← Home

@socket.tech/bungee-protocol

Bungee Protocol smart contracts

1
Versions
ISC
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

vaibhavchellaniarthcpsalilnaikthemaskedman981ameesha12vishnu_socketshreykeny

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:moment AI (phantom-deps): Declared runtime dep used in scripts/config; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:solmate AI (phantom-deps): Solidity library referenced in Hardhat/Foundry config; not directly imported in JS. ai
phantom-deps phantom-dep:fs-extra AI (phantom-deps): Used in build scripts; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:perf_hooks AI (phantom-deps): Node built-in wrapper; referenced in config, not directly imported. ai
phantom-deps phantom-dep:pre-commit AI (phantom-deps): Git hook tool declared in package.json pre-commit field; not directly imported in JS. ai
phantom-deps phantom-dep:sleep-promise AI (phantom-deps): Utility dep used in scripts; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@types/fs-extra AI (phantom-deps): Type-only package; framework-scoped, not directly imported. ai
phantom-deps phantom-dep:solidity-docgen AI (phantom-deps): Hardhat plugin loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:eth-revert-reason AI (phantom-deps): Referenced in config/scripts; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:@uniswap/permit2-sdk AI (phantom-deps): SDK dep used in contract scripts; phantom-dep heuristic false positive. ai
phantom-deps phantom-dep:hardhat-abi-exporter AI (phantom-deps): Hardhat plugin loaded by convention; not directly imported in JS. ai
phantom-deps phantom-dep:@solidity-parser/parser AI (phantom-deps): Parser used by Hardhat toolchain; phantom-dep heuristic false positive. ai

Versions (showing 1 of 1)

Version Deps Published
0.0.6 13 / 41

v0.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.