@polkadot/api-codec
15
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jacogr
Keywords
PolkadotJsonRPC
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:Metadata.rpc.d.ts | AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata, a standard pattern in @polkadot packages. Not obfuscated malicious code. | ai | |
| source-diff | obfuscated-file:Metadata.rpc.js | AI (source-diff): Long lines are a SCALE-encoded byte array (Polkadot RPC metadata), not obfuscation. This is a standard pattern in polkadot-js packages for embedding chain metadata. | ai | |
| source-diff | obfuscated-file:Metadata.rpc.ts | AI (source-diff): Same as .js counterpart — large integer array literal encoding Polkadot chain metadata, not malicious obfuscation. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance by years; published by the highly trusted original Polkadot.js author. Absence of provenance is expected for this era. | ai | |
| dependencies | unvetted-dep:@polkadot/util-keyring | AI (dependencies): @polkadot/util-keyring is a sibling package from the same Polkadot.js ecosystem by the same trusted publisher (jacogr). This dependency is expected and benign. | ai |