← Home

@meteora-ag/cp-amm-sdk

31
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

thimerosasiongdannweeeeesenddageeand4getbangyrodongnguyen91861dicksonpcodewithgunminhraccoons

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): bn.js is a canonical bignum library; addition is expected for a Solana math SDK. ai
dependencies unvetted-dep:ts-mocha AI (dependencies): Test runner dependency; referenced only in test script, not runtime code. ai
dependencies unvetted-dep:@types/chai AI (dependencies): Type definitions for test framework; no runtime impact. ai
dependencies unvetted-dep:solana-bankrun AI (dependencies): Solana test framework dependency; used in tests only, not shipped in dist. ai
phantom-deps phantom-dep:chai AI (phantom-deps): Test assertion library referenced in config; not a runtime import. ai
phantom-deps phantom-dep:tsup AI (phantom-deps): Build tool referenced in build script; not a runtime import. ai
phantom-deps phantom-dep:mocha AI (phantom-deps): Test runner referenced in config; not a runtime import. ai
phantom-deps phantom-dep:@types/mocha AI (phantom-deps): Type definitions loaded by convention; no runtime impact. ai
phantom-deps phantom-dep:solana-bankrun AI (phantom-deps): Test framework referenced in config; not a runtime import. ai
phantom-deps phantom-dep:ts-node AI (phantom-deps): TypeScript execution tool for tests; not a runtime import. ai
phantom-deps phantom-dep:ts-mocha AI (phantom-deps): Test runner referenced in test script; not a runtime import. ai
phantom-deps phantom-dep:@types/chai AI (phantom-deps): Type definitions loaded by convention; no runtime impact. ai
phantom-deps phantom-dep:chain AI (phantom-deps): chain is declared as a dep but flagged phantom; low risk and consistent with SDK build tooling patterns. ai
phantom-deps phantom-dep:@types/bn.js AI (phantom-deps): Type-only package loaded by convention; not directly imported but legitimately used for TypeScript types. ai

Versions (showing 31 of 31)

Version Deps Published
1.4.3 8 / 8
1.4.2 8 / 8
1.4.1 8 / 8
1.4.0 8 / 8
1.3.9 8 / 8
1.3.8 8 / 8
1.3.7 8 / 8
1.3.6 8 / 8
1.3.5 8 / 8
1.3.3 8 / 8
1.3.2 8 / 8
1.3.1 8 / 8
1.3.0 8 / 8
1.2.10 8 / 8
1.2.9 8 / 8
1.2.8 7 / 11
1.2.7 7 / 11
1.2.6 7 / 11
1.2.5 7 / 11
1.2.4 7 / 11
1.2.3 7 / 11
1.2.2 7 / 11
1.2.1 7 / 11
1.2.0 7 / 11
1.1.9 7 / 11
1.1.8 7 / 11
1.1.7 7 / 11
1.1.6 7 / 11
1.0.8 15 / 2
1.0.5 15 / 2
1.0.3 15 / 2

v1.4.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.2.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v1.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v1.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.