← Home

@morpho-org/blue-sdk-viem

25
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

julien-devatommorpho-rubilmaxshufflewtf0xbulma

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:lib/esm/queries/vault-v2/GetVaultV2MorphoVaultV1Adapter.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/GetHolding.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/esm/queries/GetHolding.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/GetMarket.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/esm/queries/GetMarket.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/GetToken.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/esm/queries/GetToken.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/GetVault.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/esm/queries/GetVault.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/GetVaultUser.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/esm/queries/GetVaultUser.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/vault-v2/GetVaultV2MorphoMarketV1Adapter.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/esm/queries/vault-v2/GetVaultV2MorphoMarketV1Adapter.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/vault-v2/GetVaultV2MorphoMarketV1AdapterV2.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/esm/queries/vault-v2/GetVaultV2MorphoMarketV1AdapterV2.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/vault-v2/GetVaultV2MorphoVaultV1Adapter.js AI (source-diff): EVM deployless query bytecode, explicitly labeled as such; stable pattern across all versions of this package. ai
source-diff encoded-string-file:lib/cjs/queries/vault-v2/GetVaultV2.d.ts AI (source-diff): EVM bytecode constant in type declaration; expected pattern for this DeFi SDK. ai
source-diff encoded-string-file:lib/esm/queries/vault-v2/GetVaultV2.d.ts AI (source-diff): EVM bytecode constant in type declaration; expected pattern for this DeFi SDK. ai
maintainer-change maintainer-added AI (maintainer-change): morpho-rubilmax is a GitHub username rename of rubilmax within the same Morpho org. ai
maintainer-change maintainer-removed AI (maintainer-change): rubilmax renamed to morpho-rubilmax; not a hostile removal. ai
source-diff encoded-string-file:lib/esm/queries/vault-v2/GetVaultV2.js AI (source-diff): Same EVM bytecode pattern in ESM build; stable false positive for this package. ai
source-diff encoded-string-file:lib/cjs/queries/vault-v2/GetVaultV2.js AI (source-diff): Long hex string is EVM bytecode for an on-chain query contract; standard pattern for this package. ai
source-diff obfuscated-file:lib/esm/queries/vault-v2/GetVaultV2.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai
publish-pattern dormant-publish AI (publish-pattern): Dormancy explained by major refactor adding dual CJS/ESM build; SLSA provenance confirms CI/CD publish. ai
source-diff obfuscated-file:lib/esm/queries/GetHolding.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/cjs/queries/GetHolding.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/cjs/queries/GetToken.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/esm/queries/GetToken.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/cjs/queries/GetVault.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/esm/queries/GetVault.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai
source-diff obfuscated-file:lib/cjs/queries/vault-v2/GetVaultV2.js AI (source-diff): Long lines are Ethereum ABI arrays (structured JSON), not obfuscated code. Stable pattern for this package. ai

Versions (showing 25 of 25)

Version Deps Published
5.1.0 0 / 7
5.0.1 0 / 7
5.0.0 0 / 7
4.6.6 0 / 7
4.6.5 0 / 7
4.6.4 0 / 7
4.6.3 0 / 7
4.6.2 0 / 8
4.6.1 0 / 8
4.6.0 0 / 8
4.5.0 0 / 8
4.4.0 0 / 8
4.3.0 0 / 8
4.2.4 0 / 8
4.2.3 0 / 8
4.2.2 0 / 8
4.2.1 0 / 8
4.2.0 0 / 8
4.1.4 0 / 8
4.1.3 0 / 8
4.1.2 0 / 8
4.1.1 0 / 8
4.1.0 0 / 8
4.0.1 0 / 8
4.0.0 0 / 8

v5.1.0

17 findings
HIGH Long encoded string in modified file: lib/cjs/queries/GetHolding.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/GetHolding.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/GetMarket.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/GetMarket.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/GetToken.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/GetToken.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/GetVault.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/GetVault.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/GetVaultUser.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/GetVaultUser.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/vault-v2/GetVaultV2MorphoMarketV1Adapter.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/vault-v2/GetVaultV2MorphoMarketV1Adapter.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/vault-v2/GetVaultV2MorphoMarketV1AdapterV2.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/vault-v2/GetVaultV2MorphoMarketV1AdapterV2.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/vault-v2/GetVaultV2MorphoVaultV1Adapter.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/vault-v2/GetVaultV2MorphoVaultV1Adapter.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.1

3 findings
HIGH Long encoded string in modified file: lib/cjs/queries/vault-v2/GetVaultV2.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/vault-v2/GetVaultV2.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.0

5 findings
HIGH Long encoded string in modified file: lib/cjs/queries/vault-v2/GetVaultV2.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/vault-v2/GetVaultV2.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/cjs/queries/vault-v2/GetVaultV2.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/vault-v2/GetVaultV2.d.ts source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.6

3 findings
HIGH Long encoded string in modified file: lib/cjs/queries/vault-v2/GetVaultV2.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

HIGH Long encoded string in modified file: lib/esm/queries/vault-v2/GetVaultV2.js source-diff

Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.1

9 findings
HIGH New obfuscated file: lib/cjs/queries/GetHolding.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetHolding.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/GetToken.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetToken.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/GetVault.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetVault.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/vault-v2/GetVaultV2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/vault-v2/GetVaultV2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.0

9 findings
HIGH New obfuscated file: lib/cjs/queries/GetHolding.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetHolding.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/GetToken.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetToken.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/GetVault.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetVault.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/vault-v2/GetVaultV2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/vault-v2/GetVaultV2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.5.0

9 findings
HIGH New obfuscated file: lib/cjs/queries/GetHolding.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetHolding.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/GetToken.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetToken.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/GetVault.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/GetVault.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/cjs/queries/vault-v2/GetVaultV2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: lib/esm/queries/vault-v2/GetVaultV2.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.