@kumbaya_xyz/smart-order-router
Kumbaya DEX Smart Order Router
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@uniswap/universal-router | AI (phantom-deps): npm alias maps @uniswap/universal-router to @kumbaya_xyz/universal-router; phantom-dep heuristic misfires on aliased deps. | ai | |
| phantom-deps | phantom-dep:@uniswap/swap-router-contracts | AI (phantom-deps): npm alias maps this to @kumbaya_xyz/swap-router-contracts; phantom-dep heuristic misfires on aliased deps. | ai | |
| phantom-deps | phantom-dep:graphql | AI (phantom-deps): Referenced in config files per finding; graphql-request peer dep pattern makes this a stable false positive. | ai | |
| phantom-deps | phantom-dep:@kumbaya_xyz/universal-router | AI (phantom-deps): Same-org package; likely loaded indirectly or via type resolution, not a real phantom dep concern. | ai | |
| phantom-deps | phantom-dep:@types/brotli | AI (phantom-deps): Framework-scoped type package; loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:bunyan-blackhole | AI (phantom-deps): Config-file referenced logger sink; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@kumbaya_xyz/swap-router-contracts | AI (phantom-deps): Same-org package used in build scripts (compile-router); phantom-dep heuristic is a false positive here. | ai |
Versions (showing 4 of 4)
| Version | Deps | Published |
|---|---|---|
| 4.22.43 | 26 / 45 | |
| 4.22.41 | 26 / 45 | |
| 4.22.40 | 26 / 45 | |
| 4.22.39 | 26 / 45 |
v4.22.43
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.22.41
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.22.40
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.22.39
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.