@substrate/connect
Substrate-connect to Smoldot clients. Using either substrate extension with predefined clients or an internal smoldot client based on chainSpecs provided.
30
Versions
GPL-3.0-only
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
No source commit
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
andreieresmarshacbjacogrkianenigmajoepetrowskiwirednkodniklasad1jsdwparitytech-ciimod7jimmychu0807alexandru.vasiletarikgulparitytechryan-parity
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@substrate/light-client-extension-helpers | AI (dependencies): Same @substrate org scope as this package, maintained by Parity Technologies. Legitimate intra-org dependency for the Substrate ecosystem. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed to paritytech-ci, a Parity Technologies CI account with 1730 approved packages and no rejections. This reflects a legitimate org-wide move to automated CI publishing. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of jeluard is consistent with the transition to CI-based publishing under paritytech-ci; same org, no suspicious indicators. | ai | |
| dependencies | unvetted-dep:@substrate/connect-discovery | AI (dependencies): Same-org dependency (@substrate/ scope, paritytech); consistent with the package's ecosystem and legitimate use. | ai | |
| provenance | no-provenance | AI (provenance): Established paritytech package with clean publisher history; lack of provenance is common and not a risk signal here. | ai | |
| phantom-deps | phantom-dep:@substrate/connect-extension-protocol | AI (phantom-deps): Same-org scoped package declared as dep but not directly imported; consistent with ecosystem packaging patterns for @substrate/connect across versions. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 2.1.8 | 4 / 2 | |
| 2.1.7 | 4 / 2 | |
| 2.1.6 | 4 / 2 | |
| 2.1.5 | 4 / 2 | |
| 2.1.4 | 4 / 2 | |
| 2.1.3 | 4 / 2 | |
| 2.1.2 | 4 / 2 | |
| 2.1.1 | 4 / 2 | |
| 2.1.0 | 4 / 2 | |
| 2.0.1 | 4 / 2 | |
| 2.0.0 | 4 / 2 | |
| 1.3.1 | 4 / 2 | |
| 1.3.0 | 4 / 2 | |
| 1.2.1 | 4 / 1 | |
| 1.2.0 | 4 / 1 | |
| 1.1.3 | 4 / 3 | |
| 1.1.2 | 4 / 3 | |
| 1.1.1 | 4 / 3 | |
| 1.1.0 | 4 / 3 | |
| 1.0.9 | 4 / 5 | |
| 1.0.8 | 4 / 5 | |
| 1.0.7 | 4 / 5 | |
| 1.0.6 | 4 / 5 | |
| 1.0.5 | 4 / 5 | |
| 1.0.4 | 4 / 5 | |
| 1.0.3 | 4 / 5 | |
| 1.0.2 | 5 / 5 | |
| 1.0.1 | 5 / 5 | |
| 1.0.0 | 5 / 5 | |
| 0.8.11 | 4 / 5 |