@interchainjs/cosmos
Transaction codec and client to communicate with any cosmos blockchain
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): pyramation is the primary hyperweb-io org maintainer with 2736 approved packages and no rejections; transition from zetazz is a legitimate org consolidation within the same monorepo. | ai | |
| phantom-deps | phantom-dep:bech32 | AI (phantom-deps): Bech32 is core to Cosmos address encoding; used indirectly. | ai | |
| phantom-deps | phantom-dep:decimal.js | AI (phantom-deps): Declared dep used indirectly; common monorepo pattern. | ai | |
| phantom-deps | phantom-dep:bignumber.js | AI (phantom-deps): Declared dep used indirectly; common monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@noble/curves | AI (phantom-deps): Crypto dep used indirectly for key operations; expected for blockchain SDK. | ai | |
| phantom-deps | phantom-dep:ws | AI (phantom-deps): Declared dep used indirectly via sub-modules; common monorepo pattern. | ai | |
| phantom-deps | phantom-dep:@interchainjs/crypto | AI (phantom-deps): Same-org sibling package used indirectly; monorepo pattern. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Standard blockchain hex-to-base64 hash conversion; no obfuscation, clearly readable utility code in a Cosmos transaction library. | ai | |
| semgrep | semgrep:base64-decode | AI (semgrep): Standard base64 decoding of blockchain response data (block hashes); benign and expected in a Cosmos client library. | ai | |
| phantom-deps | phantom-dep:@noble/hashes | AI (phantom-deps): Crypto dep used indirectly for hashing; expected for blockchain SDK. | ai |
Versions (showing 51 of 77)
| Version | Deps | Published |
|---|---|---|
| 1.21.0 | 16 / 6 | |
| 1.20.0 | 16 / 6 | |
| 1.19.4 | 16 / 6 | |
| 1.19.3 | 16 / 6 | |
| 1.19.2 | 16 / 6 | |
| 1.19.1 | 16 / 6 | |
| 1.19.0 | 16 / 6 | |
| 1.18.0 | 16 / 6 | |
| 1.17.8 | 16 / 6 | |
| 1.17.7 | 16 / 6 | |
| 1.17.6 | 16 / 6 | |
| 1.17.5 | 14 / 6 | |
| 1.17.4 | 14 / 5 | |
| 1.17.3 | 14 / 5 | |
| 1.17.2 | 14 / 5 | |
| 1.17.1 | 14 / 5 | |
| 1.17.0 | 14 / 5 | |
| 1.16.7 | 14 / 5 | |
| 1.16.6 | 14 / 5 | |
| 1.16.5 | 14 / 5 | |
| 1.16.4 | 14 / 5 | |
| 1.16.3 | 14 / 5 | |
| 1.16.2 | 14 / 5 | |
| 1.16.1 | 14 / 5 | |
| 1.16.0 | 14 / 5 | |
| 1.13.5 | 14 / 5 | |
| 1.13.0 | 9 / 0 | |
| 1.12.2 | 9 / 0 | |
| 1.12.1 | 9 / 0 | |
| 1.12.0 | 9 / 0 | |
| 1.11.18 | 7 / 0 | |
| 1.11.15 | 7 / 0 | |
| 1.11.14 | 7 / 0 | |
| 1.11.13 | 7 / 0 | |
| 1.11.12 | 7 / 0 | |
| 1.11.11 | 7 / 0 | |
| 1.11.10 | 7 / 0 | |
| 1.11.9 | 7 / 0 | |
| 1.11.8 | 7 / 0 | |
| 1.11.7 | 7 / 0 | |
| 1.11.6 | 7 / 0 | |
| 1.11.5 | 7 / 0 | |
| 1.11.4 | 9 / 0 | |
| 1.11.3 | 9 / 0 | |
| 1.11.2 | 9 / 0 | |
| 1.11.1 | 9 / 0 | |
| 1.11.0 | 9 / 0 | |
| 1.10.1 | 9 / 0 | |
| 1.10.0 | 9 / 0 | |
| 1.9.16 | 9 / 0 | |
| 1.9.15 | 9 / 0 |
v1.21.0
2 findingsThis version was published by a different npm account than previous versions on 2026-03-01. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.20.0
2 findingsThis version was published by a different npm account than previous versions on 2026-03-01. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.4
2 findingsThis version was published by a different npm account than previous versions on 2026-02-27. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.3
2 findingsThis version was published by a different npm account than previous versions on 2025-12-30. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.2
2 findingsThis version was published by a different npm account than previous versions on 2025-12-16. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.1
2 findingsThis version was published by a different npm account than previous versions on 2025-12-16. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.19.0
2 findingsThis version was published by a different npm account than previous versions on 2025-12-11. This could indicate a legitimate maintainer transition or an account compromise.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.18.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.17.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.16.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.13.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.18
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.12
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.11
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.11.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.10.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.9.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.