@remix-project/remix-debug
Tool to debug Ethereum transactions
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | url-dep:@ethereumjs/tx | AI (npm-metadata): Fork owned by Remix core maintainer yann300; consistent with project's pattern of patching upstream ethereumjs deps. | ai | |
| phantom-deps | phantom-dep:async | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:merge | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ansi-gray | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:commander | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:deep-equal | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:ethjs-util | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:express-ws | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| semgrep | semgrep:hex-decode | AI (semgrep): Decodes EVM bytecode hex strings for opcode analysis — core debugger functionality, not malicious. | ai | |
| phantom-deps | phantom-dep:color-support | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ethereumjs/tx | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ethereumjs/vm | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ethereumjs/block | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:string-similarity | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@remix-project/remix-simulator | AI (phantom-deps): Same-org sibling package; phantom-dep heuristic not applicable here. | ai | |
| phantom-deps | phantom-dep:time-stamp | AI (phantom-deps): Monorepo config artifact; stable false positive for this package. | ai |
Versions (showing 23 of 23)
| Version | Deps | Published |
|---|---|---|
| 0.5.91 | 22 / 10 | |
| 0.5.90 | 22 / 10 | |
| 0.5.89 | 22 / 10 | |
| 0.5.88 | 22 / 10 | |
| 0.5.87 | 21 / 10 | |
| 0.5.86 | 21 / 10 | |
| 0.5.85 | 21 / 10 | |
| 0.5.84 | 21 / 10 | |
| 0.5.83 | 21 / 10 | |
| 0.5.82 | 21 / 10 | |
| 0.5.81 | 21 / 10 | |
| 0.5.80 | 22 / 10 | |
| 0.5.79 | 22 / 10 | |
| 0.5.78 | 22 / 10 | |
| 0.5.77 | 22 / 10 | |
| 0.5.76 | 22 / 10 | |
| 0.5.75 | 22 / 10 | |
| 0.5.74 | 22 / 10 | |
| 0.5.73 | 22 / 10 | |
| 0.5.72 | 22 / 10 | |
| 0.5.71 | 22 / 10 | |
| 0.5.70 | 22 / 10 | |
| 0.5.69 | 21 / 10 |
v0.5.90
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.89
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.88
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.87
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.86
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.85
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.84
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.83
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.82
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.81
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.80
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.79
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.78
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.77
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.76
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.75
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.74
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.73
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.72
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.71
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.5.70
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.5.69
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.