← Home

@subql/common-substrate

31
Versions
GPL-3.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

onfinality-adminscott_subql

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@polkadot/util AI (phantom-deps): Declared dependency used transitively; phantom-dep pattern is expected for this package structure. ai
phantom-deps phantom-dep:bn.js AI (phantom-deps): Declared dependency used transitively; phantom-dep pattern is expected for this package structure. ai
phantom-deps phantom-dep:flatted AI (phantom-deps): Declared dependency used transitively; phantom-dep pattern is expected for this package structure. ai
phantom-deps phantom-dep:graphql AI (phantom-deps): Declared dependency used transitively; phantom-dep pattern is expected for this package structure. ai
phantom-deps phantom-dep:sequelize AI (phantom-deps): Declared dependency used transitively; phantom-dep pattern is expected for this package structure. ai
phantom-deps phantom-dep:graphql-tag AI (phantom-deps): Declared dependency used transitively; phantom-dep pattern is expected for this package structure. ai
phantom-deps phantom-dep:pino AI (phantom-deps): Declared dependency used transitively; phantom-dep pattern is expected for this package structure. ai
dependencies unvetted-dep:pino AI (dependencies): pino is a well-known, widely-used structured logging library; its use in a Substrate indexing framework is expected and benign. ai
dependencies unvetted-dep:sequelize AI (dependencies): sequelize is a well-known ORM; its use in SubQuery's indexing infrastructure is expected and benign. ai
phantom-deps phantom-dep:reflect-metadata AI (phantom-deps): reflect-metadata is a well-known implicit dependency for TypeScript decorator metadata; its indirect usage pattern is expected and stable for this package. ai
npm-metadata no-description AI (npm-metadata): Empty description is a consistent pattern in this monorepo package; not a malware indicator given publisher track record and package age. ai
phantom-deps phantom-dep:js-yaml AI (phantom-deps): js-yaml is a declared runtime dependency used for YAML config parsing in this SubQuery library; phantom detection is a false positive for this package. ai

Versions (showing 31 of 31)

Version Deps Published
4.0.0 4 / 3
3.8.1 4 / 3
3.8.0 4 / 3
3.7.0 4 / 3
3.6.0 4 / 3
3.5.0 4 / 3
3.4.0 4 / 3
3.3.2 4 / 3
3.2.1 4 / 3
3.2.0 4 / 3
3.1.2 4 / 3
3.1.1 4 / 3
2.4.0 4 / 3
2.3.0 4 / 3
2.2.1 4 / 3
2.2.0 4 / 3
2.1.1 4 / 3
2.1.0 4 / 3
2.0.0 6 / 3
1.5.0 6 / 3
1.4.0 6 / 3
1.3.0 6 / 3
1.2.1 6 / 3
1.2.0 6 / 3
1.1.1 6 / 3
1.1.0 6 / 3
1.0.0 6 / 3
0.5.0 6 / 3
0.4.0 6 / 3
0.3.0 13 / 3
0.1.0 13 / 3