@layerzerolabs/chain-utils
25
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
layerzero-bot
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@layerzerolabs/common-utils | AI (dependencies): Same-org sibling package pinned to identical version; not third-party unvetted dep. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): Used indirectly via config, common false positive for utility libs. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): New dep is an in-house sibling package, not a third-party addition. | ai | |
| dependencies | unvetted-dep:@layerzerolabs/common-canton | AI (dependencies): First-party LayerZero monorepo package, version-pinned to same release. | ai | |
| dependencies | unvetted-dep:@layerzerolabs/common-ton | AI (dependencies): First-party LayerZero monorepo package at matching version 0.2.32. | ai | |
| dependencies | unvetted-dep:@initia/initia.js | AI (dependencies): Pinned at 1.0.4 in a well-established LayerZero package; consistent across versions with no other risk signals. | ai | |
| provenance | no-provenance | AI (provenance): Publisher has 770 approved packages without provenance; consistent ecosystem pattern. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Consistent with layerzerolabs monorepo publishing pattern; not indicative of malice. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo utility package; missing metadata is a consistent pattern across the layerzerolabs ecosystem, not a spam indicator. | ai |
Versions (showing 25 of 25)
| Version | Deps | Published |
|---|---|---|
| 0.2.133 | 11 / 6 | |
| 0.2.117 | 10 / 5 | |
| 0.2.100 | 9 / 5 | |
| 0.2.96 | 9 / 5 | |
| 0.2.90 | 9 / 5 | |
| 0.2.89 | 9 / 5 | |
| 0.2.87 | 9 / 5 | |
| 0.2.84 | 9 / 5 | |
| 0.2.82 | 9 / 5 | |
| 0.2.75 | 9 / 5 | |
| 0.2.52 | 9 / 5 | |
| 0.2.50 | 9 / 5 | |
| 0.2.49 | 9 / 5 | |
| 0.2.46 | 9 / 5 | |
| 0.2.32 | 9 / 5 | |
| 0.2.31 | 9 / 5 | |
| 0.2.28 | 9 / 5 | |
| 0.2.27 | 9 / 5 | |
| 0.2.20 | 9 / 5 | |
| 0.2.18 | 9 / 5 | |
| 0.2.12 | 9 / 5 | |
| 0.0.64 | 8 / 5 | |
| 0.0.44 | 5 / 4 | |
| 0.0.35 | 5 / 4 | |
| 0.0.8 | 5 / 4 |
v0.2.133
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.2.117
1 finding
INFO
No provenance attestation
provenance
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.