 2.1.8 | 5 / 12 | |
| 2.1.7 | 5 / 12 | |
| 2.1.6 | 5 / 12 | |
| 2.1.5 | 5 / 12 | |
| 2.1.4 | 5 / 12 | |
| 2.1.3 | 5 / 12 | |
| 2.1.2 | 5 / 12 | |
| 2.1.1 | 5 / 12 | |
| 2.1.0 | 5 / 12 | |
| 2.0.3 | 5 / 12 | |
| 2.0.2 | 5 / 12 | |
| 2.0.1 | 5 / 12 | |
| 2.0.0 | 5 / 12 |
v2.23.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.21.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.20.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.16
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.11
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v2.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.