← Home

@talismn/chaindata-provider

`initChaindata.json` file should never be edit manually. it needs to be regenerated before each release using `pnpm chore:generate-init-data`

24
Versions
GPL-3.0-or-later
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

0xkheopsalectalisman

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff encoded-string-file:dist/index.js AI (source-diff): Hex strings are SCALE-encoded Substrate chain metadata, not obfuscated payloads; stable pattern for this chaindata package. ai
source-diff encoded-string-file:dist/index.mjs AI (source-diff): Same SCALE-encoded Substrate metadata pattern in ESM build; stable false positive for this package. ai
source-diff obfuscated-file:dist/index.js AI (source-diff): Standard tsup/esbuild bundle output; samples show readable library code, not obfuscation. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publishing with SLSA attestation is a documented, legitimate supply-chain improvement for this org. ai
source-diff obfuscated-file:dist/index.mjs AI (source-diff): Standard tsup/esbuild ESM bundle; samples show readable library code. ai
source-diff obfuscated-file:dist/index.d.mts AI (source-diff): TypeScript declaration file with long lines from generated type signatures; not obfuscation. ai
source-diff obfuscated-file:dist/index.d.ts AI (source-diff): TypeScript declaration file with long lines from generated type signatures; not obfuscation. ai
source-diff encoded-string-file:dist/talismn-chaindata-provider.cjs.prod.js AI (source-diff): Same Substrate SCALE metadata pattern; benign for this package. ai
source-diff encoded-string-file:dist/talismn-chaindata-provider.esm.js AI (source-diff): Same Substrate SCALE metadata pattern; benign for this package. ai
source-diff encoded-string-file:dist/talismn-chaindata-provider.cjs.dev.js AI (source-diff): Long hex strings are Substrate SCALE-encoded chain metadata (miniMetadatas), not obfuscated payloads; stable pattern for this package. ai
dependencies unvetted-dep:@talismn/util AI (dependencies): Same-org sibling dependency from TalismanSociety; stable pattern across versions. ai
bogus-package bogus-package AI (bogus-package): Established Talisman org package; sparse README/keywords are cosmetic, not indicative of spam. ai

Versions (showing 24 of 24)

Version Deps Published
2.0.0 7 / 5
1.5.1 7 / 5
1.5.0 7 / 5
1.4.0 7 / 4
1.3.9 7 / 4
1.3.8 7 / 4
1.3.7 7 / 4
1.3.6 7 / 4
1.3.5 7 / 4
1.3.4 7 / 10
1.3.3 7 / 10
1.3.2 7 / 10
1.3.1 7 / 10
1.3.0 7 / 10
1.2.0 7 / 10
1.1.6 7 / 10
1.1.5 7 / 10
1.1.4 7 / 10
1.1.2 7 / 10
1.1.1 7 / 10
1.1.0 7 / 10
1.0.2 6 / 10
1.0.1 6 / 10
1.0.0 6 / 10

v2.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.