← Home

@subql/validator

to validate subquery project

29
Versions
GPL-3.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

onfinality-adminjay_ji

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps are all first-party @subql/* sibling packages from the same SubQuery org, representing legitimate multi-chain expansion. Pattern is stable for this package. ai
phantom-deps phantom-dep:ipfs-http-client AI (phantom-deps): ipfs-http-client is declared as a runtime dep in package.json; phantom detection likely reflects indirect usage. No security concern for this package. ai
bogus-package bogus-package AI (bogus-package): Established SubQuery ecosystem package with clear purpose, repo, and publisher history. Short README and missing keywords are cosmetic, not indicative of spam or malice. ai
phantom-deps phantom-dep:axios AI (phantom-deps): Axios is a legitimate declared dependency in package.json; phantom-dep finding is a false positive for this package's usage pattern. ai

Versions (showing 29 of 29)

Version Deps Published
2.2.0 11 / 1
2.1.1 10 / 1
2.1.0 10 / 1
2.0.0 11 / 1
1.8.1 11 / 1
1.8.0 11 / 1
1.7.0 10 / 1
1.6.0 9 / 1
1.5.1 8 / 1
1.5.0 8 / 1
1.4.1 9 / 1
1.4.0 9 / 1
1.3.0 8 / 1
1.2.2 8 / 1
1.2.1 8 / 1
1.2.0 9 / 1
1.1.0 6 / 1
1.0.0 6 / 1
0.6.0 6 / 1
0.4.5 5 / 1
0.4.4 5 / 1
0.4.3 5 / 1
0.4.2 5 / 1
0.4.1 5 / 1
0.4.0 5 / 1
0.3.0 4 / 1
0.2.0 3 / 1
0.1.1 3 / 1
0.1.0 3 / 1