← Home

@lodestar/light-client

A Typescript implementation of the Ethereum Consensus light client

51
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

wemeetagainmatthewkeiljoshdougallkalambet

Keywords

ethereumeth-consensusbeaconlight-clientblockchain

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/lightclient.min.mjs AI (source-diff): Vite-bundled browser dist with sourcemap; minified light-client networking, not a dropper. ai
source-diff source-size-tripled AI (source-diff): Expected from adding bundled dist output (build:bundle script) to the package. ai
publish-pattern new-deps-added AI (publish-pattern): @chainsafe/blst is an official ChainSafe crypto lib, sibling to existing @chainsafe/bls dep. ai
provenance publisher-changed AI (provenance): ChainSafe/lodestar transitioned to GitHub Actions CI/CD publishing with SLSA provenance attestation — a security improvement, not a compromise indicator. Stable for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Package has 2672 versions and 1.6k weekly downloads; dormancy signal is a false positive likely caused by a gap in sub-package publishing within an active monorepo. ai
phantom-deps phantom-dep:@chainsafe/blst AI (phantom-deps): @chainsafe/blst is a BLS crypto library used as an optional/configurable backend; declaring it as a dep without direct imports is a known pattern for pluggable crypto backends in this ecosystem. ai

Versions (showing 51 of 69)

View all versions
Version Deps Published
1.43.0 10 / 7
1.42.0 10 / 7
1.41.1 10 / 7
1.41.0 10 / 7
1.40.0 10 / 7
1.39.1 10 / 7
1.39.0 10 / 7
1.38.0 10 / 5
1.37.0 10 / 5
1.36.0 10 / 5
1.35.0 10 / 5
1.34.1 10 / 5
1.34.0 10 / 5
1.33.0 10 / 5
1.32.0 10 / 5
1.31.0 10 / 5
1.30.0 10 / 5
1.29.0 10 / 5
1.28.1 10 / 5
1.28.0 10 / 5
1.27.1 10 / 5
1.27.0 10 / 5
1.26.0 10 / 5
1.25.0 10 / 5
1.24.0 10 / 5
1.23.1 10 / 5
1.23.0 10 / 5
1.22.0 10 / 5
1.21.0 10 / 5
1.20.2 9 / 5
1.20.1 9 / 5
1.20.0 9 / 5
1.19.0 9 / 5
1.18.1 9 / 5
1.18.0 9 / 5
1.17.0 10 / 4
1.16.0 11 / 4
1.15.1 11 / 4
1.15.0 11 / 4
1.14.0 11 / 4
1.13.0 11 / 4
1.12.1 11 / 4
1.12.0 11 / 4
1.11.3 11 / 4
1.11.2 11 / 4
1.11.1 11 / 4
1.11.0 11 / 4
1.10.0 11 / 4
1.9.2 12 / 4
1.9.1 12 / 4
1.9.0 12 / 4

v1.29.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.28.1

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.28.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.1

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.27.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.26.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.25.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.24.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.1

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.23.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.22.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.21.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.2

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.1

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.20.0

2 findings
HIGH New file with network + code execution: dist/lightclient.min.mjs source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.14.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.12.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.9.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.