@uniswap/v3-periphery
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Manual publish by known maintainer; no source-linkage regression indicating compromise. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Legit Uniswap team maintainer addition; org-owned package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): New files are hardhat build-info/artifact JSON, expected for this contracts package. | ai | |
| phantom-deps | phantom-dep:base64-sol | AI (phantom-deps): Solidity smart contract package; deps are consumed by hardhat compiler via config, not Node.js imports. Standard pattern for this package type. | ai | |
| phantom-deps | phantom-dep:@uniswap/lib | AI (phantom-deps): Solidity smart contract package; deps are consumed by hardhat compiler via config, not Node.js imports. This is the standard pattern for this package type. | ai | |
| phantom-deps | phantom-dep:@openzeppelin/contracts | AI (phantom-deps): Solidity smart contract package; deps are consumed by hardhat compiler via config, not Node.js imports. Standard pattern for this package type. | ai | |
| phantom-deps | phantom-dep:@uniswap/v2-core | AI (phantom-deps): Solidity smart contract package; deps are consumed by hardhat compiler via config, not Node.js imports. Standard pattern for this package type. | ai | |
| phantom-deps | phantom-dep:@uniswap/v3-core | AI (phantom-deps): Solidity smart contract package; deps are consumed by hardhat compiler via config, not Node.js imports. Standard pattern for this package type. | ai |
Versions (showing 12 of 12)
| Version | Deps | Published |
|---|---|---|
| 1.4.4 | 5 / 24 | |
| 1.4.3 | 5 / 24 | |
| 1.4.2 | 5 / 24 | |
| 1.4.1 | 6 / 23 | |
| 1.4.0 | 6 / 23 | |
| 1.3.0 | 6 / 23 | |
| 1.2.1 | 6 / 23 | |
| 1.2.0 | 6 / 23 | |
| 1.1.1 | 6 / 23 | |
| 1.1.0 | 6 / 23 | |
| 1.0.1 | 5 / 23 | |
| 1.0.0 | 5 / 23 |
v1.4.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.2
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: willpote.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (willpote) than the most recent previously approved version (noahwz) on 2022-09-16, but willpote is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (noahwz) than the most recent previously approved version (moodysalem) on 2022-04-22, but noahwz is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.4.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: noahwz.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (noahwz) than the most recent previously approved version (moodysalem) on 2022-01-11, but noahwz is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.3.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (moodysalem) than the most recent previously approved version (noahwz) on 2021-11-05, but moodysalem is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (noahwz) than the most recent previously approved version (moodysalem) on 2021-09-28, but noahwz is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.2.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (noahwz) than the most recent previously approved version (moodysalem) on 2021-09-15, but noahwz is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.1.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (willpote) than the most recent previously approved version (moodysalem) on 2021-06-04, but willpote is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.