← Home

@superfluid-finance/ethereum-contracts

4
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

superfluid_financemiao.decentral.ee

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@safe-global/protocol-kit AI (phantom-deps): Package already uses multiple @safe-global/* deps; usage in build/ops scripts not detected by import scanner is expected. ai
phantom-deps phantom-dep:@safe-global/api-kit AI (phantom-deps): Safe multisig tooling dep used in ops scripts, not imported as JS module; stable FP for this package. ai
phantom-deps phantom-dep:@truffle/contract AI (phantom-deps): Truffle contract dep used via Truffle plugin system, not direct ES imports. ai
phantom-deps phantom-dep:@nomiclabs/hardhat-ethers AI (phantom-deps): Hardhat plugin loaded via hardhat config, not direct imports — standard Hardhat pattern. ai
phantom-deps phantom-dep:ethereumjs-tx AI (phantom-deps): Ethereum tooling dep used transitively via Truffle/Hardhat plugin system, not direct imports. ai
phantom-deps phantom-dep:@openzeppelin/contracts AI (phantom-deps): Referenced in Solidity/config files; not a JS import — standard for Solidity contract packages. ai
phantom-deps phantom-dep:@decentral.ee/web3-helpers AI (phantom-deps): Internal org helper dep; used via runtime tooling, not direct imports. ai
phantom-deps phantom-dep:ethereumjs-util AI (phantom-deps): Ethereum tooling dep used transitively via Truffle/Hardhat plugin system, not direct imports. ai

Versions (showing 4 of 4)

Version Deps Published
1.15.2 8 / 17
1.15.1 8 / 17
1.15.0 7 / 16
1.12.0 7 / 17

v1.15.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.