@polkadot/metadata
Helpers to extract information from runtime metadata
48
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jacogrpolkadotjs
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:bn.js | AI (phantom-deps): bn.js is declared as a peer/transitive dep for consumers; not directly imported is expected for this package. | ai | |
| source-diff | obfuscated-file:v9/static.js | AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata (starts with 0x6d657461 = 'meta'). This is the documented purpose of @polkadot/metadata — storing static metadata snapshots. | ai | |
| source-diff | obfuscated-file:v12/static.js | AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata. Same pattern as v9/static.js — legitimate static metadata snapshot for offline decoding. | ai | |
| source-diff | obfuscated-file:v11/static.js | AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata. Same pattern as v9/static.js — legitimate static metadata snapshot for offline decoding. | ai | |
| source-diff | obfuscated-file:v10/static.js | AI (source-diff): Long hex string is SCALE-encoded Substrate runtime metadata. Same pattern as v9/static.js — legitimate static metadata snapshot for offline decoding. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @polkadot/types-known is a sibling package in the same polkadot-js/api monorepo, pinned to the same version. Not a suspicious third-party dependency. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Large files are versioned static metadata blobs (v9-v12) — expected growth pattern for this package as new Substrate runtime versions are added. | ai | |
| source-diff | obfuscated-file:v13/static.d.ts | AI (source-diff): TypeScript declaration file containing the same SCALE-encoded metadata hex string as a typed constant. Legitimate pattern for this package's versioned metadata distribution. | ai | |
| source-diff | obfuscated-file:v13/static.js | AI (source-diff): Large hex string is SCALE-encoded Substrate blockchain metadata — the core content this package distributes. Pattern matches existing accepted v13/static.cjs and prior versioned static files. | ai | |
| source-diff | encoded-string-file:v12/static.d.ts | AI (source-diff): TypeScript declaration file for the static metadata hex constant. The long string is the typed literal of the SCALE-encoded metadata blob, not a payload. | ai | |
| source-diff | encoded-string-file:v12/static.cjs | AI (source-diff): Long hex string is SCALE-encoded Polkadot runtime metadata (starts with 0x6d657461 = 'meta'). Shipping static metadata blobs as hex is the documented purpose of @polkadot/metadata. | ai | |
| source-diff | encoded-string-file:v12/static.js | AI (source-diff): Same SCALE-encoded Polkadot runtime metadata hex blob as the CJS variant. Expected content for this package's versioned static metadata exports. | ai | |
| source-diff | obfuscated-file:v13/static.cjs | AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. | ai | |
| source-diff | obfuscated-file:v12/static.cjs | AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. | ai | |
| source-diff | obfuscated-file:v11/static.cjs | AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. | ai | |
| source-diff | obfuscated-file:v10/static.cjs | AI (source-diff): Hex-encoded SCALE metadata blob, not obfuscated code. Standard @polkadot/metadata static snapshot pattern. | ai | |
| source-diff | obfuscated-file:v9/static.cjs | AI (source-diff): These are hex-encoded SCALE metadata blobs (Substrate runtime metadata), not obfuscated code. Standard pattern for @polkadot/metadata static snapshots. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Same legitimate org transition from jacogr to polkadotjs. Not a hostile takeover. | ai | |
| provenance | publisher-changed | AI (provenance): Documented org transition from personal account jacogr to polkadotjs org account. polkadotjs has 917 approved packages, confirming legitimacy. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 4.17.1 | 5 / 1 | |
| 4.16.2 | 5 / 1 | |
| 4.16.1 | 5 / 1 | |
| 4.15.1 | 5 / 1 | |
| 4.14.1 | 5 / 1 | |
| 4.13.1 | 6 / 1 | |
| 4.12.1 | 6 / 1 | |
| 4.11.2 | 6 / 1 | |
| 4.11.1 | 6 / 1 | |
| 4.10.1 | 6 / 1 | |
| 4.9.2 | 6 / 1 | |
| 4.8.1 | 6 / 1 | |
| 4.7.2 | 6 / 1 | |
| 4.7.1 | 6 / 1 | |
| 4.6.2 | 6 / 1 | |
| 4.6.1 | 6 / 1 | |
| 4.5.1 | 6 / 1 | |
| 4.4.1 | 6 / 1 | |
| 4.3.1 | 6 / 1 | |
| 4.2.1 | 6 / 1 | |
| 4.1.1 | 6 / 1 | |
| 4.0.3 | 6 / 1 | |
| 4.0.2 | 6 / 1 | |
| 4.0.1 | 6 / 1 | |
| 3.11.1 | 6 / 1 | |
| 3.10.2 | 6 / 1 | |
| 3.10.1 | 6 / 1 | |
| 3.9.3 | 6 / 1 | |
| 3.9.2 | 6 / 1 | |
| 3.9.1 | 6 / 1 | |
| 3.8.1 | 6 / 1 | |
| 3.7.3 | 6 / 1 | |
| 3.7.2 | 6 / 1 | |
| 3.7.1 | 6 / 1 | |
| 3.6.4 | 6 / 1 | |
| 3.6.3 | 6 / 1 | |
| 3.6.2 | 6 / 1 | |
| 3.6.1 | 6 / 1 | |
| 3.5.1 | 6 / 1 | |
| 3.4.1 | 6 / 1 | |
| 3.3.2 | 6 / 1 | |
| 3.3.1 | 6 / 1 | |
| 3.2.3 | 6 / 1 | |
| 3.2.2 | 6 / 1 | |
| 3.2.1 | 6 / 1 | |
| 3.1.1 | 6 / 1 | |
| 3.0.1 | 6 / 1 | |
| 1.7.1 | 5 / 1 |