← Home

@rev-net/core-v6

51
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

me.jango

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern rapid-publish AI (publish-pattern): Package has 71 versions in 80 days; automated rapid publishing is the established release pattern here. ai
dependencies unvetted-dep:@uniswap/permit2 AI (dependencies): GitHub-pinned to specific commit of official Uniswap/permit2 repo; used only in Foundry config, not runtime JS. ai
npm-metadata url-dep:@uniswap/permit2 AI (npm-metadata): Uniswap/permit2 is not published to npm; commit-pinned GitHub dep is the standard approach for this Solidity package. ai
phantom-deps phantom-dep:@uniswap/permit2 AI (phantom-deps): Used only in Foundry remappings/config, not imported in JS code; expected pattern for Solidity dependency packages. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall patches Solidity pragma versions across node_modules for compiler compatibility — no network access, no obfuscation, benign sed substitution consistent with this Solidity library package's purpose. ai
bogus-package bogus-package AI (bogus-package): README link dump is typical of Solidity contract packages listing deployed addresses and docs. No keywords is minor. Not indicative of spam or phishing for this package type. ai
phantom-deps phantom-dep:@bananapus/swap-terminal-v6 AI (phantom-deps): Foundry/Solidity project uses npm deps as remapping sources in foundry.toml, not JS imports. This pattern is standard for this package type. ai
phantom-deps phantom-dep:@openzeppelin/contracts AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@bananapus/buyback-hook-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@croptop/core-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@bananapus/router-terminal-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@bananapus/permission-ids-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@uniswap/v4-core AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@bananapus/core-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@bananapus/ownable-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@bananapus/suckers-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@uniswap/v4-periphery AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai
phantom-deps phantom-dep:@bananapus/721-hook-v6 AI (phantom-deps): Solidity/Foundry package; deps are referenced in config remappings, not JS imports. Phantom-dep findings are expected for this package type. ai

Versions (showing 51 of 53)

View all versions
Version Deps Published
0.0.74 10 / 3
0.0.71 10 / 3
0.0.69 10 / 3
0.0.66 10 / 3
0.0.65 10 / 3
0.0.64 10 / 3
0.0.63 10 / 3
0.0.62 10 / 3
0.0.61 10 / 3
0.0.58 10 / 3
0.0.57 10 / 3
0.0.56 10 / 3
0.0.55 10 / 3
0.0.54 10 / 3
0.0.53 10 / 3
0.0.52 10 / 3
0.0.51 10 / 3
0.0.47 10 / 3
0.0.46 10 / 3
0.0.45 10 / 3
0.0.43 10 / 3
0.0.40 10 / 3
0.0.37 11 / 2
0.0.36 11 / 2
0.0.35 11 / 2
0.0.34 11 / 2
0.0.33 11 / 2
0.0.32 11 / 2
0.0.31 11 / 2
0.0.30 11 / 2
0.0.29 11 / 2
0.0.28 11 / 2
0.0.27 11 / 1
0.0.26 11 / 1
0.0.25 11 / 1
0.0.24 11 / 1
0.0.23 11 / 1
0.0.22 11 / 1
0.0.21 11 / 1
0.0.20 11 / 1
0.0.19 11 / 1
0.0.18 11 / 1
0.0.17 11 / 1
0.0.16 11 / 1
0.0.15 11 / 1
0.0.14 11 / 1
0.0.13 11 / 1
0.0.12 11 / 1
0.0.11 11 / 1
0.0.7 8 / 1
0.0.3 8 / 1

v0.0.74

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.71

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.69

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.66

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.65

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.64

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.63

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.62

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.61

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.58

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.57

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.56

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.55

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.54

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.53

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.52

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.51

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.47

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.46

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.45

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.43

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.40

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.37

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.36

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.35

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.34

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.33

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.32

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.0.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.24

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.14

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: find node_modules -name '*.sol' -type f | xargs grep -l 'pragma solidity 0.8.23;' 2>/dev/null | xargs sed -i '' 's/pragma solidity 0.8.23;/pragma solidity 0.8.26;/g' 2>/dev/null || true

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.13

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: find node_modules -name '*.sol' -type f | xargs grep -l 'pragma solidity 0.8.23;' 2>/dev/null | xargs sed -i '' 's/pragma solidity 0.8.23;/pragma solidity 0.8.26;/g' 2>/dev/null || true

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.12

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: find node_modules -name '*.sol' -type f | xargs grep -l 'pragma solidity 0.8.23;' 2>/dev/null | xargs sed -i '' 's/pragma solidity 0.8.23;/pragma solidity 0.8.26;/g' 2>/dev/null || true

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.11

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: find node_modules -name '*.sol' -type f | xargs grep -l 'pragma solidity 0.8.23;' 2>/dev/null | xargs sed -i '' 's/pragma solidity 0.8.23;/pragma solidity 0.8.26;/g' 2>/dev/null || true

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.7

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: find node_modules -name '*.sol' -type f | xargs grep -l 'pragma solidity 0.8.23;' 2>/dev/null | xargs sed -i '' 's/pragma solidity 0.8.23;/pragma solidity 0.8.26;/g' 2>/dev/null || true

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: find node_modules -name '*.sol' -type f | xargs grep -l 'pragma solidity 0.8.23;' 2>/dev/null | xargs sed -i '' 's/pragma solidity 0.8.23;/pragma solidity 0.8.26;/g' 2>/dev/null || true

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.