@origintrail-official/dkg-publisher
Publishing protocol for DKG V9. Handles the complete lifecycle of getting Knowledge Assets from a node into the network — from RDF processing through Merkle tree construction to on-chain finalization.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): 62 new files consistent with v10.0.0 major release scope; no obfuscation or malicious patterns flagged. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Maintainer rotation within the OriginTrail org on a major version bump; consistent with normal team management. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Paired with maintainer-added in same org context; no evidence of hostile takeover. | ai | |
| source-diff | source-size-tripled | AI (source-diff): v10.0.0 major release with significant architectural expansion; size increase is expected and consistent with 62 new source files. | ai | |
| phantom-deps | phantom-dep:n3 | AI (phantom-deps): Transitive/config-level usage in RDF-processing monorepo; stable false positive. | ai | |
| phantom-deps | phantom-dep:rdf-canonize | AI (phantom-deps): Same as n3 — RDF tooling used indirectly via sibling packages. | ai | |
| phantom-deps | phantom-dep:@multiformats/multiaddr | AI (phantom-deps): Peer/transitive usage in DKG networking layer; stable false positive. | ai | |
| phantom-deps | phantom-dep:@origintrail-official/dkg-query | AI (phantom-deps): Same-org monorepo sibling; phantom-dep heuristic unreliable for intra-monorepo deps. | ai |
Versions (showing 10 of 10)
| Version | Deps | Published |
|---|---|---|
| 10.0.9 | 6 / 4 | |
| 10.0.8 | 6 / 4 | |
| 10.0.6 | 6 / 4 | |
| 10.0.5 | 6 / 4 | |
| 10.0.4 | 6 / 4 | |
| 10.0.3 | 6 / 4 | |
| 10.0.2 | 6 / 4 | |
| 10.0.1 | 6 / 2 | |
| 10.0.0 | 6 / 2 | |
| 0.0.1 | 8 / 2 |
v10.0.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (jurij89) than the most recent previously approved version (branarakic) on unknown date, but jurij89 is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v10.0.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v10.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.