@polkadot/util
A collection of useful utilities for @polkadot
100
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
jacogrpolkadotjsparitytech-ci
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@types/camelcase | AI (dependencies): @types/camelcase is the TypeScript type definitions for the well-known camelcase package; it is benign and consistent with this package's pattern of listing @types/* as runtime deps. | ai | |
| phantom-deps | phantom-dep:@types/camelcase | AI (phantom-deps): Listing @types/* packages as runtime deps without direct imports is a known pattern in this Polkadot TypeScript package; other @types/* phantom deps are already accepted. | ai | |
| phantom-deps | phantom-dep:@types/ip-regex | AI (phantom-deps): @types packages are TypeScript type declarations consumed by tooling, not direct imports; phantom-dep firing on them is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/xxhashjs | AI (phantom-deps): @types packages are TypeScript type declarations consumed by tooling, not direct imports; phantom-dep firing on them is a stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@types/deasync | AI (phantom-deps): @types packages are TypeScript type declarations consumed by tooling, not direct imports; phantom-dep firing on them is a stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/ip-regex | AI (dependencies): @types/ip-regex is a DefinitelyTyped TypeScript type definition package — benign by nature, no runtime code execution risk. | ai | |
| dependencies | unvetted-dep:@types/xxhashjs | AI (dependencies): @types/xxhashjs is a DefinitelyTyped TypeScript type definition package — benign by nature, no runtime code execution risk. | ai | |
| provenance | missing-githead | AI (provenance): Package is from a highly trusted publisher (jacogr, 8095 approved/0 rejected) with a 3000+ day history. Missing gitHead reflects a publish environment change, not a security concern for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): @polkadot/util is an actively developed utility library; adding new source files across minor versions is expected organic growth, not injected code. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): bn.js and keccak are well-established cryptographic libraries appropriate for a blockchain utility package; their addition is expected and legitimate. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Size increase reflects legitimate addition of crypto utilities (bn.js, keccak wrappers) in a growing blockchain utility library from a trusted publisher. | ai | |
| dependencies | unvetted-dep:keccak | AI (dependencies): keccak is a well-known cryptographic hash library standard in the blockchain/Ethereum ecosystem; legitimate dependency for @polkadot/util. | ai | |
| provenance | no-provenance | AI (provenance): Package predates Sigstore provenance adoption; publisher has 8083 approved packages and strong trust history. Not a meaningful risk signal here. | ai | |
| phantom-deps | phantom-dep:babel-runtime | AI (phantom-deps): babel-runtime is a legitimate runtime dependency used via babel-plugin-transform-runtime (Babel 6 pattern); not a phantom dep for this package. | ai | |
| provenance | publisher-changed | AI (provenance): paritytech-ci is Parity Technologies' CI publishing account with 111 approved packages; the polkadotjs→paritytech-ci transition is a known organizational consolidation, not a compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): paritytech-ci is a verified Parity Technologies CI account with strong track record; addition is a legitimate organizational change. | ai | |
| phantom-deps | phantom-dep:@types/bn.js | AI (phantom-deps): @types/bn.js is a TypeScript type definition used by convention in the polkadot-js ecosystem; phantom dep finding is a stable false positive here. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Hex decoding is core functionality of @polkadot/util; Buffer.from(value, 'hex') is a standard, non-obfuscated utility operation. | ai | |
| typosquat | typosquat.levenshtein:uuid | AI (typosquat): @polkadot/util is a well-known Polkadot ecosystem utility library, not a typosquat of uuid. The name similarity is purely coincidental. | ai |
Versions (showing 100 of 551)
| Version | Deps | Published |
|---|---|---|
| 14.0.3 | 7 / 0 | |
| 14.0.2 | 7 / 0 | |
| 14.0.1 | 7 / 0 | |
| 13.5.9 | 7 / 0 | |
| 13.5.8 | 7 / 0 | |
| 13.5.7 | 7 / 0 | |
| 13.5.6 | 7 / 0 | |
| 13.5.5 | 7 / 0 | |
| 13.5.4 | 7 / 0 | |
| 13.5.3 | 7 / 0 | |
| 13.5.2 | 7 / 0 | |
| 13.5.1 | 7 / 0 | |
| 13.4.4 | 7 / 0 | |
| 13.4.3 | 7 / 0 | |
| 13.4.2 | 7 / 0 | |
| 13.4.1 | 7 / 0 | |
| 13.3.1 | 7 / 0 | |
| 13.2.3 | 7 / 0 | |
| 13.2.2 | 7 / 0 | |
| 13.2.1 | 7 / 0 | |
| 13.1.1 | 7 / 0 | |
| 13.0.2 | 7 / 0 | |
| 13.0.1 | 7 / 0 | |
| 12.6.2 | 7 / 0 | |
| 12.6.1 | 7 / 0 | |
| 12.5.1 | 7 / 0 | |
| 12.4.2 | 7 / 0 | |
| 12.4.1 | 7 / 0 | |
| 12.3.2 | 7 / 0 | |
| 12.3.1 | 7 / 0 | |
| 12.2.2 | 7 / 0 | |
| 12.2.1 | 7 / 0 | |
| 12.1.2 | 7 / 0 | |
| 12.1.1 | 7 / 0 | |
| 12.0.1 | 7 / 0 | |
| 11.1.3 | 7 / 0 | |
| 11.1.2 | 7 / 0 | |
| 11.1.1 | 7 / 0 | |
| 11.0.2 | 7 / 0 | |
| 11.0.1 | 7 / 0 | |
| 10.4.2 | 7 / 0 | |
| 10.4.1 | 7 / 0 | |
| 10.3.1 | 7 / 0 | |
| 10.2.6 | 7 / 0 | |
| 10.2.5 | 7 / 0 | |
| 10.2.4 | 7 / 0 | |
| 10.2.3 | 7 / 0 | |
| 10.2.2 | 7 / 0 | |
| 10.2.1 | 7 / 0 | |
| 10.1.14 | 7 / 0 | |
| 10.1.13 | 7 / 0 | |
| 10.1.12 | 7 / 0 | |
| 10.1.11 | 7 / 0 | |
| 10.1.10 | 7 / 0 | |
| 10.1.9 | 7 / 0 | |
| 10.1.8 | 7 / 0 | |
| 10.1.7 | 7 / 0 | |
| 10.1.6 | 7 / 0 | |
| 10.1.5 | 7 / 0 | |
| 10.1.4 | 7 / 0 | |
| 10.1.3 | 7 / 0 | |
| 10.1.2 | 7 / 0 | |
| 10.1.1 | 7 / 0 | |
| 10.0.2 | 7 / 0 | |
| 10.0.1 | 7 / 0 | |
| 9.7.2 | 8 / 0 | |
| 9.7.1 | 8 / 0 | |
| 9.6.2 | 8 / 0 | |
| 9.6.1 | 8 / 0 | |
| 9.5.1 | 8 / 0 | |
| 9.4.1 | 8 / 0 | |
| 9.3.1 | 8 / 0 | |
| 9.2.1 | 8 / 0 | |
| 9.1.1 | 8 / 0 | |
| 9.0.1 | 8 / 0 | |
| 8.7.1 | 8 / 0 | |
| 8.6.1 | 8 / 0 | |
| 8.5.1 | 8 / 0 | |
| 8.4.1 | 8 / 0 | |
| 8.3.3 | 8 / 0 | |
| 8.3.2 | 8 / 0 | |
| 8.3.1 | 8 / 0 | |
| 8.2.2 | 8 / 1 | |
| 8.1.2 | 8 / 0 | |
| 8.1.1 | 8 / 0 | |
| 8.0.5 | 6 / 0 | |
| 8.0.4 | 6 / 0 | |
| 8.0.3 | 6 / 0 | |
| 8.0.2 | 6 / 0 | |
| 8.0.1 | 6 / 0 | |
| 8.0.0 | 6 / 0 | |
| 7.9.2 | 7 / 0 | |
| 7.9.1 | 7 / 0 | |
| 7.8.2 | 7 / 0 | |
| 7.8.1 | 7 / 0 | |
| 7.7.1 | 7 / 0 | |
| 7.6.1 | 7 / 0 | |
| 7.5.1 | 7 / 0 | |
| 7.4.1 | 7 / 0 | |
| 7.3.1 | 7 / 0 |
Showing 100 of 551
Next page →