@marinade.finance/validator-bonds-cli
CLI of the validator bonds contract
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:rpc-websockets | AI (phantom-deps): Solana web3.js ecosystem commonly uses rpc-websockets as a transitive/peer dep; phantom detection is a stable false positive here. | ai | |
| dependencies | unvetted-dep:solana-spl-token-modern | AI (dependencies): npm alias for @solana/spl-token; standard Solana ecosystem pattern for managing multiple SPL token versions. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): Logging dep declared in package.json; indirect usage expected in CLI. | ai | |
| phantom-deps | phantom-dep:yaml | AI (phantom-deps): Config parsing dep; indirect usage stable for this CLI package. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): Logging formatter; indirect usage stable for this CLI package. | ai | |
| phantom-deps | phantom-dep:@ledgerhq/errors | AI (phantom-deps): Ledger hardware wallet dep; indirect usage stable for this package. | ai | |
| phantom-deps | phantom-dep:@coral-xyz/anchor | AI (phantom-deps): Anchor framework dep; indirect usage common in Solana CLI tooling. | ai | |
| phantom-deps | phantom-dep:bs58 | AI (phantom-deps): CLI tool; transitive/config-level usage common in Solana tooling. | ai | |
| phantom-deps | phantom-dep:solana-spl-token-modern | AI (phantom-deps): npm alias for @solana/spl-token; indirect usage stable for this package. | ai | |
| phantom-deps | phantom-dep:@marinade.finance/ts-common | AI (phantom-deps): Same-org dep; indirect usage stable across versions. | ai | |
| phantom-deps | phantom-dep:@marinade.finance/ledger-utils | AI (phantom-deps): Same-org dep; indirect usage stable across versions. | ai | |
| phantom-deps | phantom-dep:@marinade.finance/anchor-common | AI (phantom-deps): Same-org dep; indirect usage stable across versions. | ai | |
| phantom-deps | phantom-dep:@ledgerhq/hw-transport-node-hid-noevents | AI (phantom-deps): Ledger HID transport dep; indirect usage stable for this package. | ai | |
| phantom-deps | phantom-dep:@ledgerhq/hw-app-solana | AI (phantom-deps): Ledger Solana app dep; indirect usage stable for this package. | ai | |
| phantom-deps | phantom-dep:jsbi | AI (phantom-deps): Solana ecosystem dep; indirect usage pattern stable for this package. | ai |
Versions (showing 11 of 11)
| Version | Deps | Published |
|---|---|---|
| 2.4.7 | 23 / 2 | |
| 2.4.6 | 21 / 2 | |
| 2.4.5 | 21 / 2 | |
| 2.4.4 | 21 / 2 | |
| 2.4.3 | 21 / 2 | |
| 2.4.2 | 20 / 2 | |
| 2.4.1 | 20 / 2 | |
| 2.3.2 | 17 / 2 | |
| 2.3.1 | 17 / 2 | |
| 2.3.0 | 17 / 2 | |
| 2.2.3 | 17 / 2 |
v2.4.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.3.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.3.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.2.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.