@pancakeswap/sdk
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:viem | AI (phantom-deps): viem is a declared runtime dep used in compiled output; stable FP for this package. | ai | |
| phantom-deps | phantom-dep:big.js | AI (phantom-deps): big.js is a declared runtime dep used in compiled output; stable FP. | ai | |
| phantom-deps | phantom-dep:toformat | AI (phantom-deps): toformat is a declared runtime dep used in compiled output; stable FP. | ai | |
| phantom-deps | phantom-dep:tiny-warning | AI (phantom-deps): tiny-warning is a declared runtime dep used in compiled output; stable FP. | ai | |
| phantom-deps | phantom-dep:decimal.js-light | AI (phantom-deps): decimal.js-light is a declared runtime dep used in compiled output; stable FP. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 5.9.0 | 11 / 2 | |
| 5.8.18 | 11 / 2 | |
| 5.8.17 | 11 / 2 | |
| 5.8.16 | 11 / 2 | |
| 5.8.15 | 10 / 2 | |
| 5.8.14 | 10 / 2 | |
| 5.8.13 | 10 / 2 |
v5.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.8.18
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.8.17
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.8.16
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.8.15
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.8.14
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v5.8.13
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.