@layerzerolabs/oft-v2-solana-sdk
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| bogus-package | bogus-package | AI (bogus-package): Established LayerZero SDK package; sparse metadata is typical for org-internal SDKs, not spam. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Known LayerZero org package; missing description is a style choice, not a malware indicator. | ai | |
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): bn.js is a transitive Solana/web3 dep; phantom-dep heuristic fires on indirect usage patterns. | ai | |
| phantom-deps | phantom-dep:dotenv | AI (phantom-deps): dotenv used in test/config scripts; phantom-dep heuristic false positive for this SDK. | ai | |
| phantom-deps | phantom-dep:@metaplex-foundation/beet | AI (phantom-deps): Metaplex beet used in generated Solana code; phantom-dep heuristic false positive. | ai | |
| phantom-deps | phantom-dep:@layerzerolabs/lz-foundation | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for monorepo packages. | ai | |
| phantom-deps | phantom-dep:@layerzerolabs/lz-v2-utilities | AI (phantom-deps): Same-org dep; phantom-dep heuristic unreliable for monorepo packages. | ai | |
| phantom-deps | phantom-dep:@metaplex-foundation/beet-solana | AI (phantom-deps): Metaplex beet-solana used in generated Solana code; phantom-dep heuristic false positive. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 3.0.168 | 13 / 31 | |
| 3.0.163 | 13 / 31 | |
| 3.0.158 | 13 / 31 | |
| 3.0.152 | 13 / 31 | |
| 3.0.148 | 13 / 31 | |
| 3.0.147 | 13 / 31 | |
| 3.0.145 | 13 / 31 | |
| 3.0.143 | 13 / 31 | |
| 3.0.142 | 13 / 31 | |
| 3.0.136 | 13 / 31 | |
| 3.0.129 | 13 / 31 | |
| 3.0.126 | 13 / 31 | |
| 3.0.118 | 13 / 31 | |
| 3.0.111 | 13 / 31 | |
| 3.0.109 | 13 / 31 | |
| 3.0.105 | 13 / 31 | |
| 3.0.100 | 13 / 31 | |
| 3.0.97 | 13 / 31 |
v3.0.168
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.163
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.158
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.152
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.148
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.147
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.145
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.143
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.142
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.136
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.129
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.126
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.118
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.111
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.109
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.105
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.100
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.97
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.