@turnkey/viem
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Historical maintainer transition, unchanged since; legitimate org package. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Org-wide Turnkey maintainer rotation, publisher has strong track record. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Consistent with legitimate team transition, no behavioral change in diff. | ai | |
| phantom-deps | phantom-dep:typescript | AI (phantom-deps): Used for build/typecheck, not runtime import. | ai | |
| phantom-deps | phantom-dep:@openzeppelin/contracts | AI (phantom-deps): Solidity contracts dependency referenced in hardhat/compile config, not a JS import; false positive for this package. | ai | |
| phantom-deps | phantom-dep:cross-fetch | AI (phantom-deps): cross-fetch is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai | |
| typosquat | typosquat.levenshtein:vite | AI (typosquat): @turnkey/viem is intentionally named for the viem library, not a typo of vite. | ai |
Versions (showing 51 of 93)
| Version | Deps | Published |
|---|---|---|
| 0.14.32 | 8 / 4 | |
| 0.14.31 | 8 / 4 | |
| 0.14.30 | 8 / 4 | |
| 0.14.29 | 8 / 4 | |
| 0.14.28 | 8 / 4 | |
| 0.14.27 | 8 / 4 | |
| 0.14.26 | 8 / 4 | |
| 0.14.25 | 8 / 4 | |
| 0.14.24 | 8 / 4 | |
| 0.14.23 | 8 / 4 | |
| 0.14.22 | 8 / 4 | |
| 0.14.21 | 8 / 4 | |
| 0.14.20 | 8 / 4 | |
| 0.14.19 | 8 / 4 | |
| 0.14.18 | 8 / 4 | |
| 0.14.17 | 8 / 4 | |
| 0.14.16 | 8 / 4 | |
| 0.14.15 | 8 / 4 | |
| 0.14.14 | 8 / 4 | |
| 0.14.13 | 8 / 4 | |
| 0.14.12 | 8 / 4 | |
| 0.14.11 | 8 / 4 | |
| 0.14.10 | 8 / 4 | |
| 0.14.9 | 8 / 4 | |
| 0.14.8 | 8 / 4 | |
| 0.14.7 | 8 / 4 | |
| 0.14.6 | 8 / 4 | |
| 0.14.5 | 8 / 4 | |
| 0.14.4 | 8 / 4 | |
| 0.14.3 | 8 / 4 | |
| 0.14.2 | 8 / 4 | |
| 0.14.1 | 8 / 4 | |
| 0.14.0 | 8 / 4 | |
| 0.13.1 | 7 / 4 | |
| 0.13.0 | 7 / 4 | |
| 0.12.1 | 7 / 4 | |
| 0.12.0 | 7 / 4 | |
| 0.11.1 | 7 / 4 | |
| 0.11.0 | 7 / 4 | |
| 0.10.5 | 6 / 4 | |
| 0.10.4 | 6 / 4 | |
| 0.10.3 | 6 / 4 | |
| 0.9.10 | 6 / 4 | |
| 0.9.9 | 6 / 4 | |
| 0.9.8 | 6 / 4 | |
| 0.9.7 | 6 / 4 | |
| 0.9.6 | 6 / 4 | |
| 0.9.5 | 6 / 4 | |
| 0.9.4 | 6 / 4 | |
| 0.9.3 | 6 / 4 | |
| 0.9.2 | 6 / 4 |
v0.14.32
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.27
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.26
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.25
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.24
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.23
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.22
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.21
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.20
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (bcturnkey) on 2025-12-18, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.19
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.18
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.17
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.16
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-11-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.15
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.14
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.13
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.12
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.14.11
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-10-31, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.10
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (r-n-o) on 2025-10-21, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.14.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.14.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (andrewtk) than the most recent previously approved version (r-n-o) on 2025-09-10, but andrewtk is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.13.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-08-28, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.13.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.12.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.11.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.10.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-08-01, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.10.3
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (r-n-o) than the most recent previously approved version (bcturnkey) on 2025-07-31, but r-n-o is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v0.9.8
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bcturnkey) than the most recent previously approved version (andrewtk) on 2025-06-17, but bcturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.7
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (bcturnkey) than the most recent previously approved version (moe-dev) on 2025-06-12, but bcturnkey is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.6
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-06-02, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v0.9.4
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moe-dev) than the most recent previously approved version (andrewtk) on 2025-05-22, but moe-dev is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.