← Home

@stacks/clarinet-sdk

A SDK to interact with Clarity Smart Contracts in node.js

21
Versions
GPL-3.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

rafa-stackshugo-stacksstackslabs-admin

Keywords

stacksclarityclarinettests

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance missing-githead AI (provenance): SLSA provenance attestation present; gitHead absence is benign given CI/CD publish flow with Sigstore attestation. ai
phantom-deps phantom-dep:prompts AI (phantom-deps): Declared runtime dep used in CLI/config tooling; not directly imported in main source but legitimately bundled. ai
phantom-deps phantom-dep:kolorist AI (phantom-deps): Declared runtime dep used in CLI/config tooling; not directly imported in main source but legitimately bundled. ai

Versions (showing 21 of 21)

Version Deps Published
3.22.0 5 / 7
3.21.1 5 / 7
3.21.0 5 / 7
3.20.0 5 / 7
3.19.0 5 / 4
3.18.1 5 / 4
3.17.0 5 / 4
3.16.0 5 / 4
3.15.1 5 / 4
3.15.0 5 / 4
3.14.1 5 / 4
3.14.0 5 / 4
3.13.1 5 / 4
3.13.0 5 / 4
3.12.0 5 / 4
3.11.0 5 / 4
3.10.0 5 / 4
3.9.2 5 / 4
3.9.1 5 / 4
3.9.0 5 / 4
3.8.1 5 / 4

v3.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.21.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.