← Home

@solana/kit

20
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

solana-devs

Keywords

blockchainsolanaweb3

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@solana/transaction-introspection AI (dependencies): Same-org @solana/* sibling at matching version; consistent with monorepo release pattern. ai
typosquat typosquat.levenshtein:vite AI (typosquat): @solana/kit is the official Solana SDK under the @solana scope; not a typosquat of vite. Scoped package comparison is a false positive. ai
typosquat typosquat.levenshtein:got AI (typosquat): @solana/kit is the official Solana SDK under the @solana scope; not a typosquat of got. Scoped package comparison is a false positive. ai
typosquat typosquat.levenshtein:koa AI (typosquat): @solana/kit is the official Solana SDK under the @solana scope; not a typosquat of koa. Scoped package comparison is a false positive. ai
phantom-deps phantom-dep:@solana/rpc-api AI (phantom-deps): Umbrella/barrel package re-exports from sibling @solana/* packages; direct import not required in source. ai
phantom-deps phantom-dep:@solana/sysvars AI (phantom-deps): Umbrella/barrel package re-exports from sibling @solana/* packages; direct import not required in source. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): 127.0.0.1:8899 is the standard Solana local validator address, used only in JSDoc documentation examples. Not a malicious raw IP. ai

Versions (showing 20 of 20)

Version Deps Published
7.0.0 26 / 0
6.10.0 25 / 0
6.9.0 25 / 0
6.8.0 25 / 0
6.7.0 24 / 0
6.6.0 24 / 0
6.5.0 24 / 0
6.4.0 24 / 0
6.3.1 24 / 0
6.3.0 24 / 0
6.2.0 24 / 0
6.1.0 24 / 0
6.0.1 22 / 0
6.0.0 22 / 0
5.5.1 22 / 0
5.5.0 22 / 0
5.4.0 22 / 0
5.3.0 22 / 0
5.2.0 22 / 0
5.1.0 20 / 0

v7.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.